Nobody who does serious damage from the inside makes an announcement about it. A login goes on working long after the leaving date. An export runs on a quiet Tuesday afternoon. An archive gets assembled the evening before a resignation letter appears. The investigation is built out of records the business is already keeping — on endpoints, on servers, on the network — and it reports only what those records will bear, tied to named accounts, sessions and hours. Instructed by logistics operators, software houses and professional firms throughout Berkshire, Surrey and London.
◇ Footing first, bench afterwards. An investigation with its full written report is £800 + VAT; a verified image with deleted-file extraction and no report written is £400 + VAT, the same point as a recorder disk. The diagnostic is free and the scope goes in writing first. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are published on the data recovery cost page.
Each of these is the point at which an uneasy feeling turns into a written instruction.
Access outlives employment far more often than boards expect. Copy a user profile and the cached credentials and the password manager store go with it. Keys and tokens taken during a final week carry on functioning until somebody remembers to revoke them. A colleague's password, observed once over a shoulder, works perfectly well from a kitchen table in Camberley. Using any of that once the employment has finished is unauthorised access under the Computer Misuse Act 1990. The work therefore runs in two stages: establish which credentials left the building, then read authentication records against endpoint artefacts until every system they reached can be listed with hours and source addresses beside it. The entries falling after the leaving date are usually the ones that end the argument.
Endpoints are the smaller half of most of these cases. Query history exposes bulk extraction — a single statement that lifted the customer table, timed and tied to an account. Backups and snapshots compared with one another date the point at which records were altered or removed. File-server auditing shows which shares were opened and by whom, and where that pattern departed from habit; wholesale access across directories a role had no business in is among the most reliable indicators available. Print service logging and spool remnants show protected material reaching paper, with the document name, the user and the page count. Firewall and proxy records expose sustained transfers to destinations no process accounts for. Server evidence also decays faster than anything else, because log rotation runs to a timetable measured in weeks, so it heads the preservation list rather than trailing it.
Judges and tribunal panels distinguish carelessness from planning, so the examination collects what bears on that distinction and leaves the conclusion wherever it lands. Messages about the move or the material, held in Teams and Slack caches on the endpoint. Archives built over a final week, whose file listings are frequently recoverable even where the archive body is not. Recruitment sites and a rival's product pages threaded through the browsing record. Document metadata whose last-saved-by field puts a named account on a named file at a named minute. Not one of those settles anything alone, and the report says as much. Laid out in sequence across a fortnight, they generally do.
A personal laptop on the office network sits directly on a legal boundary, and we stay on the lawful side of it without exception. What the infrastructure recorded is the company's and is fair evidence: association times, hardware identifiers, how much traffic was carried, which destinations were reached. The device itself is off limits without the owner's agreement, a protocol agreed between solicitors, or a direction of the court. Live traffic is never intercepted here under any circumstances, interception being reserved to the bodies named in the Investigatory Powers Act 2016. The report works from what the network lawfully shows and states that limit in terms — which is exactly what keeps it standing when somebody sets about attacking it.
The capture discipline underneath all of this is described at the forensic recovery hub. Exits through a tenancy go on at email and cloud exfiltration, taking an endpoint properly at workstation deep imaging, and the trade-secret version of the same story at trade secret and IP theft. Where the incident turns out to have come from outside the business instead, that is ransomware recovery.
Each one pinned to an account, given an hour, and traced back to the record it came from.
Which keys, tokens and saved passwords left the estate, and on what date.
Every system those credentials touched, with hours and originating addresses.
Bulk exports out of databases and shares, with the query record behind them.
Directories opened far outside the role, clustered around a resignation.
Archives, messages, print runs and browsing that go to intent.
What the network lawfully reveals about a personal device — and where that stops.
Start with the part people are least often told: a forensic examination sits outside no fix, no fee. That guarantee belongs to logical recovery work, and the stated exclusions are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench time spent answering a question, so it is charged whether the answer helps you or not. What it does have is two published figures, which is two more than most laboratories will put in front of you. An examination that ends in a full written report is £800 + VAT. An examination that stops at the evidence itself — a verified binary image with the deleted material extracted out of it, handed over for somebody else to interpret — is £400 + VAT. That second figure is the same point on the list as a recorder disk or a BitLocker volume, so it adds nothing new to the five bands the rest of the site publishes.
The examination and the full written report that comes out of it, produced so an expert acting against you can follow every step and test it.
The verified binary image with deleted files extracted from it, and no report written. The same figure a recorder disk or an encrypted volume carries, not an extra band.
Both figures assume one machine and one question put to it. Nine laptops, a file server and a tenancy export is a larger exercise, so anything spanning several devices is measured after the free diagnostic and written down before you agree to it. Diagnosis still costs nothing and still closes 2 working days after the device is booked in, and the fee is settled before an examiner opens the image rather than after. Several servers, or an entire log estate, is a larger scope and gets its own written quotation once the free diagnostic has closed. Everything that is not forensic keeps its published band on the prices page.
This work is confined to systems and records the company owns, under HR authority or a solicitor's written instruction. Three routes reach this bench and there has never been a fourth. Equipment the business itself bought and issued. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means one owned outright or owned jointly. Nothing is broken into here. We do not work out somebody else's password, we do not put monitoring software on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to nobody else. Where a client has no lawful right to look inside a device, instructing us does not create one. Handsets and tablets fall outside the practice altogether.
These instructions tend to start with a telephone call rather than a box. Ring 0800 689 0668, tell us what is in front of you, and you will come off the call with a list of what has to be preserved before the logs rotate tonight. Should hardware need to travel, it reaches Guildford by tracked, insured post or over the counter there in office hours. Nobody in this network collects and Bracknell has no counter. Every item is signed into custody as it arrives.
Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.
↓ Print the shipping & booking-in form (PDF)
The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.
Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.
Get the logs preserved before rotation reaches them — the freephone puts you through to an examiner rather than a queue.