WhatsApp
← Blog·Guides·03/02/2026
Insider threat investigation — silhouette employee at desk with USB, outbound file arrow to cloud, and audit shield.

Investigating insider threats without breaking the evidence.

Insider matters — IP theft, data exfiltration, misconduct — follow a predictable pattern and leave signals across email, file-access logs, USB events, cloud-sync activity and messaging platforms. The evidence is usually there. The question is whether it survives the moment the individual realises the organisation is looking. This guide sets out the order that preserves the case, the artefacts that carry the weight, and the actions that routinely destroy otherwise strong matters.

Insider investigations are technically easier than external intrusions because the organisation already owns the systems and the data. They are procedurally harder because the subject is a person with employment rights, contractual expectations and, often, colleagues who will be interviewed as witnesses. The evidence has to be secured before the subject knows to obscure it, and it has to be secured in a way that will survive a tribunal, a High Court injunction hearing, or — where the matter escalates — a criminal referral.

The order that works

  1. 01
    Preserve, quietly. Forensic images of the endpoint, exports of the mailbox and OneDrive/Google Drive, tenant audit logs for the last 90 days, and MDM records — before any conversation with the subject.
  2. 02
    Analyse. Establish what was accessed, copied, printed, forwarded or synced, and where it went. Build a timeline against the subject's stated duties and the dates of the suspected conduct.
  3. 03
    Corroborate. Cross-reference device artefacts with tenant logs, badge access, and — where lawful — CCTV. A single source is a hypothesis; two independent sources is a case.
  4. 04
    Then act. Suspension, injunction, without-notice search order, or termination — instructed on the basis of evidence rather than suspicion, and with the preservation record in the bundle.

The artefacts that carry the weight

ArtefactWhat it showsWhere it lives
USB connection logDevices attached, first/last connect times, volume serials.Windows registry (USBSTOR, MountedDevices), setupapi.dev.log, macOS unified log.
LNK / Jump ListsFiles opened from external volumes, including deleted originals.Windows AutomaticDestinations, Recent folder.
Cloud-sync client logsFiles uploaded to personal OneDrive/Dropbox/Drive from the corporate endpoint.Client log directories, plus provider audit API where linked.
Tenant audit logDownloads, external shares, mailbox rule changes, admin actions.Microsoft 365 Unified Audit Log, Google Workspace Admin log, Slack audit log.
Mail-forwarding rulesSilent exfiltration of correspondence to a personal address.Mailbox rules, transport rules, tenant audit.
Print historyBulk printing of client files ahead of departure.Print server logs, endpoint spool artefacts.

What destroys these cases

  • Confronting the subject before the evidence is secured — giving them notice to wipe, sync-delete or factory-reset.
  • Confiscating the laptop and letting a manager 'have a look' — every click alters timestamps and access logs.
  • Asking IT to 'quickly image' the device without documented method, tooling and hashes — the resulting image will be argued about, not relied on.
  • Turning the device on to check something after suspension — updates, sync clients and telemetry will overwrite exactly the artefacts that matter.
  • Failing to preserve the tenant audit log within its default retention window — 90 days for many Microsoft 365 SKUs, less on some.

Legal and HR alignment

The investigation must sit within the employer's data-protection framework: a documented lawful basis, a proportionality assessment, and — for personal-device review — either policy-based consent or a court order. HR should be briefed in parallel with legal so that the disciplinary or dismissal process, if it comes, is not undermined by a procedural gap the tribunal can seize on. The forensic examiner should be instructed early enough to advise on scope, not just to execute it.

The most common single mistake in insider matters is the well-meaning line manager who wants to 'just have a word first'. That conversation ends the covert preservation window and, in more than one case we have seen, ended the matter.

Frequently asked questions

Can we image an employee's laptop without telling them?

Yes, where the device is company-owned, the employer's policy reserves the right, and the imaging is proportionate to a legitimate concern. Document the decision, the basis, and the scope before you act.

What about a personal phone used for work?

Preservation of personal devices requires consent or a court order. In practice, an examiner can produce a targeted, keyword-scoped extraction that addresses the concern while minimising incursion into private material — and that scoping should be agreed with the subject or the court in advance.

How long do we have before the cloud audit log is gone?

Microsoft 365 retains the Unified Audit Log for 90 or 180 days on most SKUs; Google Workspace and Slack vary. Preserve on the day the concern arises — waiting a week can cost the case.

Do we need to involve the police?

For pure civil recovery of confidential information, usually no. For criminal conduct — Computer Misuse Act offences, fraud, or theft of trade secrets — a referral may be appropriate once the civil position is secured. Take advice before contacting law enforcement.

Can the report be used at tribunal and in the civil court?

A CPR Part 35-compliant report from an independent examiner is admissible in both, provided the examiner has been properly instructed and the chain of custody is intact from acquisition onwards.