The Brief
A senior employee had resigned and joined a direct competitor. Within a fortnight, the client noticed that two prospective tenders they had been quietly preparing were being competed for — accurately, and aggressively — by the new employer. The board needed to know whether confidential material had left the building, and if so, what, when, and by what route.
Our Approach
We executed a forensically sound acquisition of the departing employee's issued devices and a targeted review of cloud activity logs across the final 90 days of access. In parallel, our offensive security team conducted a controlled assessment of the data exfiltration paths the employee had access to — not to attribute, but to map what was technically possible. The two streams were then reconciled.
What We Found
Two specific document sets — one of them the tender material — had been synchronised to a personal cloud account in the final week of employment. The forensic record was unambiguous: filenames, timestamps, hashes and the offline-online sync events were all preserved. The control gap that allowed it was mapped and documented.
Outcome
The client's solicitors used the report to send a precisely scoped letter before action. The competitor returned and certified destruction of the relevant material under independent supervision, and the prospective tender process was re-set. In the hardening phase that followed, we closed the DLP gap, tightened off-boarding, and ran a tabletop exercise with the leadership team so the same pattern would be visible far earlier next time.
We expected a forensic report. We received a forensic report, a legal lever, and a quieter Monday morning. That is the order it should arrive in.— Board chair, anonymised