Insider investigations are technically easier than external intrusions because the organisation already owns the systems and the data. They are procedurally harder because the subject is a person with employment rights, contractual expectations and, often, colleagues who will be interviewed as witnesses. The evidence has to be secured before the subject knows to obscure it, and it has to be secured in a way that will survive a tribunal, a High Court injunction hearing, or — where the matter escalates — a criminal referral.
The order that works
- 01Preserve, quietly. Forensic images of the endpoint, exports of the mailbox and OneDrive/Google Drive, tenant audit logs for the last 90 days, and MDM records — before any conversation with the subject.
- 02Analyse. Establish what was accessed, copied, printed, forwarded or synced, and where it went. Build a timeline against the subject's stated duties and the dates of the suspected conduct.
- 03Corroborate. Cross-reference device artefacts with tenant logs, badge access, and — where lawful — CCTV. A single source is a hypothesis; two independent sources is a case.
- 04Then act. Suspension, injunction, without-notice search order, or termination — instructed on the basis of evidence rather than suspicion, and with the preservation record in the bundle.
The artefacts that carry the weight
| Artefact | What it shows | Where it lives |
|---|---|---|
| USB connection log | Devices attached, first/last connect times, volume serials. | Windows registry (USBSTOR, MountedDevices), setupapi.dev.log, macOS unified log. |
| LNK / Jump Lists | Files opened from external volumes, including deleted originals. | Windows AutomaticDestinations, Recent folder. |
| Cloud-sync client logs | Files uploaded to personal OneDrive/Dropbox/Drive from the corporate endpoint. | Client log directories, plus provider audit API where linked. |
| Tenant audit log | Downloads, external shares, mailbox rule changes, admin actions. | Microsoft 365 Unified Audit Log, Google Workspace Admin log, Slack audit log. |
| Mail-forwarding rules | Silent exfiltration of correspondence to a personal address. | Mailbox rules, transport rules, tenant audit. |
| Print history | Bulk printing of client files ahead of departure. | Print server logs, endpoint spool artefacts. |
What destroys these cases
- Confronting the subject before the evidence is secured — giving them notice to wipe, sync-delete or factory-reset.
- Confiscating the laptop and letting a manager 'have a look' — every click alters timestamps and access logs.
- Asking IT to 'quickly image' the device without documented method, tooling and hashes — the resulting image will be argued about, not relied on.
- Turning the device on to check something after suspension — updates, sync clients and telemetry will overwrite exactly the artefacts that matter.
- Failing to preserve the tenant audit log within its default retention window — 90 days for many Microsoft 365 SKUs, less on some.
Legal and HR alignment
The investigation must sit within the employer's data-protection framework: a documented lawful basis, a proportionality assessment, and — for personal-device review — either policy-based consent or a court order. HR should be briefed in parallel with legal so that the disciplinary or dismissal process, if it comes, is not undermined by a procedural gap the tribunal can seize on. The forensic examiner should be instructed early enough to advise on scope, not just to execute it.
The most common single mistake in insider matters is the well-meaning line manager who wants to 'just have a word first'. That conversation ends the covert preservation window and, in more than one case we have seen, ended the matter.
Frequently asked questions
Yes, where the device is company-owned, the employer's policy reserves the right, and the imaging is proportionate to a legitimate concern. Document the decision, the basis, and the scope before you act.
Preservation of personal devices requires consent or a court order. In practice, an examiner can produce a targeted, keyword-scoped extraction that addresses the concern while minimising incursion into private material — and that scoping should be agreed with the subject or the court in advance.
Microsoft 365 retains the Unified Audit Log for 90 or 180 days on most SKUs; Google Workspace and Slack vary. Preserve on the day the concern arises — waiting a week can cost the case.
For pure civil recovery of confidential information, usually no. For criminal conduct — Computer Misuse Act offences, fraud, or theft of trade secrets — a referral may be appropriate once the civil position is secured. Take advice before contacting law enforcement.
A CPR Part 35-compliant report from an independent examiner is admissible in both, provided the examiner has been properly instructed and the chain of custody is intact from acquisition onwards.
