Insider Threat and Access That Outlived the Job

Very little of this is settled on a laptop. It is settled in racks: identity platform sign-in history, remote-access sessions, file server auditing, database export logs — records your own estate has been writing steadily without anybody asking it to. An endpoint contributes context and sometimes intention. The servers contribute the dates, which is the harder half. Most of the work is getting at those records before a retention policy quietly removes them.

Ransomware is not this. It takes the media bands. Investigation examined and reported: £800 + VAT. Verified image with deleted material extracted, unreported: £400 + VAT, the recorder-disk figure. Diagnosis free, scope written first. Forensic work is one of the four exclusions from no fix, no fee. Recovery prices.

Someone left on Friday. Which of their credentials knows that?

Departure is a payroll event; withdrawal of access is a technical one, and the space between them is where these cases sit. The mailbox is disabled and a VPN certificate is not. The domain account goes and a subscription billed to a different cost centre carries on. Shared logins that were never attached to a named person keep working, because nobody can say whose they were to remove. Keys and API tokens get copied rather than borrowed, so resetting a password does nothing whatever to them. Authentication logging speaks to all of that directly — which credential, from which address, at what hour, against which system — and a session dated after somebody's final working day is one of very few findings in this practice that is genuinely difficult to talk your way out of.

Containment and evidence want doing in the same hour, not in turn

The reflex on discovery is to shut everything down, and the reflex is broadly right. Rotating credentials and revoking tokens governs what happens next, and it does not erase anything already written. The complication is indirect. A rotation can start a retention period running. Deleting an account can take its own sign-in history with it, which is a poor trade when that history was about to be the strongest exhibit in the file. Releasing a licence can close a mailbox export window. So the two jobs are done together: pull the authentication export while the passwords are being changed, hold the mailbox before the licence is released, image the endpoint before the reissue ticket moves. Where that did not happen, ask for the logs this week rather than after the next board meeting — the honest answer to what survives changes with the calendar and only in one direction.

Nothing leaves the rack, and that surprises people

Almost none of this requires a server to be taken out of service, still less shipped anywhere. What travels is an extract: log data, audit records and targeted copies, taken to a scope agreed beforehand and analysed against whatever endpoint material exists. Domain controller and identity provider sign-ins. Remote sessions with their source addresses. File server auditing on what was read and what was copied out. Query and export logs from the line-of-business database. Administrative and download records from whatever the firm runs as a service. Backup catalogues, which now and then hold a version of a share that has since been tidied. In the minority of cases where a physical disk does have to be examined, it comes on its own with its bay position marked on it, and rebuilding a failed array is a separate job on the ordinary media bands rather than investigation time.

A shape, not an accusation

Opening files is what employment consists of, so access by itself proves very little and a report that pretends otherwise gets taken apart. What actually distinguishes these cases is shape. Directory reads at a scale the role never called for, bunched around a resignation. An archive assembled over three consecutive evenings. The same folders revisited on the night before a laptop goes back. A browser session holding a competitor's careers page and a recruitment portal within the same half hour. Each of those has an innocent reading and the report acknowledges it. Dated and laid in sequence, they are usually the substance of the matter, and saying that plainly stands up in cross-examination far better than leaning on any single item.

Kit the business does not own, sitting on a network the business does

Employers get this wrong in both directions, generally by assuming the answer is entirely one or entirely the other. A personal laptop somebody carried into the office is their property. It is not examined without their agreement, a protocol settled between solicitors, or a direction of the court, and paying for an examination does not change whose property it is. What is unambiguously yours is your own network's record of that machine: address leases, wireless association entries, switch port records, the hardware address, what it authenticated against and what it was able to reach. Presence, timing and reach can usually be established from those without the device being touched at all, and the report is explicit about the line where that evidence stops.

Handling and custody are set out on the forensic practice hub. Capturing an endpoint properly is workstation deep imaging, mailbox and tenancy activity is email and cloud exfiltration, and where what is at stake is designs, code or a customer database the version written for that is trade secret and IP theft.

// what usually starts one of these

When a suspicion becomes an instruction

Each of these is the moment an uneasy feeling turns into something somebody is willing to put in writing.

Authentication entries dated after a leaver's last day on the payroll
Tokens, keys or a saved credential store that appear to have travelled
Database extracts at a size no routine business process would generate
An archive built up over several consecutive evenings in one week
Recruitment sites and one particular rival, together in a browser history
Something on the office wireless matching nothing on the asset register
// how long each record lasts, roughly

The windows that are closing while you decide

Nobody can give exact figures because retention is a licence and configuration question in every organisation. What can be said is the rough shape of it, and the shape is why the first hour of one of these instructions goes on working out which of these are still open:

  • Identity platform sign-in history — weeks to months, entirely dependent on the licence tier you happen to hold.
  • Firewall, VPN and remote-access logs — often days, unless somebody arranged for them to be shipped somewhere central.
  • File server auditing — exists at all only where it was deliberately switched on, which is a minority of the estates seen here.
  • Database query and export logging — highly variable, and frequently the first thing disabled when a server ran short of disk.
  • Mailbox and tenancy audit records — a defined window that starts running whether or not anybody is watching it.
  • Backup catalogues — sometimes the longest reach of the lot, and routinely forgotten because nobody thinks of a backup as a log.
// the pillars of an insider case

Six lines of evidence, run together

Dates come from the servers and context comes from the endpoint, and each finding says which of the two it is standing on.

Credentials that moved

Tokens, keys and saved credential stores that travelled, each one dated.

How far they reached

Which systems those credentials opened, at what hour, from which address.

Extraction at scale

Share and database pulls out of all proportion, with the queries behind them.

Reading past the role

Folder access at a volume the job never required, clustered near a departure.

Groundwork

Archives, print runs, messages and browsing that speak to what was intended.

The boundary

What your network lawfully shows about a personal device, and nothing beyond it.

// the fee, and who may lawfully ask for it

What it costs, and the authority it stands on

What is charged, and what is not charged as this

£800 + VAT is one system, one question, examined and reported. £400 + VAT is an image verified and stripped of its deleted material with no report attached, and that figure is shared with CCTV recorder disks and encrypted volumes rather than being a sixth band added for investigators. Both are agreed in advance, because forensic work is one of the four things published as sitting outside no fix, no fee, next to electronic and mechanical failure, chip-level work and DVR jobs. An authentication export that shows nothing took the same hours as one that shows everything.

£800 + VATLogs, endpoint and account history read together and written up, with each finding tied to the system that recorded it and the date it carries.
£400 + VATImage, verify, extract, hand over. No analysis. The recorder-disk figure rather than a tier of its own.

Worth separating out on this page in particular: an encrypted server is not this product. Getting files back after a ransomware attack is media recovery on working hardware and takes the media bands — £300 + VAT a drive, from £500 + VAT an array or a server. Asking afterwards how the intruder got in and what left with them is a second instruction at £800 + VAT, scoped, quoted and invoiced on its own. Anything spanning more than one machine is measured in the free diagnostic, which costs nothing and closes two working days after booking in at Oxford, and written down before you commit.

Your logs, your systems, your issued hardware

An insider instruction runs on a company's own logs, systems and issued equipment, with that company's authority behind it or a solicitor's written instruction — and a court or an insurer instructing in writing counts the same way. The third route, a private client's own hardware, rarely arises in these matters. What is not available: a personal laptop that was merely present on your network, absent its owner's agreement, a protocol between solicitors or an order of the court. Nor is anybody's password defeated or worked out, nor monitoring software supplied, fitted or advised on, nor live traffic intercepted — the Investigatory Powers Act 2016 reserves that to bodies a private laboratory is not among. Instructing a laboratory does not manufacture a right of access. Phones and tablets are not examined here at all.

// insider work — put to us on the first call

What employers want settled about access

It is among the firmest findings this work produces, and it needs two things put side by side. The leaving date, which comes off the payroll record and is not in dispute. And the authentication history, which gives the credential used, the source address and the hour. After that the question becomes which system the session actually reached and what it did inside. One caution about sequence: get the export taken before anything is revoked, because deleting an account occasionally takes its own sign-in history away with it.
Usually, yes, though the answer changes shape. Auditing on a file server is switched on in a minority of the estates seen here, so the account gets built from what does exist: identity platform sign-ins, remote-access sessions, mailbox and tenancy records, database export logs, backup catalogues and whatever the endpoint is still holding. The first conversation is spent working out which of those you have rather than which you wish you had, and you will be told plainly if the honest answer is that too little survives to be worth the fee.
The machine itself, no — not absent their agreement, a solicitors' protocol or a court direction. It is their property and instructing a laboratory does not alter that. Your network's observations of it are a different matter and are usually the more practical route in any case: address leases, wireless association entries, switch port records, the hardware address, and every system the device authenticated against. Presence, timing and reach generally come out of those without anybody touching the device.
No, and containment was the right call. Changing credentials governs the future and leaves the past exactly as it was already recorded. The only risk is second-order: a rotation can set a retention period running or push a log over, which is the argument for taking the authentication export at the same time rather than afterwards. If that did not happen, request the logs immediately — every week of delay narrows what can be asked for.
Those are two different purchases and it is worth being clear which one you are making. Getting the files back is media recovery on hardware that is generally healthy, priced on the ordinary bands — £300 + VAT a drive, from £500 + VAT an array or a server — and it is never billed as forensic work here. Establishing how the intruder arrived, what they were able to reach and what went out with them is an investigation at £800 + VAT, scoped and invoiced separately. Plenty of incidents want both. They are still quoted as two.
Very seldom. What leaves the building is an export — log extracts, audit data and targeted copies against a scope agreed in advance — while the machine stays racked and running. Where a disk does genuinely have to be examined it travels by itself with its bay position written on it. And if the array has failed rather than been interfered with, that is ordinary recovery work on the media bands, not an investigation.
// getting your media to Oxford

Posting a device in — what goes in the box

An insider instruction runs mostly on your own estate, so make the call to 0800 689 0668 before anything is switched off and we will agree the exports and the order they happen in. Where hardware does have to be examined, the disk travels and the machine stays racked. Nothing is collected anywhere in this network and Coventry has no counter: tracked and insured post to Oxford, or over the counter there in office hours.

As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.

  • Use a box or padded mailer with some rigidity to it, and pack around the drive until nothing shifts when the parcel is tilted. Mains adaptors, docks and leads are not wanted at this end.
  • Sending a RAID or a server? Only the member disks travel — not the chassis, not the controller — and each one wants its bay number written on it. Take a photograph of the front of the unit before anything is pulled; it costs nothing and now and again it saves a day.
  • Print the shipping and booking-in form (PDF), add a name, a number you will answer and a sentence on how the trouble began, and drop it in beside the media.
  • Most people use Special Delivery, which is tracked and covered; a courier of your own does the same job. You can also bring it: the Oxford reception takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Coventry counter nor a collection round exists.
// write this on the label

Oxford Data Recovery

John Eccles House
Oxford Science Park
Robert Robinson Avenue
Littlemore, Oxford, OX4 4GP

↓ Print the shipping & booking-in form (PDF)

Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.

Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.

Your own systems wrote it down. We read it back.

Take the log export while you are rotating the passwords rather than the week after. One call will tell you which records are still worth asking your IT provider for.