By Quinn Varcoe, Founder & CEO, SleuthX
Start here, before anything else
You have probably just found something: a large download the week before a resignation, a forwarded client list, a USB device in a log. The instinct is to confront the person or to have IT go through the laptop. Both make the problem worse.
Three things, in this order, and none of them takes long.
- Preserve the device. If the laptop has been returned, take it out of the equipment pool now and label it. Do not reimage it, do not lend it to the next hire, do not let anyone log in to check.
- Freeze the logs. Your file-share, email, and identity systems keep audit records on a retention clock that is often 90 days and sometimes 30. Export them or extend retention today. This is the evidence that most often vanishes, and it vanishes on a schedule rather than through anyone’s decision.
- Write down what you know. When you first noticed, who told you, who has had access to the device since, and what anyone has already done to it. This becomes the first page of the chain of custody.
What the evidence usually looks like
Departing-employee cases are rarely subtle, because the person is usually in a hurry and does not think of themselves as a thief. The recurring patterns are ordinary.
- Bulk download shortly before notice. A volume of file access far outside the person’s normal pattern, concentrated in a few days.
- Forwarding to a personal address. Often a handful of messages with attachments, sometimes an auto-forward rule left in place.
- Removable media. A USB device attached once, briefly, on a machine that has never seen one before.
- Cloud sync to a personal account. A second account signed in to a sync client, which moves a great deal of data without ever looking like a download.
Each of these leaves a record in more than one place, which is what makes the question answerable. A file-share log and a device artifact that tell the same story are much harder to argue with than either alone.
What is often innocent
It is worth saying plainly, because a wrong accusation is expensive in a different way. People take their own work samples. People sync a personal phone to a work calendar and never think about it. People download a folder in bulk because they are working on a plane. Volume alone is a reason to look, not a conclusion.
The distinction that usually matters is not how much was taken but what, and whether the pattern lines up with the departure. A designer keeping a portfolio and a salesperson taking the customer list two days before joining a competitor are different facts, and an examination can tell them apart.
What an examination will and will not settle
It will establish what was accessed, copied, forwarded, or attached, by which account, and when. Where the data went afterwards is often reachable and sometimes not, depending on whether it crossed into systems you control.
It will not tell you whether you have a legal claim. That depends on your agreements, your jurisdiction, and what the material actually was, and it is a question for an employment or trade-secrets attorney. We work alongside counsel routinely, and where an engagement is aimed at developing evidence for litigation it runs under the retaining attorney’s direction.
It will also not manufacture certainty. If the retention window closed before you looked, the honest finding is that the record no longer exists.
If you do nothing else
Take the returned laptop out of circulation and extend your audit-log retention. Those two steps cost almost nothing, take an afternoon, and preserve nearly everything that matters. The decision about whether to investigate can wait a week. The evidence cannot.
For the wider incident-handling picture, NIST SP 800-61r3 is the current guidance, and CISA’s Insider Threat Mitigation Guide is the standard reference for the preventive side.
Common questions
Should I confront the employee?
Can I look through their laptop myself?
What if they used their own phone or a personal cloud account?
Is taking company data actually illegal?
How quickly does the evidence disappear?
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.















