ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Employment / trade secrets / insider risk

Preserve the record before offboarding rewrites it

Account suspension, device reissue, remote wipe, and retention timers can erase the history needed to assess copying, deletion, or unauthorized access.

Chain-of-custody workflow from source identification through preservation, examination, and reporting
Custody records preserve what was collected before accounts, devices, and access change.

Departures create two competing pressures: secure the environment quickly and retain the technical record. GDF coordinates with counsel and IT to preserve relevant devices, accounts, file repositories, access events, email, collaboration data, and removable-media history before ordinary offboarding changes the source.

A preservation hold that IT can execute

The plan identifies laptops, phones, virtual desktops, mailboxes, cloud drives, shared repositories, development platforms, backup sources, and security logs. It distinguishes actions that should happen immediately from actions that can wait for imaging or export. The objective is to reduce ongoing access without destroying useful historical data.

Counsel defines legal scope and privilege. GDF documents technical sources and implements the approved protocol. Human resources and security teams receive a concise preservation checklist rather than a generic instruction to save everything.

Activity examined in context

USB connections, archive creation, bulk file access, personal cloud synchronization, email forwarding, code-repository activity, deletion, remote sessions, and authentication events may be relevant. None is treated as misconduct by itself. Analysts compare the activity with job duties, ordinary workflow, timing, file sensitivity, and corroborating records.

  • Rapid laptop and cloud-account preservation
  • File-access, copy, deletion, and transfer timelines
  • Personal email, USB, browser, and sync-service artifacts where in scope
  • Source-code and repository activity analysis
  • Reports and declarations prepared under counsel's direction

Findings that separate fact from suspicion

The deliverable identifies what happened, the source supporting it, and the limits of attribution. It avoids inferring intent from a single technical event. If a gap can be addressed through a server log, administrator record, or third-party subpoena, that next source is identified.

Preserve a departing employee record

Tell us what is disputed, which devices or systems may hold the answer, and the next deadline. Counsel retains all legal decisions.

Contact GDF