TRADE SECRET & EMPLOYEE DATA THEFT INVESTIGATIONS
Trade Secret Theft Investigations
Built on Evidence.
Cyber Centaurs investigates suspected trade secret theft, employee data removal, and unauthorized use of confidential or proprietary business information. We preserve and analyze digital evidence to identify relevant information, reconstruct access and transfer activity, trace potential data movement, and develop defensible findings for organizations and counsel.
Confidential Consultation
WHEN TO INVESTIGATE
When Proprietary Information
May Have Left the Business.
Trade secret and employee data theft investigations often begin after an employee departure, unusual access to sensitive information, unexpected downloads, or evidence that company data may have been transferred outside authorized systems. Early preservation can be critical to understanding what occurred and what the available evidence can establish. Related matters centered on trusted-user behavior may also involve Insider Threat Investigations.
Departing Employee Activity
Unusual Access to Proprietary Information
Large or Unexpected File Downloads
Personal Email or Cloud Transfers
USB & External Storage Activity
Deletion or Alteration of Relevant Evidence
INVESTIGATIVE OBJECTIVES
Preserve the Evidence.
Trace the Information.
A trade secret investigation should protect the available record, identify the information at issue, reconstruct relevant access and transfer activity, and develop findings that distinguish supported evidence from allegation or assumption.
Preserve the Record
Protect relevant computers, accounts, communications, cloud records, file systems, logs, storage media, and other evidence before unnecessary changes alter the available record.
Identify Relevant Information
Determine which files, folders, repositories, communications, or other proprietary information are implicated by the investigation.
Trace Access & Movement
Evaluate how relevant information was accessed, copied, downloaded, synchronized, emailed, uploaded, archived, transferred, or moved to external devices or services.
Establish Findings
Correlate the available evidence to document supported activity, evidentiary limitations, unresolved questions, and findings appropriate for corporate or legal decisions.
TRADE SECRET INVESTIGATION EVIDENCE
Follow the Evidence
Across the Environment.
Evidence of proprietary-data access or movement may exist across employee computers, company file systems, cloud platforms, communications, removable media, and security telemetry. Relevant sources are examined together to reconstruct activity and establish context; endpoint-focused matters may require computer forensic examination.
Computers & Endpoints
File-system artifacts
Recent files
User profiles
Application activity
Browser activity
System logs
File Shares & Repositories
Network shares
Document repositories
Project folders
File metadata
Access records
Version history
Cloud & Collaboration
Microsoft 365
SharePoint
OneDrive
Google Workspace
Dropbox
Cloud audit activity
Email & Communications
Business email
Message headers
Attachments
Forwarding activity
Communications history
Relevant metadata
USB & External Storage
Connected devices
USB history
External drives
Removable-media activity
Device identifiers
Relevant file interaction
Identity & Security Telemetry
Authentication activity
Account access
VPN activity
EDR / XDR
Security logs
Access or privilege changes
INVESTIGATIVE QUESTIONS
What Can the Digital Record
Establish?
The investigation should test suspected activity against the available evidence. The objective is to determine what information was involved, how it was accessed or moved, which users and systems are implicated, and which conclusions the digital record can reliably support.
What Proprietary Information Was Accessed?
Identify relevant files, folders, repositories, communications, or other confidential information implicated by the available evidence.
Was Information Copied or Removed?
Evaluate evidence of file copying, downloads, archive creation, email forwarding, uploads, cloud synchronization, removable media, or other transfer activity.
Where Did the Information Go?
Assess evidence concerning personal email, external cloud services, removable storage, connected devices, remote systems, or other potential destinations.
When Did the Activity Occur?
Develop timelines of relevant access and transfer activity, including activity before or after resignation, termination, competitive employment, or other significant events.
Which Users, Devices, or Accounts Are Implicated?
Correlate account activity, endpoint evidence, device usage, authentication records, communications, and other artifacts associated with relevant actions.
What Does the Evidence Actually Support?
Compare the digital record with reported events, access expectations, business records, witness accounts, and allegations to distinguish supported findings from unresolved questions.
TRADE SECRET INVESTIGATION PROCESS
A Disciplined Examination
of the Digital Record.
The investigative process is structured to preserve relevant evidence, identify the information at issue, reconstruct access and transfer activity, correlate findings across sources, and communicate conclusions according to what the available record supports.
01
Define Scope & Preserve
Identify the information, users, devices, accounts, systems, time periods, and investigative questions relevant to the matter, then preserve available evidence.
02
Collect Evidence
Acquire authorized endpoint data, file-system evidence, cloud records, communications, logs, removable-media artifacts, and other relevant sources.
03
Examine Access & Movement
Analyze file activity, downloads, communications, connected devices, cloud usage, archive creation, account activity, and other evidence associated with proprietary information.
04
Correlate & Reconstruct
Compare evidence across sources to develop timelines, trace potential data movement, identify relationships, and evaluate competing explanations.
05
Report & Advise
Document supported findings, evidentiary limitations, relevant timelines or exhibits, and technical conclusions for counsel, leadership, investigators, or other authorized stakeholders.
INVESTIGATIVE FINDINGS
From Digital Activity to
Defensible Findings.
Individual artifacts rarely establish trade secret misappropriation on their own. Cyber Centaurs correlates evidence across systems and data sources to document relevant activity and explain what the digital record does—and does not—support.
Information Access Findings
Identification of proprietary files, folders, repositories, communications, or other information implicated by the available evidence.
Data Movement Findings
Analysis of evidence associated with downloads, copying, synchronization, forwarding, uploads, removable media, archive creation, or external transfer.
Reconstructed Timelines
Chronologies of relevant access, file activity, communications, device connections, account usage, and other events.
User, Device & Account Activity
Findings concerning the users, computers, accounts, cloud services, connected devices, and authentication activity relevant to the investigation.
Evidence Preservation & Limitations
Documentation of preserved evidence, unavailable sources, retention limitations, conflicting artifacts, or other factors affecting investigative conclusions.
Decision-Ready Reporting
Clear findings, timelines, supporting exhibits, and technical explanations appropriate for counsel, leadership, litigation strategy, or other authorized decision-makers.
WHY CYBER CENTAURS
Technical Depth.
Investigative Judgment.
Trade secret allegations require a defensible digital record.
Cyber Centaurs combines digital forensics, cybersecurity expertise, and investigative discipline to examine suspected proprietary-data theft and provide organizations and counsel with findings grounded in the available evidence.
Digital Forensic Expertise
Technical examination across computers, file systems, accounts, cloud platforms, communications, removable media, and related evidence sources.
Evidence-Driven Methodology
Findings are developed through preservation, examination, correlation, validation, and documentation rather than assumption.
Support for Counsel & Organizations
Technical findings are communicated clearly to in-house and outside counsel, executives, investigators, HR, and other authorized stakeholders.
Expert Witness & Litigation Experience
Forensic findings can be documented and communicated with attention to evidentiary integrity, technical support, exhibits, and the scrutiny associated with disputed legal matters.
TRADE SECRET THEFT FAQ
Practical Questions
Before Engagement.
Trade secret investigations often begin with uncertainty about what information was accessed, whether it left the organization, and what evidence remains available. These questions address common considerations at the beginning of a forensic investigation.
When should a company begin a trade secret theft investigation?
An investigation may be appropriate when there is credible concern that proprietary or confidential information was accessed, copied, transferred, retained, or used outside authorized business purposes. Common triggers include employee departures, unusual downloads, competitor transitions, personal cloud or email activity, removable media, or other unexplained access to sensitive information.
Can you determine which company files an employee accessed?
Depending on the systems and evidence available, forensic artifacts, file-system metadata, cloud audit records, application activity, logs, and other sources may help identify files, folders, repositories, or information accessed by a relevant user.
Can you determine whether trade secret files were copied?
In some matters, evidence may indicate that files were copied, downloaded, synchronized, archived, emailed, uploaded, or transferred to removable media or another location. Whether specific copying can be conclusively established depends on the artifacts retained by the relevant devices and systems.
Can you determine whether files were transferred to a USB drive?
Forensic artifacts may identify connected USB or external storage devices and may provide evidence concerning relevant file activity. The ability to establish which files were transferred depends on the artifacts available from the computer, storage device, and other evidence sources.
Can you investigate transfers to personal email or cloud storage?
Yes. Depending on the authorized scope and available evidence, an investigation may examine email activity, message headers, attachments, browser artifacts, cloud audit records, synchronization activity, endpoint evidence, and other sources associated with potential external transfers.
What should we preserve after discovering suspected trade secret theft?
Relevant computers, company accounts, email, cloud records, file shares, security logs, removable-media evidence, and other potentially relevant systems should be considered for preservation. Avoid unnecessary reimaging, deletion, account cleanup, or other changes before preservation priorities have been evaluated.
Do you work with attorneys in trade secret litigation?
Yes. Cyber Centaurs can work with in-house and outside counsel in matters involving forensic investigation, evidence preservation, technical analysis, litigation support, expert consultation, and expert-witness requirements.
Can a trade secret investigation begin remotely?
Many investigations can begin remotely through secure collection of endpoint evidence, cloud records, email, logs, and other authorized sources. Some matters may require shipment of devices or on-site collection depending on the evidence, legal requirements, or technical circumstances.
CONFIDENTIAL INQUIRY
Speak With a
Trade Secret Investigator.
Tell us briefly about the suspected activity, the proprietary information involved, the employee or user at issue, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.
Confidential inquiry. Please do not submit evidence, credentials, trade secret materials, or sensitive files through this form.
