Every organisation has a version of this moment — suspicion. Documents moving when they shouldn’t. Conversations travelling beyond the only people who should have known. Things that may be happening internally. But can that suspicion be backed?
A client came to SIAGA Informatics with exactly this situation. They believed company information was leaving the organisation. They believed it was moving from the inside — from a team with privileged access to company systems.
SIAGA’s Digital Forensics and Incident Response (DFIR) team was engaged to determine whether company information had indeed been accessed or handled in an unauthorised manner.
The scope covered several endpoint devices assigned to that team, across more than one operating system. Each device was forensically acquired and analysed under a defined chain of custody. But when the devices under examination belong to users with elevated privileges, an investigation cannot rely on the obvious.
So SIAGA went to the places that are hardest to tidy up: user activity artefacts, browser artefacts, email access records, and the small operational traces a system writes while nobody is watching.
Many underestimate what a computer remembers. Modern operating systems and browsers keep a continuous, low-level account of their own existence. Which tabs sat beside which other tabs. Which windows were open. What was restored after a restart. When a session began, and when it ended. These records were never designed to be evidence — but in the right hands, that is exactly what they become.
Our team used Oxygen Forensic Detective, a solution more commonly applied to mobile and cloud data. Applied to one of the devices, it surfaced something notable: timestamps for every tab opened and visited. From there we read the patterns of movement, and the sequence began to explain itself. Our analysis established that one of the devices had accessed a mailbox belonging to another member of staff.
That is the discipline of digital forensics: not finding a confession, but reading the residue of ordinary behaviour closely enough that the event reconstructs itself.
The forensic findings determined that:
- The mailbox was accessed from a device not assigned to the account holder
- No evidence indicated that the access was authorised, operationally required, or carried out under instruction from managemen
- Browser artefacts allowed our analysts to reconstruct the user’s activity in sequence, including the timestamps attached to individual browser tab
- The reconstructed timeline allowed investigators to correlate device activity against specific instances of mailbox access, minute by minute
Evidence was preserved in accordance with digital forensic best practice. The client received a clear, evidence-based account of what had taken place on the device — what was accessed, from where, and in what order. That gave them defensible ground on which to make their internal investigation and response decisions.
In a suspected data leak, the priority is to contain the incident, secure affected systems, and begin a forensic investigation to establish the scope and the source. Just as important is taking proactive steps so it does not happen in the first place.
Learn more about how we can support you during a data leak — and how to prepare your organisation before an incident happens. SIAGA Informatics provides end-to-end support, from forensic analysis and incident response to risk assessment and training, keeping your organisation resilient and ready.










