Staff hand in their notice, quietly move the customer base onto a memory stick or a private cloud account, then reset the laptop on the way out. We put the evidence back together for employers across Swansea, Llanelli, Neath and the wider South Wales area — free diagnostic and freephone advice first.
Discreet, documented, defensible. A free diagnostic and an agreed written scope come first; forensic work is payable upfront.
If your Swansea Bay business recognises any of these, set the machine aside and have it examined before anyone wipes or reissues it.
Ask any employment solicitor in Swansea or Cardiff and they will recognise the sequence: an employee about to leave spends the notice period harvesting documents, contact lists and pricing, moves them onto a stick or into a private cloud account, then hands the laptop back freshly reset. To the eye there is nothing left; to a forensic examiner there is plenty. A reset rarely destroys the deeper traces — the record of the wiping tool itself and the minute it ran, the flurry of file activity before departure, and a large share of the deleted documents, which can be carved straight back off the disk.
Few people realise how much Windows remembers about removable media. The registry's USBSTOR key logs the make, model and serial number of every stick and external drive ever attached; the setupapi log records when each was first plugged in; MountedDevices and MountPoints2 tie a device to the profile that used it. Around that sit shortcut (LNK) files and jump lists showing your documents being opened from a lettered removable drive, shellbags recording which folders on the stick were browsed, and the NTFS USN change journal noting file operations minute by minute. Stitched together, those artefacts convert a hunch into a dated, itemised account of what was taken.
Not every exfiltration involves hardware. We also reconstruct browser and webmail activity — attachments sent to private addresses, files pushed through transfer sites, and folders synchronised out to a personal OneDrive, Dropbox or Google Drive. Deleted messages are recovered from unallocated space and sync-client logs show what went up and when, so the report covers every route out of the business, not just the obvious one.
Procedure is what separates evidence from anecdote. The suspect drive is imaged behind a hardware write-blocker and the image verified against MD5 and SHA-256 hashes, so nobody can suggest it was altered. Every movement of the exhibit goes into a chain-of-custody log, the examination runs on OSForensics with Passware Kit Forensic brought in for password-protected material, and the finished report pairs plain-English findings with a technical appendix. It is written to survive cross-examination at an employment tribunal, and we are happy to follow directions agreed with your solicitor.
The imaging, hashing and custody discipline behind this page is set out on our forensic data recovery hub. Forensic work is payable upfront: a standard investigation with a detailed report is £800 + VAT, and a leaner £400 + VAT forensic binary-image and deleted-file extraction is available without the report — both appear on the data recovery cost page. If the returned laptop is encrypted, our BitLocker recovery service decrypts it with the recovery key before analysis begins.
From a company machine, these are the strands of evidence an examination typically pulls together.
Serial numbers and connection times for every stick and drive attached.
LNK and jump-list traces tying files to a removable drive letter.
Shellbag entries for directories opened on the device.
NTFS USN activity around the dates in question, minute by minute.
Webmail sends, transfer-site uploads and sync-client logs.
Carved documents plus the footprint of any erasing tool.
Company equipment is fair ground, as is a personal device where a signed policy or a solicitor's instruction provides the lawful basis; covert access to an ex-employee's private phone or home computer is something we will never undertake. In the meantime, treat the laptop as an exhibit: power it off, put it somewhere safe, and make sure IT does not rebuild or reissue it — a reinstall grinds away the very traces the case depends on.
Treat the device as an exhibit rather than a computer. Call 0800 689 0668 before sending anything and we will agree what to submit and how to package it — the chain of custody is logged from the moment it reaches our secure Bristol location.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Set the laptop aside and call the freephone — the earlier it is imaged, the more the evidence shows.