Investigating an incident at your company
A departed employee who still had access, data that went out of the door, or a system somebody got into. We work out what happened.
What we examine
- Who had access to what and when, and whether that access matched the role.
- Which data was accessed, copied or sent, and where to.
- Whether accounts or access remained after somebody left.
- How somebody got in, and whether that same route is still open.
- What the logs still hold, and how long they are kept.
What you receive
A report with a timeline of what happened, supported by the record.
A list of what has to be closed now, separated from what can be tidied up later.
The technical basis you need for a notification, a police report, or a conversation with your insurer.
What we do not do
- We do not conduct staff investigations and do not question employees. We examine systems, not people.
- We do not advise on employment law.
- We cannot establish what happened in periods for which no logs remain, and we write it up that way.
Do not rebuild systems or wipe anything before it has been looked at. It is an understandable first reaction, and it frequently makes investigation impossible.
Tell us what you are seeing. We will take it from there.