Workplace investigations

Forensic Investigation of Employee Data Theft and File Copying

Preservation-first investigation of suspected USB copying, personal email, cloud transfers, deletion, remote access and computer use around an employee’s departure.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Preserve before reset, reissue or routine use changes the record

When an employee leaves or misuse is suspected, normal IT actions can change useful records. Reissuing a laptop, resetting an account, allowing extended use or waiting for short-retention cloud logs may narrow the questions that can later be answered.

Alistair works directly with the organisation and its advisers to identify proportionate sources, preserve what is available and build a documented chronology. The technical work is kept separate from HR findings and legal conclusions, and collection is limited to what is properly authorised and relevant.

Questions the investigation may address

  • Whether removable storage was connected and what file activity coincided with that use.
  • Whether cloud-sync tools, webmail, browsers or transfer services record relevant activity.
  • Whether files were accessed, copied, renamed, archived or deleted around key dates.
  • Whether remote access, account logins or system events support a reliable chronology.
  • What alternative business or automated explanations remain plausible.

Potential sources to protect

  • The employee computer and any company mobile device, without unnecessary further use.
  • Identity, email, cloud, VPN, endpoint and other available audit logs.
  • USB history, recent-file records, browser artefacts and cloud-client databases.
  • Employment dates, role, authorised working practices and the known timeline.
  • Relevant policies, preservation notices and an agreed lawful scope.

Investigating whether an employee copied files to USB

A connected USB device is a lead, not proof of copying. A useful review compares the connection history with relevant file activity, available destination records, application traces and the working timeline. It also tests ordinary explanations such as authorised transfers, backups and synchronisation. The USB connection and file-copying guide explains the difference.

Where personal cloud storage, webmail or Microsoft 365 is involved, the computer may hold only part of the history. Preservation can also need relevant tenant, mailbox, SharePoint, OneDrive or endpoint records, subject to authority and availability. The scope should identify those sources before a laptop is reset or logs expire.

Digital evidence for an Employment Tribunal or related dispute

A focused chronology can help test allegations about deletion, access, disclosure of business material or disputed communications. Alistair can prepare a technical schedule or expert report to the agreed purpose. The legal team sets the questions and advises on relevance, privacy and the tribunal’s directions. Tribunal procedure should not be treated as automatically interchangeable with civil-court CPR Part 35 requirements. See the Employment Tribunal evidence section.

What workplace artefacts do not prove

  • A file-access record or connected USB device does not automatically prove that confidential material was taken.
  • Synchronisation, backups, software updates and normal work can produce similar artefacts.
  • Attribution may remain qualified on shared devices or accounts.
  • Employment, privacy and monitoring decisions require advice from the organisation’s legal or HR team.

Information needed before preservation or examination

  • Employee, company, opposing party and adviser names for conflicts.
  • The suspected conduct, key dates and business systems involved.
  • Device count, ownership, present location and whether any have been reset or reissued.
  • Available log sources and their retention periods.
  • Any urgent preservation deadline and the required form of findings.

Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.

How conflict checks, quotations and evidence transfer work

Frequently asked questions

Should IT inspect the laptop first?

Avoid exploratory use if a formal investigation may follow. Record its state, protect it from routine change and obtain scoped advice on the least disruptive preservation step.

Can the work be done remotely?

Some collection and review can be remote. Device state, data volume, access, security and the required assurance determine whether remote or on-site work is appropriate.

Read all questions about fees, timing, evidence and instructing Alistair

Initial enquiry

Protect the evidence before routine IT work changes it

Describe the device and account status, suspected activity, key dates and any planned reset, reissue or access change. Source-specific preservation advice can then be scoped.

Discuss workplace evidence