Insider Threat Forensics

Insiders who do real damage do not announce themselves. Access carries on working past the leaving date. An export fires mid-afternoon on a Tuesday. The archive gets built the night before a resignation. Investigations here are assembled from records the company already holds, across endpoint, server and network, and they report what those records will carry against named accounts, sessions and hours.

Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// signs of an insider problem

What tends to prompt an investigation

These are what turn an uneasy feeling into a written instruction.

Sign-ins are logged after somebody's final day of employment
Saved passwords, API tokens or SSH keys look to have gone with someone
Bulk exports have run against a database and nobody owns them
Archives were built and compressed in the days before a departure
Browsing history on a work machine is job boards and competitors
A personal device nobody recognises has joined the office network

Access that outlives the employment

Access survives employment far more often than companies plan for. Copy a profile and the cached credentials plus the password-manager store go with it. Keys and tokens taken during a final week keep on working until someone gets round to revoking them. A colleague's password, seen once across a desk, works fine from a kitchen table. So the job is to establish which credentials left, then read authentication logs alongside endpoint traces until the systems reached can be listed with their source addresses and hours. Everything after the leaving date goes in, and that is commonly the part that decides it.

What the servers are sitting on

Endpoints only ever give you half. Query history exposes extraction at scale: the SELECT that lifted a client table, timed and owned by an account. Set backups and snapshots side by side and the moment records altered or vanished acquires a date. File-server logs show who opened which shares and where a pattern broke away from habit. Network records and captures show sustained transfers out to addresses no business process explains. Server material also ages faster than anything else, because logs rotate to schedules counted in weeks, so it heads the preservation list. Targeted capture also keeps the business trading while the evidence sits still, which matters when the server in question runs job costing.

Intent, evidenced instead of assumed

A tribunal will draw its own line between carelessness and planning, so the investigation gathers whatever speaks to it. Teams and Slack traffic discussing either the move or the material. Archives in RAR or 7z put together across the last few days, whose contents lists frequently survive even once the archives have been binned. Competitor sites and job boards threaded through browsing history. Metadata with a last-modified-by value setting a named account against a named file at a stated hour. Individually, not one of those decides a thing. Lined up, they generally do.

Private devices on the office network

Somebody's own handset or laptop on the office Wi-Fi puts us hard against a legal line, and we stop on the lawful side of it. Whatever your network wrote down is company property and perfectly fair evidence: association times, hardware identifiers, volume carried, destination reached. Examining the kit itself would need the owner agreeing, a protocol settled between solicitors, or an order of the court. Reports here are built out of what the infrastructure lawfully shows, and they state where that line falls, which is exactly what keeps them usable.

Imaging discipline behind this service belongs to the forensic recovery hub. For exits by way of a tenancy, see email and cloud exfiltration. Endpoint capture is workstation deep imaging. The trade-secret angle is the IP theft page. Figures are on the prices page.

// what the work establishes

The findings an insider case stands on

Tied to accounts and sessions, dated, and traced back into the systems' own records.

Credentials

Which keys, tokens and stored passwords went, and when.

Access rebuilt

The systems reached with them, by hour and source address.

Exports

Extraction at scale out of databases and file servers, backed by query evidence.

Network

Steady outbound transfers to external addresses, out of logs and captures.

Planning

Messages, archives, browsing and metadata that speak to intent.

The boundary

What Wi-Fi records lawfully show about a personally owned device.

// the price, and who we may act for

Forensic fees, and the footing underneath them

The money, stated plainly

Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Where a scope reaches across several servers, we quote in writing once the free diagnostic is done. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.

The footing we need

Insider instructions run on systems and records in the company's ownership, behind HR or behind a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.

// getting your device to us

Getting it to the bench — plainly done

These cases usually begin with a scoping call and not a parcel. Ring 0800 689 0668, tell us what you are looking at, and we will list what needs preserving before tonight. Collection is not offered here. Where hardware has to travel it goes tracked and insured, or comes across the counter, and is booked into custody once it lands in Edinburgh.

Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.

  • Bubble wrap, then a rigid box or padded envelope packed tight enough that nothing rattles. Keep the cables, caddies and power bricks at home.
  • Print the shipping & booking-in form (PDF). Name, mobile number, two lines on what went wrong. In the box with the drive.
  • Royal Mail Special Delivery is tracked and insured door to door. Your own courier account does the same job if you would rather use it.
  • Handing it over yourself instead? Reception takes drop-offs at the address below, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Edinburgh Data Recovery

4 Redheughs Rigg
Westpoint, South Gyle
Edinburgh, EH12 9DQ

↓ Print the shipping & booking-in form (PDF)

Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.

Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.

// insider threat · asked before instruction

What boards and IT leads want answered

Session records, source addresses and authentication logs normally settle that: the account, its origin, the hour, and what it touched. Preserve those logs now, since rotation throws them away to its own timetable, and pull the access once a capture exists.
Rarely. Most server-side work is narrow: exports of logs, snapshots of databases, images of named volumes, taken into hash-verified files with your own IT staff present and generally without a minute of downtime. What gets taken, and the reason for it, goes in the written scope.
Not without agreement, a settled protocol or an order of the court. That machine belongs to them. What your own network recorded about it belongs to you, though, and association times, volumes carried and destinations reached frequently carry the point without anyone touching the device.
No. Rotation was the right security decision, and the history outlives it. Query records, endpoint traces and logs all still show what those credentials were used for while they worked. The thing that counts now is getting the lot preserved before routine housekeeping thins it out.

Your own systems wrote it down. We read it straight back.

Preserve the logs before rotation takes them. The freephone puts you through to an examiner, not a queue.