Skip to content
DataForensics Book an AppointmentBook Now

Digital Forensics

Suspect a partner or director is taking your data? We can prove it — or rule it out.

Partners and directors carry the widest access in a business and the least day-to-day oversight. When sensitive data goes missing, our in-house lab establishes what was taken, when, and by whom — with evidence built to stand up in court.

I.

Why this is different

Insider access is the hardest kind to police.

Most data protection is built to keep outsiders out. It does little against someone who is already trusted with the keys.

A director or business partner rarely needs to "hack" anything. Client lists, financials, supplier terms and product designs are often already open to them — through their own login, on their own laptop, in their own inbox.

  • Timing is often the first clue. A sudden resignation, a new competing venture, or a dispute between partners frequently follows months of quiet copying.
  • Deletion is not disqualifying. Files removed from a laptop, phone or shared drive routinely leave a forensic trail even when the files themselves are gone.
  • Personal devices and accounts count. A company laptop synced to a personal cloud account, or a BYOD phone, can carry as much evidential value as anything on the office network.

This is one of the most common instructions we receive as part of our wider digital forensics & eDiscovery work — and it needs to be handled quickly, quietly, and correctly from the first step.

II.

What we examine

The trail a departing partner leaves behind.

i

Laptops & Desktops

Forensic imaging surfaces deleted files, connected USB history and recently accessed folders — even after an attempt to tidy up.

ii

Email & Cloud Accounts

Outlook, Microsoft 365 and Google Workspace logs can show forwarding rules, bulk downloads and unfamiliar sign-in locations.

iii

USB & External Storage

Connection logs on a device record exactly which USB drives were plugged in and when — whether or not the drive is ever found.

iv

Mobile Phones

Company or personal phones can hold messaging activity, file-sharing app history and photographs of screens used to bypass controls.

v

File Servers & Shared Drives

Access and version history show who opened, copied or moved specific files, and precisely when it happened.

vi

Cloud Storage & File Transfers

Dropbox, Google Drive, OneDrive and similar services leave records of unusual or bulk uploads ahead of a resignation.

III.

Process

A quiet, forensically sound investigation.

  1. 01

    Confidential consultation

    Speak to a specialist in strict confidence. We assess what evidence is likely to exist and the best route forward — before anything is done that could alert the individual concerned.

  2. 02

    Forensic imaging & preservation

    Devices and accounts are imaged under a documented chain of custody, so the original data — and its evidential value — is preserved untouched.

  3. 03

    Expert analysis

    We examine file access, deletion, transfer and communication activity across every relevant device and account to build a clear, factual timeline.

  4. 04

    Expert report

    Findings are set out in a report written for directors, solicitors and, where needed, a court — with the underlying evidence to support every conclusion.

IV.

Questions

What business owners ask us.

What are the warning signs of a partner or director taking data?

A sudden resignation, an unexplained new competing venture, unusual after-hours system access, USB drives appearing in logs that were never declared, or a personal cloud account newly syncing to a company device are all common triggers for an instruction like this.

Can you investigate without the person knowing?

Yes. Forensic imaging of a device or account can normally be carried out discreetly, without alerting the individual concerned, which matters if you need to preserve evidence before confronting them or taking formal action.

Will the evidence hold up in court or an employment tribunal?

Our work follows a documented chain of custody from the moment a device or account is received, so findings are presented in a form recognised by courts and tribunals, and we routinely support the solicitors running the case.

What if they have already deleted files or wiped a device?

Deleted material is very often still recoverable, and even where the files themselves cannot be restored, records of what was accessed, copied or transferred frequently survive. Send devices as-is and we will give you an honest assessment.

Do you work directly with solicitors and corporate clients?

Yes, routinely. We support solicitors, directors and insurers through disputes exactly like this — from initial evidence preservation through to a court-ready report. See examples in our case studies.

Confidential consultation
Think you already know the answer?

Speak to a specialist in strict confidence and find out what the evidence can prove — before you act.