Active Incident? 24/7 Response →

For Business Owners

An Employee May Have Taken Data

What to preserve in the first days, what destroys the evidence, and how to tell a real problem from a resignation that merely looks like one.

By Quinn Varcoe, Founder & CEO, SleuthX

Start here, before anything else

You have probably just found something: a large download the week before a resignation, a forwarded client list, a USB device in a log. The instinct is to confront the person or to have IT go through the laptop. Both make the problem worse.

Three things, in this order, and none of them takes long.

  1. Preserve the device. If the laptop has been returned, take it out of the equipment pool now and label it. Do not reimage it, do not lend it to the next hire, do not let anyone log in to check.
  2. Freeze the logs. Your file-share, email, and identity systems keep audit records on a retention clock that is often 90 days and sometimes 30. Export them or extend retention today. This is the evidence that most often vanishes, and it vanishes on a schedule rather than through anyone’s decision.
  3. Write down what you know. When you first noticed, who told you, who has had access to the device since, and what anyone has already done to it. This becomes the first page of the chain of custody.

What the evidence usually looks like

Departing-employee cases are rarely subtle, because the person is usually in a hurry and does not think of themselves as a thief. The recurring patterns are ordinary.

Each of these leaves a record in more than one place, which is what makes the question answerable. A file-share log and a device artifact that tell the same story are much harder to argue with than either alone.

What is often innocent

It is worth saying plainly, because a wrong accusation is expensive in a different way. People take their own work samples. People sync a personal phone to a work calendar and never think about it. People download a folder in bulk because they are working on a plane. Volume alone is a reason to look, not a conclusion.

The distinction that usually matters is not how much was taken but what, and whether the pattern lines up with the departure. A designer keeping a portfolio and a salesperson taking the customer list two days before joining a competitor are different facts, and an examination can tell them apart.

What an examination will and will not settle

It will establish what was accessed, copied, forwarded, or attached, by which account, and when. Where the data went afterwards is often reachable and sometimes not, depending on whether it crossed into systems you control.

It will not tell you whether you have a legal claim. That depends on your agreements, your jurisdiction, and what the material actually was, and it is a question for an employment or trade-secrets attorney. We work alongside counsel routinely, and where an engagement is aimed at developing evidence for litigation it runs under the retaining attorney’s direction.

It will also not manufacture certainty. If the retention window closed before you looked, the honest finding is that the record no longer exists.

If you do nothing else

Take the returned laptop out of circulation and extend your audit-log retention. Those two steps cost almost nothing, take an afternoon, and preserve nearly everything that matters. The decision about whether to investigate can wait a week. The evidence cannot.

For the wider incident-handling picture, NIST SP 800-61r3 is the current guidance, and CISA’s Insider Threat Mitigation Guide is the standard reference for the preventive side.

Common questions

Should I confront the employee?
Not before you have preserved the evidence, and usually not before you have taken advice. A confrontation tells the person exactly what you know and gives them a reason to delete things, including from personal accounts and devices you cannot reach. If they are still employed and still have access, the sequence that protects you is preserve, then restrict access, then talk.
Can I look through their laptop myself?
You can, and it is one of the more expensive things you can do. Browsing a machine changes access timestamps, and an opposing expert will point out that the person with a motive was alone with the evidence before anyone recorded its state. If you need to know something urgently, note what you did and when, so it can be accounted for later rather than discovered later.
What if they used their own phone or a personal cloud account?
That is common, and it narrows what you can reach directly. What you usually can reach is your own side of the transaction: your email logs showing what was forwarded, your file-share audit records showing what was downloaded and when, and your endpoint records showing what devices were attached. Personal devices generally come into scope only through a legal process, which is a question for counsel rather than for us.
Is taking company data actually illegal?
It depends on what was taken, how, and where you are, and it is genuinely a question for an employment or trade-secrets attorney rather than a forensic examiner. What we can tell you is what the evidence shows: what was accessed, copied, or transmitted, when, and by which account. Whether that supports a claim is the lawyer's call, and a report that is careful about the difference is more useful to them than one that overstates.
How quickly does the evidence disappear?
Faster than most people expect. Cloud audit logs commonly retain for 90 days on standard plans and sometimes 30. Endpoint telemetry is often shorter. If the laptop goes back into the equipment pool and gets reimaged for the next hire, the device evidence is gone entirely. The practical window is weeks, not months, and it starts closing the day they leave.

What this means for you

Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management