INSIDER THREAT & EMPLOYEE INVESTIGATIONS
Insider Threat Investigations
Built on Evidence.
Cyber Centaurs investigates suspected insider activity, employee data theft, unauthorized access, and misuse of company information. We preserve and analyze digital evidence to reconstruct user activity, trace data access and movement, evaluate disputed events, and develop defensible findings for organizations and counsel.
Confidential Consultation
WHEN TO INVESTIGATE
When Trusted Access
Becomes a Question.
Insider investigations often begin with incomplete information: unusual file activity, a departing employee, unexpected access to sensitive information, or concern that company data may have been copied, transferred, or removed. The objective is to preserve the available record and determine what the evidence actually supports.
Departing Employee Activity
Suspected Data Copying or Removal
Unauthorized Access to Sensitive Information
Personal Email or Cloud Transfers
USB & External Storage Activity
Deletion or Alteration of Relevant Evidence
INVESTIGATIVE OBJECTIVES
Preserve the Record.
Establish the Activity.
An insider threat investigation should protect relevant evidence, reconstruct user activity, determine how information was accessed or moved, and distinguish supported findings from assumptions or incomplete allegations.
Preserve Evidence
Protect relevant computers, accounts, logs, communications, cloud records, storage media, and other evidence before unnecessary changes alter the record.
Reconstruct Activity
Develop timelines of relevant user actions across systems, files, accounts, applications, communications, and connected devices.
Trace Data Movement
Evaluate evidence of copying, downloads, uploads, email forwarding, cloud synchronization, archive creation, removable media, and other transfer activity.
Establish Findings
Document what the available evidence supports, identify limitations or unresolved questions, and provide findings appropriate for corporate, legal, or investigative decisions.
INSIDER INVESTIGATION EVIDENCE
Evidence Across the
Employee Environment.
Relevant evidence may exist across the employee's computer, company accounts, cloud platforms, communications, storage systems, and security telemetry. Cyber Centaurs correlates available sources to understand activity in context; endpoint-focused matters may require computer forensic examination of relevant systems.
Endpoint & Computer Activity
File-system artifacts
recent files
application activity
browser activity
user profiles
system logs
Cloud & Collaboration
Microsoft 365
Google Workspace
SharePoint
OneDrive
Dropbox
cloud audit activity
Email & Communications
Business email
message headers
attachments
forwarding activity
communications history
relevant metadata
USB & External Storage
connected devices
USB history
external drives
removable-media activity
file interaction
device identifiers
File Access & Data Movement
downloads
uploads
copy activity
archive creation
external sharing
synchronization activity
Identity & Security Telemetry
authentication activity
account access
VPN
EDR / XDR
security logs
privilege or access changes
INVESTIGATIVE QUESTIONS
What Does the Evidence
Actually Establish?
The purpose of an insider investigation is not to confirm a suspicion. It is to evaluate the available digital record and determine which conclusions are supported, which remain uncertain, and what activity can be reconstructed.
What Information Was Accessed?
Determine which files, folders, systems, mailboxes, cloud repositories, or other information sources are implicated by the available evidence.
Was Company Data Copied or Transferred?
Evaluate evidence of downloads, file copying, email forwarding, cloud synchronization, uploads, removable media, archive creation, or other transfer activity.
Where Did the Data Go?
Assess available evidence concerning personal email, cloud accounts, external storage, connected devices, remote systems, or other potential destinations.
When Did the Activity Occur?
Correlate timestamps and activity across systems to establish relevant sequences before, during, or after significant employment events.
Was Relevant Evidence Deleted or Altered?
Examine available artifacts for deletion, wiping, file modification, account changes, log loss, or other activity that may affect the evidentiary record.
Does the Evidence Support the Allegation?
Compare the digital record with reported events, business records, access expectations, witness accounts, and other relevant information to distinguish supported findings from assumption.
INSIDER THREAT INVESTIGATION PROCESS
A Disciplined Investigation
of User Activity.
The investigative process is structured to preserve evidence, identify relevant sources, reconstruct activity, correlate findings across systems, and communicate conclusions according to what the available record supports.
01
Define Scope & Preserve
Identify the investigative questions, relevant users, systems, accounts, time periods, and evidence sources, then preserve the available record.
02
Collect Evidence
Acquire relevant endpoint data, cloud records, communications, logs, storage media, security telemetry, and other authorized evidence.
03
Examine User Activity
Analyze file activity, applications, communications, account usage, connected devices, cloud activity, and other artifacts relevant to the matter.
04
Correlate & Reconstruct
Compare evidence across sources to develop timelines, trace data movement, evaluate disputed events, and test competing explanations.
05
Report & Advise
Document supported findings, evidentiary limitations, relevant timelines or exhibits, and conclusions for counsel, leadership, HR, investigators, or other authorized stakeholders.
INVESTIGATIVE FINDINGS
From User Activity to
Defensible Findings.
Individual forensic artifacts rarely answer an insider allegation by themselves. Cyber Centaurs correlates evidence across devices, accounts, communications, and data sources to establish relevant activity and explain what the available record does—and does not—support.
Reconstructed User Timelines
Chronologies of relevant access, file activity, communications, account usage, device connections, and other events.
Data Access Findings
Identification of relevant information accessed, opened, downloaded, modified, or otherwise implicated by the evidence.
Data Movement Findings
Analysis of evidence associated with copying, forwarding, synchronization, cloud transfer, removable media, external storage, or other movement.
Device & Account Activity
Findings concerning relevant computers, user accounts, applications, cloud services, connected devices, and authentication activity.
Evidence Preservation & Limitations
Documentation of preserved sources, unavailable evidence, retention limitations, conflicting artifacts, or other factors affecting conclusions.
Decision-Ready Reporting
Clear findings, timelines, supporting exhibits, and technical explanations appropriate for counsel, leadership, HR, or other authorized decision-makers.
WHY CYBER CENTAURS
Technical Depth.
Investigative Judgment.
Insider allegations require evidence, not assumptions.
Cyber Centaurs combines digital forensics, cybersecurity expertise, and investigative discipline to evaluate complex employee activity and provide organizations and counsel with findings grounded in the available digital record.
Digital Forensic Expertise
Technical examination across endpoints, accounts, cloud platforms, communications, storage media, and related evidence sources.
Evidence-Driven Methodology
Investigative conclusions are developed through preservation, examination, correlation, validation, and documentation of available evidence.
Support for Counsel, Leadership & HR
Findings are communicated clearly to legal counsel, executives, human resources, investigators, and other authorized stakeholders.
Defensible Investigation
The work is structured with attention to evidentiary integrity, technical support, documentation, and the scrutiny associated with disputed corporate or legal matters.
INSIDER THREAT FAQ
Practical Questions
Before Engagement.
Insider investigations often begin before the organization knows exactly what occurred or what evidence remains available. These questions address common considerations when employee activity, company data, or trusted access is in dispute.
When should an organization begin an insider threat investigation?
An investigation may be appropriate when there is credible concern about unusual access, suspected data copying, unauthorized use of company information, suspicious activity before or after an employee departure, or another event where digital evidence may help establish what occurred. The organization does not need to know the full scope before preserving relevant evidence and assessing investigative options.
Can you determine whether an employee copied company files?
In some matters, forensic artifacts may show that files were accessed, copied, downloaded, synchronized, archived, emailed, uploaded, or transferred to removable media or other locations. Whether specific copying can be conclusively established depends on the evidence retained by the relevant systems and devices.
Can you determine whether a USB drive or external device was used?
Computer forensic artifacts may identify connected USB or external storage devices and provide information about device history and relevant file activity. The extent to which specific transferred files can be established depends on the artifacts available from the computer, device, and other evidence sources.
Can you investigate files sent to personal email or cloud storage?
Yes. Depending on the available evidence and authorized scope, an investigation may examine business email, message activity, browser artifacts, cloud audit records, synchronization activity, endpoint evidence, and other sources associated with potential transfers to personal email or external cloud services.
Should we preserve an employee's computer after termination or resignation?
If the computer may contain relevant evidence, avoid unnecessary reimaging, reassignment, deletion, software installation, or other changes until preservation needs have been evaluated. Relevant cloud accounts, email, logs, and security telemetry may also require preservation.
Can you investigate a former employee after access has been disabled?
Potentially. Even after access is revoked, relevant evidence may remain on company computers, cloud platforms, email systems, security tools, logs, backups, storage systems, and other authorized sources. The available evidence depends on retention, system configuration, and subsequent activity.
Do you work with legal counsel and human resources?
Yes. Cyber Centaurs can support internal and outside counsel, executive leadership, human resources, corporate security, IT teams, and other authorized stakeholders. The investigative scope and communication process can be structured according to the needs of the matter.
Can an insider investigation be performed remotely?
Many investigations can begin remotely through secure collection of endpoint evidence, cloud records, email, logs, and other relevant sources. Some matters may require shipment of devices or on-site collection depending on the evidence, legal requirements, or technical circumstances.
CONFIDENTIAL INQUIRY
Speak With an
Insider Threat Investigator.
Tell us briefly about the suspected activity, the employee or user involved, the systems or information at issue, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.
Confidential inquiry. Please do not submit evidence, credentials, or sensitive files through this form.
