Most insider cases are not solved on a laptop. They are solved in authentication records, database logs, VPN sessions and file server auditing, all of which your own systems have been writing without being asked. The endpoint fills in intent. The servers supply the dates. This page is about reading both back before retention quietly deletes half of it.
◇ Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.
Each of these is the point at which an uneasy feeling turns into something worth putting in writing.
Leaving is an HR process and revocation is a technical one, and the gap between them is where these cases live. A mailbox gets disabled while a VPN certificate does not. A domain account is removed while a SaaS licence billed to a different department survives. Shared credentials that were never tied to a person carry on regardless. SSH keys and API tokens are copied rather than borrowed, so revoking the person's password changes nothing. Authentication logs answer this directly: which credential was used, from which address, at what hour, against which system. Activity after a final working day is one of the few findings in this practice that is genuinely difficult to explain away.
Ask for the server-side records early, because most of them expire. Domain controller and identity provider sign-in logs. VPN and remote access sessions with source addresses. File server auditing showing what was read and copied. Database query and export logs. SaaS admin and download logs. Backup catalogues, which sometimes preserve a version of a share that has since been tidied. None of this requires the servers to leave the building — extracts are taken under an agreed scope and analysed against whatever endpoint material exists. Where a physical disk out of a server does need to come in, that is the ordinary array route and the bands on the <a href="data-recovery-cost.html">prices</a> page apply to the recovery half of it.
Access on its own is ambiguous, because people have jobs and jobs involve files. What distinguishes an insider case is pattern: directories opened at a scale the role never needed, clustered around a resignation; archives assembled in the evenings; the same folders touched the night before a laptop is handed back; browsing that shows a competitor's site and a recruitment portal in the same session. None of those is conclusive by itself and the report does not pretend otherwise. Put in sequence and dated, they are usually the substance of the case, and a report that says so plainly survives cross-examination better than one that overstates any single item.
This is the question employers most often get wrong in both directions. A personal laptop brought into the office cannot be examined without its owner's agreement, a protocol settled between solicitors, or a court order — it is somebody else's property and instructing a laboratory does not change that. What can be examined is your own network's record of it: DHCP leases, switch port and wireless association logs, the MAC address, what it authenticated against and what it reached. That is frequently enough to establish presence and access without ever touching the device, and the report is explicit about where that evidence stops.
Handling and custody are at the forensic recovery hub. Capturing the endpoint properly is workstation deep imaging, mail and tenancy activity is at email and cloud exfiltration, and where the material at stake is designs, code or client lists the version written for that is trade secret and IP theft.
Server records supply the dates, the endpoint supplies the context, and the report shows which of the two each finding rests on.
The keys, tokens and stored passwords that travelled, each with a date on it.
Which systems those credentials reached, at what hour, from which address.
Database and share exports at volume, with the queries that produced them.
Directories opened well outside the role, clustered around a leaving date.
Archives, messages, print runs and browsing that bear on intention.
What your own network lawfully shows about a personal device, and no further.
The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.
The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.
The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.
Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Anything that is not forensic keeps the band it has always had on the prices page.
Insider work runs on the company's own systems, logs and issued hardware, with the company's authority or on a solicitor's written instruction. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.
Most of an insider investigation happens on your own systems, so ring 0800 689 0668 before you move anything and we will agree the extract and the order of work. Where hardware does need examining, send the drive rather than the machine, by tracked, insured post to Cambridge or over the counter there in office hours. Nothing is collected and Leicester has no counter.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
Preserve the logs before you revoke anything, then ring the freephone and we will scope the extract with you.