24/7 INCIDENT RESPONSE
(877) 259-0509

INSIDER THREAT & EMPLOYEE INVESTIGATIONS

Insider Threat Investigations
Built on Evidence.

Cyber Centaurs investigates suspected insider activity, employee data theft, unauthorized access, and misuse of company information. We preserve and analyze digital evidence to reconstruct user activity, trace data access and movement, evaluate disputed events, and develop defensible findings for organizations and counsel.

WHEN TO INVESTIGATE

When Trusted Access
Becomes a Question.

Insider investigations often begin with incomplete information: unusual file activity, a departing employee, unexpected access to sensitive information, or concern that company data may have been copied, transferred, or removed. The objective is to preserve the available record and determine what the evidence actually supports.

Departing Employee Activity

Suspected Data Copying or Removal

Unauthorized Access to Sensitive Information

Personal Email or Cloud Transfers

USB & External Storage Activity

Deletion or Alteration of Relevant Evidence

INVESTIGATIVE OBJECTIVES

Preserve the Record.
Establish the Activity.

An insider threat investigation should protect relevant evidence, reconstruct user activity, determine how information was accessed or moved, and distinguish supported findings from assumptions or incomplete allegations.

Preserve Evidence

Protect relevant computers, accounts, logs, communications, cloud records, storage media, and other evidence before unnecessary changes alter the record.

Reconstruct Activity

Develop timelines of relevant user actions across systems, files, accounts, applications, communications, and connected devices.

Trace Data Movement

Evaluate evidence of copying, downloads, uploads, email forwarding, cloud synchronization, archive creation, removable media, and other transfer activity.

Establish Findings

Document what the available evidence supports, identify limitations or unresolved questions, and provide findings appropriate for corporate, legal, or investigative decisions.

INSIDER INVESTIGATION EVIDENCE

Evidence Across the
Employee Environment.

Relevant evidence may exist across the employee's computer, company accounts, cloud platforms, communications, storage systems, and security telemetry. Cyber Centaurs correlates available sources to understand activity in context; endpoint-focused matters may require computer forensic examination of relevant systems.

Endpoint & Computer Activity

File-system artifacts

recent files

application activity

browser activity

user profiles

system logs

Cloud & Collaboration

Microsoft 365

Google Workspace

SharePoint

OneDrive

Dropbox

cloud audit activity

Email & Communications

Business email

message headers

attachments

forwarding activity

communications history

relevant metadata

USB & External Storage

connected devices

USB history

external drives

removable-media activity

file interaction

device identifiers

File Access & Data Movement

downloads

uploads

copy activity

archive creation

external sharing

synchronization activity

Identity & Security Telemetry

authentication activity

account access

VPN

EDR / XDR

security logs

privilege or access changes

INVESTIGATIVE QUESTIONS

What Does the Evidence
Actually Establish?

The purpose of an insider investigation is not to confirm a suspicion. It is to evaluate the available digital record and determine which conclusions are supported, which remain uncertain, and what activity can be reconstructed.

What Information Was Accessed?

Determine which files, folders, systems, mailboxes, cloud repositories, or other information sources are implicated by the available evidence.

Was Company Data Copied or Transferred?

Evaluate evidence of downloads, file copying, email forwarding, cloud synchronization, uploads, removable media, archive creation, or other transfer activity.

Where Did the Data Go?

Assess available evidence concerning personal email, cloud accounts, external storage, connected devices, remote systems, or other potential destinations.

When Did the Activity Occur?

Correlate timestamps and activity across systems to establish relevant sequences before, during, or after significant employment events.

Was Relevant Evidence Deleted or Altered?

Examine available artifacts for deletion, wiping, file modification, account changes, log loss, or other activity that may affect the evidentiary record.

Does the Evidence Support the Allegation?

Compare the digital record with reported events, business records, access expectations, witness accounts, and other relevant information to distinguish supported findings from assumption.

INSIDER THREAT INVESTIGATION PROCESS

A Disciplined Investigation
of User Activity.

The investigative process is structured to preserve evidence, identify relevant sources, reconstruct activity, correlate findings across systems, and communicate conclusions according to what the available record supports.

01

Define Scope & Preserve

Identify the investigative questions, relevant users, systems, accounts, time periods, and evidence sources, then preserve the available record.

02

Collect Evidence

Acquire relevant endpoint data, cloud records, communications, logs, storage media, security telemetry, and other authorized evidence.

03

Examine User Activity

Analyze file activity, applications, communications, account usage, connected devices, cloud activity, and other artifacts relevant to the matter.

04

Correlate & Reconstruct

Compare evidence across sources to develop timelines, trace data movement, evaluate disputed events, and test competing explanations.

05

Report & Advise

Document supported findings, evidentiary limitations, relevant timelines or exhibits, and conclusions for counsel, leadership, HR, investigators, or other authorized stakeholders.

INVESTIGATIVE FINDINGS

From User Activity to
Defensible Findings.

Individual forensic artifacts rarely answer an insider allegation by themselves. Cyber Centaurs correlates evidence across devices, accounts, communications, and data sources to establish relevant activity and explain what the available record does—and does not—support.

Reconstructed User Timelines

Chronologies of relevant access, file activity, communications, account usage, device connections, and other events.

Data Access Findings

Identification of relevant information accessed, opened, downloaded, modified, or otherwise implicated by the evidence.

Data Movement Findings

Analysis of evidence associated with copying, forwarding, synchronization, cloud transfer, removable media, external storage, or other movement.

Device & Account Activity

Findings concerning relevant computers, user accounts, applications, cloud services, connected devices, and authentication activity.

Evidence Preservation & Limitations

Documentation of preserved sources, unavailable evidence, retention limitations, conflicting artifacts, or other factors affecting conclusions.

Decision-Ready Reporting

Clear findings, timelines, supporting exhibits, and technical explanations appropriate for counsel, leadership, HR, or other authorized decision-makers.

WHY CYBER CENTAURS

Technical Depth.
Investigative Judgment.

Insider allegations require evidence, not assumptions.

Cyber Centaurs combines digital forensics, cybersecurity expertise, and investigative discipline to evaluate complex employee activity and provide organizations and counsel with findings grounded in the available digital record.

Digital Forensic Expertise

Technical examination across endpoints, accounts, cloud platforms, communications, storage media, and related evidence sources.

Evidence-Driven Methodology

Investigative conclusions are developed through preservation, examination, correlation, validation, and documentation of available evidence.

Support for Counsel, Leadership & HR

Findings are communicated clearly to legal counsel, executives, human resources, investigators, and other authorized stakeholders.

Defensible Investigation

The work is structured with attention to evidentiary integrity, technical support, documentation, and the scrutiny associated with disputed corporate or legal matters.

INSIDER THREAT FAQ

Practical Questions
Before Engagement.

Insider investigations often begin before the organization knows exactly what occurred or what evidence remains available. These questions address common considerations when employee activity, company data, or trusted access is in dispute.

When should an organization begin an insider threat investigation?

An investigation may be appropriate when there is credible concern about unusual access, suspected data copying, unauthorized use of company information, suspicious activity before or after an employee departure, or another event where digital evidence may help establish what occurred. The organization does not need to know the full scope before preserving relevant evidence and assessing investigative options.

Can you determine whether an employee copied company files?

In some matters, forensic artifacts may show that files were accessed, copied, downloaded, synchronized, archived, emailed, uploaded, or transferred to removable media or other locations. Whether specific copying can be conclusively established depends on the evidence retained by the relevant systems and devices.

Can you determine whether a USB drive or external device was used?

Computer forensic artifacts may identify connected USB or external storage devices and provide information about device history and relevant file activity. The extent to which specific transferred files can be established depends on the artifacts available from the computer, device, and other evidence sources.

Can you investigate files sent to personal email or cloud storage?

Yes. Depending on the available evidence and authorized scope, an investigation may examine business email, message activity, browser artifacts, cloud audit records, synchronization activity, endpoint evidence, and other sources associated with potential transfers to personal email or external cloud services.

Should we preserve an employee's computer after termination or resignation?

If the computer may contain relevant evidence, avoid unnecessary reimaging, reassignment, deletion, software installation, or other changes until preservation needs have been evaluated. Relevant cloud accounts, email, logs, and security telemetry may also require preservation.

Can you investigate a former employee after access has been disabled?

Potentially. Even after access is revoked, relevant evidence may remain on company computers, cloud platforms, email systems, security tools, logs, backups, storage systems, and other authorized sources. The available evidence depends on retention, system configuration, and subsequent activity.

Do you work with legal counsel and human resources?

Yes. Cyber Centaurs can support internal and outside counsel, executive leadership, human resources, corporate security, IT teams, and other authorized stakeholders. The investigative scope and communication process can be structured according to the needs of the matter.

Can an insider investigation be performed remotely?

Many investigations can begin remotely through secure collection of endpoint evidence, cloud records, email, logs, and other relevant sources. Some matters may require shipment of devices or on-site collection depending on the evidence, legal requirements, or technical circumstances.

CONFIDENTIAL INQUIRY

Speak With an
Insider Threat Investigator.

Tell us briefly about the suspected activity, the employee or user involved, the systems or information at issue, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.

Confidential inquiry. Please do not submit evidence, credentials, or sensitive files through this form.

DISCUSS AN INVESTIGATION

(877) 259-0509

Confidential Consultation