Insider Threat Forensics

Nobody who does serious damage from the inside makes an announcement about it. A login goes on working long after the leaving date. An export runs on a quiet Tuesday afternoon. An archive gets assembled the evening before a resignation letter appears. The investigation is built out of records the business is already keeping — on endpoints, on servers, on the network — and it reports only what those records will bear, tied to named accounts, sessions and hours. Instructed by logistics operators, software houses and professional firms throughout Berkshire, Surrey and London.

Footing first, bench afterwards. An investigation with its full written report is £800 + VAT; a verified image with deleted-file extraction and no report written is £400 + VAT, the same point as a recorder disk. The diagnostic is free and the scope goes in writing first. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are published on the data recovery cost page.

// what surfaces first

What usually sets one of these off

Each of these is the point at which an uneasy feeling turns into a written instruction.

Authentication records show activity after somebody's final working day
SSH keys, API tokens or a password manager store appear to have travelled
The database has produced bulk exports that no business process explains
Compressed archives were assembled across somebody's last few evenings
Recruitment sites and a competitor's pages fill a work machine's history
An unfamiliar personal device has attached itself to the office network

Access that keeps working after the job ends

Access outlives employment far more often than boards expect. Copy a user profile and the cached credentials and the password manager store go with it. Keys and tokens taken during a final week carry on functioning until somebody remembers to revoke them. A colleague's password, observed once over a shoulder, works perfectly well from a kitchen table in Camberley. Using any of that once the employment has finished is unauthorised access under the Computer Misuse Act 1990. The work therefore runs in two stages: establish which credentials left the building, then read authentication records against endpoint artefacts until every system they reached can be listed with hours and source addresses beside it. The entries falling after the leaving date are usually the ones that end the argument.

The half of the evidence that lives on servers

Endpoints are the smaller half of most of these cases. Query history exposes bulk extraction — a single statement that lifted the customer table, timed and tied to an account. Backups and snapshots compared with one another date the point at which records were altered or removed. File-server auditing shows which shares were opened and by whom, and where that pattern departed from habit; wholesale access across directories a role had no business in is among the most reliable indicators available. Print service logging and spool remnants show protected material reaching paper, with the document name, the user and the page count. Firewall and proxy records expose sustained transfers to destinations no process accounts for. Server evidence also decays faster than anything else, because log rotation runs to a timetable measured in weeks, so it heads the preservation list rather than trailing it.

Showing intent instead of assuming it

Judges and tribunal panels distinguish carelessness from planning, so the examination collects what bears on that distinction and leaves the conclusion wherever it lands. Messages about the move or the material, held in Teams and Slack caches on the endpoint. Archives built over a final week, whose file listings are frequently recoverable even where the archive body is not. Recruitment sites and a rival's product pages threaded through the browsing record. Document metadata whose last-saved-by field puts a named account on a named file at a named minute. Not one of those settles anything alone, and the report says as much. Laid out in sequence across a fortnight, they generally do.

Privately owned kit on a company network

A personal laptop on the office network sits directly on a legal boundary, and we stay on the lawful side of it without exception. What the infrastructure recorded is the company's and is fair evidence: association times, hardware identifiers, how much traffic was carried, which destinations were reached. The device itself is off limits without the owner's agreement, a protocol agreed between solicitors, or a direction of the court. Live traffic is never intercepted here under any circumstances, interception being reserved to the bodies named in the Investigatory Powers Act 2016. The report works from what the network lawfully shows and states that limit in terms — which is exactly what keeps it standing when somebody sets about attacking it.

The capture discipline underneath all of this is described at the forensic recovery hub. Exits through a tenancy go on at email and cloud exfiltration, taking an endpoint properly at workstation deep imaging, and the trade-secret version of the same story at trade secret and IP theft. Where the incident turns out to have come from outside the business instead, that is ransomware recovery.

// what the examination establishes

The six pillars of an insider case

Each one pinned to an account, given an hour, and traced back to the record it came from.

Credentials

Which keys, tokens and saved passwords left the estate, and on what date.

Reach

Every system those credentials touched, with hours and originating addresses.

Extraction

Bulk exports out of databases and shares, with the query record behind them.

Mass access

Directories opened far outside the role, clustered around a resignation.

Preparation

Archives, messages, print runs and browsing that go to intent.

The limit

What the network lawfully reveals about a personal device — and where that stops.

// paying for it, and being entitled to ask

What it costs, and who may instruct

Two figures, printed rather than hinted at

Start with the part people are least often told: a forensic examination sits outside no fix, no fee. That guarantee belongs to logical recovery work, and the stated exclusions are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench time spent answering a question, so it is charged whether the answer helps you or not. What it does have is two published figures, which is two more than most laboratories will put in front of you. An examination that ends in a full written report is £800 + VAT. An examination that stops at the evidence itself — a verified binary image with the deleted material extracted out of it, handed over for somebody else to interpret — is £400 + VAT. That second figure is the same point on the list as a recorder disk or a BitLocker volume, so it adds nothing new to the five bands the rest of the site publishes.

£800 + VAT

The examination and the full written report that comes out of it, produced so an expert acting against you can follow every step and test it.

£400 + VAT

The verified binary image with deleted files extracted from it, and no report written. The same figure a recorder disk or an encrypted volume carries, not an extra band.

Both figures assume one machine and one question put to it. Nine laptops, a file server and a tenancy export is a larger exercise, so anything spanning several devices is measured after the free diagnostic and written down before you agree to it. Diagnosis still costs nothing and still closes 2 working days after the device is booked in, and the fee is settled before an examiner opens the image rather than after. Several servers, or an entire log estate, is a larger scope and gets its own written quotation once the free diagnostic has closed. Everything that is not forensic keeps its published band on the prices page.

The footing an examination needs

This work is confined to systems and records the company owns, under HR authority or a solicitor's written instruction. Three routes reach this bench and there has never been a fourth. Equipment the business itself bought and issued. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means one owned outright or owned jointly. Nothing is broken into here. We do not work out somebody else's password, we do not put monitoring software on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to nobody else. Where a client has no lawful right to look inside a device, instructing us does not create one. Handsets and tablets fall outside the practice altogether.

// getting the media to the bench

Booking a device in — what actually has to happen

These instructions tend to start with a telephone call rather than a box. Ring 0800 689 0668, tell us what is in front of you, and you will come off the call with a list of what has to be preserved before the logs rotate tonight. Should hardware need to travel, it reaches Guildford by tracked, insured post or over the counter there in office hours. Nobody in this network collects and Bracknell has no counter. Every item is signed into custody as it arrives.

Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.

  • Pick packaging that holds its shape — a rigid carton or a heavy padded mailer — and pack round the unit so it cannot shift in transit. Leave the caddy, the mains adaptor and the leads at home; none of them are wanted at this end.
  • Print the shipping and booking-in form (PDF), put your name and mobile on it along with a sentence describing how the fault started, and slip it in alongside the media.
  • Send it Special Delivery through the Post Office and it travels tracked and covered. A courier account of your own works just as well. The only thing that matters is that somebody signs for it at this end.
  • If you would sooner deliver it by hand, the Guildford reception on the address card takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Bracknell shopfront nor a pickup van exists — those are the two things we cannot offer.
// write this on the label

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the shipping & booking-in form (PDF)

The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.

Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.

// insider cases — what directors ask

What boards need answered

Authentication records, originating addresses and session logs normally answer it outright: which account, from where, at what time, and what it reached once inside. Two things matter now. Preserve those logs today, because rotation removes them on a schedule that will not wait for your decision. And revoke the access after the capture exists rather than before it.
Almost never. Server work is done on targeted material — exported logs, database snapshots, images of specific volumes — written to hash-verified files with your own IT staff present, usually with no downtime at all. The written scope says precisely what is being taken and why before anybody touches a console.
Not without their agreement, a protocol between solicitors or a direction of the court, since the machine is theirs. What the network recorded about it, however, is yours: association times, traffic volumes and destinations reached frequently carry the point without anybody going near the device.
No. Rotating them was the correct security call and it does not erase the history. Logs, query records and endpoint artefacts all still show what those credentials were doing while they worked. The urgent job now is preserving that before routine housekeeping thins it out, and housekeeping works in weeks rather than months.

Your systems already wrote it down. We read it back.

Get the logs preserved before rotation reaches them — the freephone puts you through to an examiner rather than a queue.