Design files, source repositories, formulations and client lists tend to leave through a valid login rather than a break-in, which is why nothing looks wrong until the material turns up elsewhere. The investigation reconstructs the route out and dates each step of it, and it is worth far more in the first fortnight than in the third month. Instructed by engineering, software and manufacturing firms across Leicestershire.
◇ Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.
These are usually spotted by the people who use the material daily. Preserve first, investigate second, and confront only once both are done.
Almost none of this work involves an intrusion. The access was granted, it was appropriate for the job, and it was used for something else in the last few weeks of employment. So the investigation is not looking for a break-in; it is looking for a change in behaviour that has dates attached. Volume is the usual signal — a repository cloned in full rather than a branch checked out, a drawing library copied entire rather than the three parts anybody needed, a CRM exported wholesale on a Tuesday evening. Read against six months of normal use by the same account, that shift is measurable rather than impressionistic.
There are a limited number of exits and each leaves its own residue. Removable media leaves a device register, connection times and link files. Personal cloud clients leave local databases, mirrored folders and upload logs. Webmail leaves browser history, cache and sometimes the attachment itself. Large-file transfer sites leave session records. Source control leaves clone and push logs on the server. Printing leaves a spool and a job history and is forgotten by nearly everybody. The examination runs all of them rather than picking one, because a case built on a single channel falls over as soon as the other side suggests a second.
Documents carry more than their contents. Office files and CAD formats hold embedded metadata: author, company, revision identifiers, template paths, editing history, and sometimes the original file name and location. Drawings keep part numbers and title-block data. Source files keep comments, variable names and, in the awkward cases, the same mistakes. Where a competitor's document can lawfully be obtained — in disclosure, or because it was sent to you — that metadata can be compared with yours and the relationship described precisely. Hash matching turns resemblance into identity where the file is unchanged, and near-duplicate analysis handles the cases where it has been edited.
This is the part worth acting on today. Server logs roll, tenancy audit data expires on a licence-dependent schedule, backups rotate, and a laptop in daily use overwrites the unallocated space an examination reads. None of that is recoverable once it has gone. So the order is preservation, then investigation, then any confrontation — in that order and not another. Approaching the person first is the reliable way to lose the evidence, because the next thing that happens is a device being wiped, an account being tidied and a story being prepared. Where an injunction or a search order is in prospect, the solicitors will want the preservation done properly first in any event.
Custody and method are set out at the forensic recovery hub. Credentials and access run alongside this at insider threat forensics, removable media at USB device forensics, and the preservation that has to happen first is at legal hold and chain of custody.
Each part is dated and attributed, and the report states where the technical evidence ends and inference would have to begin.
Repositories, drawing sets and databases leaving in a single operation.
Part numbers, project code names and confidentiality banners found on the image.
Embedded metadata and revision identifiers linking a rival document to yours.
Browser sends, transfer sites, personal cloud and the printer, each one dated.
Deleted files and archives put back into the record wherever they survived.
Every opening, export and print run against protected material, with its login.
The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.
The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.
The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.
Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Anything that is not forensic keeps the band it has always had on the prices page.
IP instructions are taken over the company's own systems and issued hardware, or on written instruction from a solicitor where proceedings are in prospect. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.
Preservation comes before packing, so ring 0800 689 0668 first and we will agree what is captured, in what order, and what actually needs to travel. Send drives rather than whole machines where the disk comes out. Nothing is collected anywhere in this network and there is no counter in Leicester: tracked, insured post to Cambridge, or over the counter there during office hours, with custody opening at booking-in.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
Preserve, then investigate, then confront. Ring the freephone before the logs roll and before anybody is spoken to.