Very little of this is settled on a laptop. It is settled in racks: identity platform sign-in history, remote-access sessions, file server auditing, database export logs — records your own estate has been writing steadily without anybody asking it to. An endpoint contributes context and sometimes intention. The servers contribute the dates, which is the harder half. Most of the work is getting at those records before a retention policy quietly removes them.
◇ Ransomware is not this. It takes the media bands. Investigation examined and reported: £800 + VAT. Verified image with deleted material extracted, unreported: £400 + VAT, the recorder-disk figure. Diagnosis free, scope written first. Forensic work is one of the four exclusions from no fix, no fee. Recovery prices.
Departure is a payroll event; withdrawal of access is a technical one, and the space between them is where these cases sit. The mailbox is disabled and a VPN certificate is not. The domain account goes and a subscription billed to a different cost centre carries on. Shared logins that were never attached to a named person keep working, because nobody can say whose they were to remove. Keys and API tokens get copied rather than borrowed, so resetting a password does nothing whatever to them. Authentication logging speaks to all of that directly — which credential, from which address, at what hour, against which system — and a session dated after somebody's final working day is one of very few findings in this practice that is genuinely difficult to talk your way out of.
The reflex on discovery is to shut everything down, and the reflex is broadly right. Rotating credentials and revoking tokens governs what happens next, and it does not erase anything already written. The complication is indirect. A rotation can start a retention period running. Deleting an account can take its own sign-in history with it, which is a poor trade when that history was about to be the strongest exhibit in the file. Releasing a licence can close a mailbox export window. So the two jobs are done together: pull the authentication export while the passwords are being changed, hold the mailbox before the licence is released, image the endpoint before the reissue ticket moves. Where that did not happen, ask for the logs this week rather than after the next board meeting — the honest answer to what survives changes with the calendar and only in one direction.
Almost none of this requires a server to be taken out of service, still less shipped anywhere. What travels is an extract: log data, audit records and targeted copies, taken to a scope agreed beforehand and analysed against whatever endpoint material exists. Domain controller and identity provider sign-ins. Remote sessions with their source addresses. File server auditing on what was read and what was copied out. Query and export logs from the line-of-business database. Administrative and download records from whatever the firm runs as a service. Backup catalogues, which now and then hold a version of a share that has since been tidied. In the minority of cases where a physical disk does have to be examined, it comes on its own with its bay position marked on it, and rebuilding a failed array is a separate job on the ordinary media bands rather than investigation time.
Opening files is what employment consists of, so access by itself proves very little and a report that pretends otherwise gets taken apart. What actually distinguishes these cases is shape. Directory reads at a scale the role never called for, bunched around a resignation. An archive assembled over three consecutive evenings. The same folders revisited on the night before a laptop goes back. A browser session holding a competitor's careers page and a recruitment portal within the same half hour. Each of those has an innocent reading and the report acknowledges it. Dated and laid in sequence, they are usually the substance of the matter, and saying that plainly stands up in cross-examination far better than leaning on any single item.
Employers get this wrong in both directions, generally by assuming the answer is entirely one or entirely the other. A personal laptop somebody carried into the office is their property. It is not examined without their agreement, a protocol settled between solicitors, or a direction of the court, and paying for an examination does not change whose property it is. What is unambiguously yours is your own network's record of that machine: address leases, wireless association entries, switch port records, the hardware address, what it authenticated against and what it was able to reach. Presence, timing and reach can usually be established from those without the device being touched at all, and the report is explicit about the line where that evidence stops.
Handling and custody are set out on the forensic practice hub. Capturing an endpoint properly is workstation deep imaging, mailbox and tenancy activity is email and cloud exfiltration, and where what is at stake is designs, code or a customer database the version written for that is trade secret and IP theft.
Each of these is the moment an uneasy feeling turns into something somebody is willing to put in writing.
Nobody can give exact figures because retention is a licence and configuration question in every organisation. What can be said is the rough shape of it, and the shape is why the first hour of one of these instructions goes on working out which of these are still open:
Dates come from the servers and context comes from the endpoint, and each finding says which of the two it is standing on.
Tokens, keys and saved credential stores that travelled, each one dated.
Which systems those credentials opened, at what hour, from which address.
Share and database pulls out of all proportion, with the queries behind them.
Folder access at a volume the job never required, clustered near a departure.
Archives, print runs, messages and browsing that speak to what was intended.
What your network lawfully shows about a personal device, and nothing beyond it.
£800 + VAT is one system, one question, examined and reported. £400 + VAT is an image verified and stripped of its deleted material with no report attached, and that figure is shared with CCTV recorder disks and encrypted volumes rather than being a sixth band added for investigators. Both are agreed in advance, because forensic work is one of the four things published as sitting outside no fix, no fee, next to electronic and mechanical failure, chip-level work and DVR jobs. An authentication export that shows nothing took the same hours as one that shows everything.
Worth separating out on this page in particular: an encrypted server is not this product. Getting files back after a ransomware attack is media recovery on working hardware and takes the media bands — £300 + VAT a drive, from £500 + VAT an array or a server. Asking afterwards how the intruder got in and what left with them is a second instruction at £800 + VAT, scoped, quoted and invoiced on its own. Anything spanning more than one machine is measured in the free diagnostic, which costs nothing and closes two working days after booking in at Oxford, and written down before you commit.
An insider instruction runs on a company's own logs, systems and issued equipment, with that company's authority behind it or a solicitor's written instruction — and a court or an insurer instructing in writing counts the same way. The third route, a private client's own hardware, rarely arises in these matters. What is not available: a personal laptop that was merely present on your network, absent its owner's agreement, a protocol between solicitors or an order of the court. Nor is anybody's password defeated or worked out, nor monitoring software supplied, fitted or advised on, nor live traffic intercepted — the Investigatory Powers Act 2016 reserves that to bodies a private laboratory is not among. Instructing a laboratory does not manufacture a right of access. Phones and tablets are not examined here at all.
An insider instruction runs mostly on your own estate, so make the call to 0800 689 0668 before anything is switched off and we will agree the exports and the order they happen in. Where hardware does have to be examined, the disk travels and the machine stays racked. Nothing is collected anywhere in this network and Coventry has no counter: tracked and insured post to Oxford, or over the counter there in office hours.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.
Take the log export while you are rotating the passwords rather than the week after. One call will tell you which records are still worth asking your IT provider for.