An employee left and took your data?
A forensic investigation shows what they took and when.

People who leave for a competitor, or to start their own business, usually leave the evidence behind. It sits on the laptop they handed back, in their mailbox and in the cloud accounts they used at work. We examine those and date each finding. Every analysis is done in Australia, and the report is written so it can go to court.

Before you call

Do these 4 things today

Evidence is usually lost after the person has gone, when the laptop is reused or someone looks through it.

Put the laptop away

Do not reissue it, wipe it or send it back to the leasing company. Turn it off, lock it away and note who has handled it.

Do not look through it yourself

Logging in and opening files changes the dates the investigation relies on. That includes a quick look by your IT provider.

Keep the accounts

Block sign-in to their Microsoft 365 or Google Workspace account, but do not delete the account or remove its licence. Deleting it can start a deletion period for the mailbox and its history.

Write down the dates

When they resigned, their last day, when they returned equipment, and anything a client or colleague has told you since. The investigation starts from those dates.

Questions we answer

What the investigation shows

Each finding comes with the record it came from, so the other side can test it.

Files copied to a USB drive

Which drives were plugged in, when, and which files were opened or copied around those times.

Files uploaded or synced to personal cloud storage

Personal Dropbox, Google Drive or iCloud accounts used from the work laptop, and what was moved through them.

Emails forwarded to a personal address

Mail sent or auto-forwarded outside the business, including forwarding rules set up and removed before the last day.

Client lists and reports exported

Exports from CRM and business systems, reports run in the weeks before departure, and spreadsheets built from them.

Files deleted to hide what happened

Deleted files and folders recovered where the device still holds them, with the date each was removed.

Activity in the final weeks

A timeline across the laptop, mailbox and cloud accounts, so you can see what changed once they had resigned.

Case study

The salesperson who took the client list

A software company’s first forensic investigator found little. Our second examination found USB transfers and client data copied out of the CRM into spreadsheets. We also recovered reports the salesperson ran before leaving from old tape backups. The evidence went to the Federal Court and then to the Full Court on appeal, which said Matt O’Kane’s evidence “explained how that material was found and expressed an opinion as to what that meant” (Garner v Central Innovation Pty Limited [2022] FCAFC 64). Read the case study.

How it works

From the first call to the report

A short call

Tell us who left, when, and what you think went. We tell you what to preserve and what the examination can and cannot show.

A fixed price before we start

Priced per laptop, with the mailbox and cloud scan as an add-on. You agree the scope before any work begins.

Collection and examination

We image the laptop with forensic tools to AS ISO/IEC 27037 and NIST SP 800-86, with hash values and a chain of custody record. We examine the copy and leave the original untouched.

A findings report

Each finding in plain language, with the record behind it. If the matter goes to court, the findings can become an expert report and Matt O’Kane can give evidence.

Call before anyone touches the laptop

Employers, HR teams and their solicitors call us. Most departing employee matters are not emergencies, but evidence starts to be lost from the day the laptop is reused. Related: incident response and forensics and who investigates a data breach in Australia.