An employee left and took your data?
A forensic investigation shows what they took and when.
People who leave for a competitor, or to start their own business, usually leave the evidence behind. It sits on the laptop they handed back, in their mailbox and in the cloud accounts they used at work. We examine those and date each finding. Every analysis is done in Australia, and the report is written so it can go to court.
Before you call
Do these 4 things today
Evidence is usually lost after the person has gone, when the laptop is reused or someone looks through it.
Put the laptop away
Do not reissue it, wipe it or send it back to the leasing company. Turn it off, lock it away and note who has handled it.
Do not look through it yourself
Logging in and opening files changes the dates the investigation relies on. That includes a quick look by your IT provider.
Keep the accounts
Block sign-in to their Microsoft 365 or Google Workspace account, but do not delete the account or remove its licence. Deleting it can start a deletion period for the mailbox and its history.
Write down the dates
When they resigned, their last day, when they returned equipment, and anything a client or colleague has told you since. The investigation starts from those dates.
Questions we answer
What the investigation shows
Each finding comes with the record it came from, so the other side can test it.
Files copied to a USB drive
Which drives were plugged in, when, and which files were opened or copied around those times.
Files uploaded or synced to personal cloud storage
Personal Dropbox, Google Drive or iCloud accounts used from the work laptop, and what was moved through them.
Emails forwarded to a personal address
Mail sent or auto-forwarded outside the business, including forwarding rules set up and removed before the last day.
Client lists and reports exported
Exports from CRM and business systems, reports run in the weeks before departure, and spreadsheets built from them.
Files deleted to hide what happened
Deleted files and folders recovered where the device still holds them, with the date each was removed.
Activity in the final weeks
A timeline across the laptop, mailbox and cloud accounts, so you can see what changed once they had resigned.
Case study
The salesperson who took the client list
A software company’s first forensic investigator found little. Our second examination found USB transfers and client data copied out of the CRM into spreadsheets. We also recovered reports the salesperson ran before leaving from old tape backups. The evidence went to the Federal Court and then to the Full Court on appeal, which said Matt O’Kane’s evidence “explained how that material was found and expressed an opinion as to what that meant” (Garner v Central Innovation Pty Limited [2022] FCAFC 64). Read the case study.
How it works
From the first call to the report
A short call
Tell us who left, when, and what you think went. We tell you what to preserve and what the examination can and cannot show.
A fixed price before we start
Priced per laptop, with the mailbox and cloud scan as an add-on. You agree the scope before any work begins.
Collection and examination
We image the laptop with forensic tools to AS ISO/IEC 27037 and NIST SP 800-86, with hash values and a chain of custody record. We examine the copy and leave the original untouched.
A findings report
Each finding in plain language, with the record behind it. If the matter goes to court, the findings can become an expert report and Matt O’Kane can give evidence.
Call before anyone touches the laptop
Employers, HR teams and their solicitors call us. Most departing employee matters are not emergencies, but evidence starts to be lost from the day the laptop is reused. Related: incident response and forensics and who investigates a data breach in Australia.
