Page 1
EMPLOYEEDATATHEFT · A GUIDE FOR UK LAWYERS Investigating Suspected Employee Data Theft From First Suspicion to Springboard Relief: The Forensic Investigation Done Right COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM INJUNCTION-SPEED REPORTING CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: exits leave trails, and panic destroys them 03 First response: triggers, containment and what not to touch 04 The exfiltration-artefact map: USB, cloud, email, print and beyond 05 Lawful investigation: UK GDPR, monitoring rules and employment process 06 Attribution, quantification and the choreography timeline 07 Legal deployment: undertakings, delivery-up and springboard relief 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: PRESERVEFIRST, INVESTIGATELAWFULLY, BUILDTHE CHOREOGRAPHY, ANDMOVEFAST: DATA - THEFTCASESAREWONBYTHEQUALITYOF THEFIRSTFORTNIGHT ' SFORENSICSANDLOSTBYTHEITDEPARTMENT ' SFIRST AFTER NO ON
§ 02 · FIRST PRINCIPLES The problem in plain English: exits leave trails, and panic destroys them
§ 03 · THE FIRST RESPONSE First response: triggers, containment and what not to touch
Page 2
§ 04 · THETRAIL The exfiltration-artefact map: USB, cloud, email, print and beyond
§ 05 · INSIDETHELAW Lawful investigation: UK GDPR, monitoring rules and employment process
§ 06 · THECASEASSEMBLED Attribution, quantification and the choreography timeline
§ 07 · INTO COURT Legal deployment: undertakings, delivery-up and springboard relief
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE SYSTEM ESTATES (
§ 7 END POINT PLATFORM NETWORK / PHYSICAL IMAGE AUDIT LOGS PROXY LAYER MAIL- COUNTERPART RECORDS ROUTES)
Page 3
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THESUNDAYHARVESTANDTHEMONDAYRESIGNATION EXAMPLE2 · THELOOK - AROUNDTHATNEARLYLOSTTHECASE EXAMPLE3 · THEARTEFACTSTHATTOLDANINNOCENTSTORY
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent (the former employee / new employer) Ask your e Discovery / forensic provider LETTER )
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The exit-investigation checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions We suspect a departing employee right now. What are the first three actions? Can we search a leaver's work email and files without their consent? The employee used their personal Dropbox and phone. Can we get at those? What is springboard relief and why the urgency? Our IT team already went through the laptop. Is the case dead? What if the artefacts have an innocent explanation?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
Page 4
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab 35 reports produced on injunction timetables and independent-examiner structures offered where personal Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, Investigating Suspected Employee Data Theft, Computer Forensics Lab, https://e-discovery.uk/library/investigating-suspected-employee-data-theft/pdf.
