Data theft or breach: establishing what actually left
A departing employee, an exfiltration, a ransomware attack. We establish what left, when and through which channel — and document what has to be notified.
The signs
What raised the alarm
A breach is rarely witnessed as it happens. It is inferred from traces that prove nothing on their own and, put side by side, form a timeline.
A departure that raises questions
Bulk copies to a USB stick or a personal cloud account in the days before a resignation, a dismissal or the end of a contract.
Your data surfaces elsewhere
A competitor knows your prices, your client list is circulating, an internal document is produced in proceedings.
A technical alert
A sign-in from an unusual country, abnormal outbound volume, a forwarding rule created in a mailbox, an unknown service account.
A ransom demand
Encrypted files, an extortion message, a threat to publish on a leak site.
A useful distinction: encryption by ransomware says nothing about whether the data was copied beforehand. That is a separate question, and it is the one that determines your notification duties.
The examination
What we look for, in practice
Media are copied first and examined on those copies. Your systems stay available — which is what makes the findings verifiable without bringing the business to a halt.
01
Exfiltration
USB devices connected, transfers to a cloud account or personal mailbox, large uploads, archives created and then deleted.
02
Point of entry
Compromised account, phishing, exposed remote access, exploited vulnerability, persistence through an account or a scheduled task.
03
Scope of the data
Which files, which databases, how many data subjects and which categories — the answer drives the notification.
04
Timeline
System logs, authentications, cloud history, timestamps: an ordered reconstruction, from first access to last.
05
Erased traces
Purged logs, emptied recycle bins, deleted or backdated files, while the media still allow them to be recovered.
06
The report
Findings, method, SHA-256 hashes and chain of custody. Written to be read by a judge, an insurer or the data protection authority.
In the meantime: preserve the evidence
Strictly avoid
- Reinstalling the machine or server concerned, or restoring it from a backup.
- Letting logs expire: many are kept for only a few days.
- Deleting the suspected person's account, or reassigning their equipment.
- Paying a ransom before establishing what actually left.
Do this
- Isolate from the network without powering down: volatile memory holds traces that vanish at shutdown.
- Freeze existing logs and backups, and extend their retention.
- Record who did what, and at what time, since the discovery.
- Note the time of discovery: the 72-hour notification deadline runs from that moment.
How it unfolds
How an investigation works
-
1
First conversation
You set out the facts, we ask the right questions and tell you what can still be established.
-
2
Freezing the traces
Copies of media and logs, SHA-256 hashes, handover record. On site or at our office.
-
3
Analysis
Reconstruction of the timeline and the scope, on the copies. Your systems stay in service.
-
4
Report and next steps
Delivery of the signed report, support for the notification, the complaint, the insurer or the proceedings.
Frequently asked
Frequently asked questions about data theft
Must I notify the data protection authority?
If the breach involves personal data and poses a risk to the people concerned, yes — within 72 hours of becoming aware of it. Our findings document what actually leaked, which is the piece most notifications are missing.
Can it be proved that a former employee copied files?
Often, yes: USB connections, transfers, file openings and timestamps leave durable traces — provided the machine has not been reassigned or reinstalled.
Do the servers have to be shut down?
No. Isolating them from the network is usually enough, and powering down destroys volatile memory. We work on copies so your business keeps running.
What if the logs are already gone?
There is almost always something else: workstations, cloud logs, backups, network equipment. We will tell you plainly what can still be established, and what cannot.
Have the incident examined
First conversation free and confidential. We will tell you plainly what can still be established, and how quickly.
- Professional secrecy
- Quote before any work
- Court-registered expert