Insider Threat Investigation

An employee is leaving. You suspect they’ve taken your data.

GCIT conducts forensic investigations across Microsoft 365, cloud storage, and endpoint systems to identify exactly what was taken, when, and how. Court-ready evidence reports delivered within days.

GCIT

Confidential

Executive Summary
Insider Threat Investigation
Investigation period: 90 days | Multiple users examined
42
File Transfers
1K+
Deletions Logged
19K+
Emails Traced
Systematic data export detected – 20+ client folders transferred to personal email via file-sharing service

Financial documents forwarded – cash flow forecasts and tax reports sent to personal accounts

Third user cleared – legitimate client correspondence only

90
Day audit window
as standard

3–5
Business days to
full report delivery

70K+
Audit events analysed
in our largest investigation

100%
Evidence preserved
even after deletion

Every action leaves a digital trail

Microsoft 365 records every email sent, file downloaded, link shared, and item deleted. We know where to look and how to interpret what we find.

Email Forwarding to Personal Accounts

We trace every email sent to personal Gmail, Hotmail, or private domain addresses. Deleted sent items are recovered from the mailbox dumpster and litigation hold.

File Downloads & SharePoint Activity

Every FileSyncDownloadedFull event in the Unified Audit Log is captured and cross-referenced with email sends. We map which files were downloaded and where they went.

Cloud Storage & File Sharing

WeTransfer exports, Dropbox downloads, anonymous sharing links, and OneDrive sync activity are all traced. We identify what was exported and to whom.

Deletion & Concealment Patterns

Bulk deletion of sent items, targeted purging of evidence, and attempts to clean up trails are flagged. Litigation hold preserves items even after permanent deletion.

Sign-in & Location Analysis

Entra ID sign-in logs reveal login locations, device types, and access times. Anomalous sign-ins from unexpected locations or devices are flagged.

Endpoint & Device Forensics

Managed device software inventories, USB activity, and application usage are reviewed where endpoint management tools are deployed.

From suspicion to evidence in days

Our process is designed to preserve evidence integrity while delivering actionable findings quickly.

Engage

You brief us on the situation. We scope the investigation: which users, what timeframe, what data sources. We enable litigation hold to freeze all evidence before proceeding.

Collect

We extract the Unified Audit Log, message traces, mailbox content, cloud storage logs, and sign-in records using the organisation’s own Microsoft 365 administrative access.

Analyse

Cross-referencing multiple data sources reveals the full picture. File downloads are correlated with email sends. Deletion patterns are mapped. Timelines are reconstructed.

Report

You receive an executive summary, detailed per-user findings, an interactive evidence timeline, the full evidence package (preserved .eml files), and prioritised recommendations.

Real investigations. Real findings.

Names and identifying details have been changed. The patterns, data volumes, and findings are real.

High Risk – Active Exfiltration

The Departing Director

A managing director of a property firm announced he was leaving to start a competing business. The owner suspected data had been taken and engaged GCIT to investigate.

We found 42 confirmed file transfers of client deal folders to an associate’s personal Gmail via a file-sharing service. Financial documents including cash flow forecasts, tax reports, and engagement letters had been forwarded to personal Hotmail accounts. A second employee received all exports and had deleted her file-sharing account from her work email to shift the trail to an unmanaged personal address.

The exfiltration was still ongoing two days after we delivered the report.

42
High-Risk Transfers
90
Day Audit Window
3
Users Examined
GCIT

Confidential

Executive Summary
Insider Threat Investigation
90-day audit | 3 users | Commercial property
42
High-Risk Transfers
20+
Client Folders Exported
1K+
Deletions Logged
Director A (HIGH) – Systematic export of 20+ property deal folders to personal email. Financial documents forwarded pre-departure. Majority of audit log activity is deletions.

Employee B (HIGH) – Received all exports at personal Gmail. Deleted work file-sharing account to shift trail to unmanaged personal address.

Employee C (LOW) – 229 external emails reviewed. Legitimate client correspondence only. Cleared.

High Risk – Systematic Exfiltration

The Quiet Exit

A senior employee at an industrial services company resigned and joined a competitor. The general manager asked GCIT to review what, if anything, had been taken.

We found 23 emails forwarded to a personal domain over three months – all deleted from Sent Items after forwarding. Content included client quotes from three major accounts, purchase orders, the full company contact list (taken on his final day), a colleague’s CV, and client site requirements documents. File download timestamps in the audit log matched the forwarding timestamps exactly: download from SharePoint, then forward to personal email, same day.

The pattern escalated from quotes and purchase orders in February to the full company contact list on his final day.

3K+
File Events Analysed
23
Emails to Personal Domain
69.6%
High-Concern Events
GCIT

Confidential

Risk Overview
File Activity Audit Report
90-day audit | 1 user | Industrial services

69.6% High-concern events
Date Subject Risk
02 Feb FW: Purchase order for quote #SQ— HIGH
09 Feb FW: Capability Statement HIGH
23 Mar FW: Colleague’s CV HIGH
30 Mar FW: Client survey reports HIGH
13 Apr FW: Client estimates HIGH
14 Apr FW: Full Contact List HIGH

Medium-High Risk – Selective Exfiltration

The Business Buyout

A partner at a mid-sized consulting firm was exiting the business as part of a structured buyout. The remaining partners suspected sensitive documents were being copied to a personal account ahead of the settlement.

We found multiple emails forwarded to a personal address over several weeks. Content included signed commercial agreements, confidential client engagement letters, and key financial documents. All forwarded items were purged from Deleted Items in a single bulk session – targeted evidence concealment. A litigation hold preserved everything the departing partner believed they had permanently destroyed.

70K+
Audit Events Analysed
6
Month Audit Window
50+
Evidence Files Preserved
GCIT

Confidential

Evidence Timeline
Evidence Concealment Analysis
6-month audit | 1 user | Consulting firm
  • Week 1First email forwarded to personal address (signed commercial agreement)
  • Week 3Confidential engagement letters forwarded to personal address
  • Week 4Key financial documents forwarded to personal address
  • Week 5Last exfiltration email sent to personal address
  • Week 6All forwarded emails purged from Deleted Items in single session
LITIGATION HOLD ACTIVE
All purged items preserved and recovered. Pre-existing hold ensured no data was lost.

Microsoft 365 forensic investigation

We use multiple independent data sources within your Microsoft 365 tenant. Cross-referencing these sources produces a complete, corroborated evidence chain.

Unified Audit Log (UAL)

The primary forensic data source. Records every file download, email access, sharing link creation, deletion event, and admin action across all Microsoft 365 services. Up to 180 days of history. We extract, parse, and classify every event by risk level.

Exchange Message Trace

90 days of email routing metadata: every email sent and received, with sender, recipient, subject, timestamp, and delivery status. We identify forwarding to personal domains, unusual external recipients, and volume anomalies.

Mailbox Content Inspection

Using application-level Mail.Read permissions, we inspect Sent Items, Deleted Items, and the recoverable items dumpster. Items preserved by litigation hold are recovered even after the user has permanently deleted them.

Cloud Storage Audit

Dropbox Business audit logs, OneDrive activity, SharePoint file operations, and third-party file transfer services (WeTransfer, Google Drive) are traced where applicable. Anonymous sharing links are identified and mapped.

Australian Legal Context
When employee data theft becomes a legal matter
Australian businesses face specific legal obligations and protections when an insider threat is identified. GCIT’s reports are structured to support legal proceedings and regulatory compliance from the outset.

Obligations
Privacy Act 1988 & Notifiable Data Breaches
If personal information of clients or employees was accessed or exfiltrated, a Notifiable Data Breach may be triggered under the NDB scheme. Businesses have 30 days to assess and report to the OAIC.
  • 30-day assessment and notification window
  • OAIC reporting requirement if serious harm is likely
  • GCIT reports provide the forensic evidence to complete the assessment
  • Evidence chain supports OAIC and legal proceedings
Protections
Employment law & evidence preservation
Employers can lawfully investigate employee use of company IT systems under Australian employment law. Our investigations use the organisation’s own administrative access and Microsoft’s built-in audit tools.
Court-ready deliverables include timestamped evidence chains, cross-referenced data sources, preserved .eml files, and a methodology section that withstands legal scrutiny.

Common trigger scenarios

Employee Resignation

An employee has resigned and you suspect they may have taken client data, pricing, IP, or contact lists to a competitor. The days between resignation and departure are the highest-risk window for data exfiltration.

Suspicious Forwarding Detected

Your DLP policy, email gateway, or IT team has flagged emails being sent to personal accounts. You need to determine the scope: was it one email, or a systematic campaign?

Business Buyout or Partnership Dispute

A departing partner or director may be taking client records, financial documents, or legally sensitive materials to gain leverage. Evidence concealment is common in these scenarios.

Post-Breach Compliance

A data breach has occurred and you need to assess the scope for OAIC notification. Our forensic audit provides the evidence required to complete the 30-day NDB assessment and support any legal proceedings.

A complete evidence package

Every investigation delivers five core deliverables, designed to be immediately useful for legal counsel, HR, and board-level reporting.

📋
Executive Summary
One-page overview for board and legal counsel. Key findings, risk ratings, and recommended actions.

🔍
Detailed Report
Per-user analysis with full evidence chains, cross-referenced data sources, and methodology documentation.

📈
Interactive Timeline
Filterable, searchable event timeline. Sort by user, risk level, date, or activity type.

📦
Evidence Package
Preserved .eml files of all relevant emails. Downloaded files and audit log exports for legal discovery.

🛠
Recommendations
Prioritised security improvements: DLP policies, access controls, monitoring, and prevention measures.

Employee data theft investigation FAQ

Can an employer investigate an employee’s email in Australia?

+
Yes. Under Australian law, employers generally have the right to investigate employee use of company-provided email and IT systems, particularly when there is reasonable suspicion of misconduct. Microsoft 365 audit logs, message traces, and mailbox content are all accessible to the account owner (the business). GCIT conducts these investigations using the organisation’s own administrative access and Microsoft’s built-in forensic tools, ensuring the evidence is collected lawfully and is admissible in proceedings.

Is it illegal for an employee to take company data when they leave?

+
Taking company data without authorisation can breach confidentiality clauses in employment contracts, the Corporations Act 2001 (for directors and officers), and potentially the Criminal Code Act 1995 provisions on unauthorised access to computer data. Under the Privacy Act 1988, if personal information of clients or staff is involved, a Notifiable Data Breach may also be triggered. The severity depends on what was taken, how it was taken, and whether it was used competitively.

How do you detect data exfiltration in Microsoft 365?

+
We analyse the Microsoft 365 Unified Audit Log (UAL), which records every file download, email send, sharing link creation, and deletion event. We cross-reference this with Exchange message traces (90 days of email routing data), mailbox content inspection (Sent Items, Deleted Items, and recoverable items preserved by litigation hold), sign-in logs for location anomalies, and cloud storage audit logs (Dropbox, OneDrive, SharePoint). Patterns like forwarding emails to personal domains, bulk file downloads before resignation, and targeted deletion of sent items are common indicators.

What evidence is needed to prove employee data theft in Australia?

+
Useful evidence includes: audit log records showing file downloads and email forwarding to personal accounts, message trace data confirming delivery to external domains, recovered mailbox items showing deleted evidence, IP geolocation confirming activity from expected locations, and a timeline correlating file access with known events (resignation date, competitive activity). GCIT produces court-ready reports with timestamped evidence chains, cross-referenced data sources, and preserved .eml files of relevant emails.

How long does an insider threat investigation take?

+
A typical investigation covering one to three users over a 90-day audit window takes 3 to 5 business days from engagement to report delivery. Complex investigations involving multiple data sources (M365, Dropbox, endpoint forensics), extended timeframes (180+ days), or more than three users may take 5 to 10 business days. Urgent matters involving active exfiltration can be triaged within 24 hours.

How much does a digital forensics investigation cost in Australia?

+
GCIT’s insider threat investigations are scoped and quoted per engagement. A standard investigation covering 1–3 users across Microsoft 365 typically ranges from $2,000 to $5,000 AUD + GST, depending on the number of users, data sources, and audit period. This includes the full forensic report, executive summary, evidence package, and recommendations. Enterprise investigations involving larger user counts, multiple cloud platforms, or endpoint forensics are quoted separately.

Can you recover deleted emails in Microsoft 365?

+
Yes, in most cases. Microsoft 365 retains deleted items in a recoverable items folder for 14–30 days by default. If a litigation hold or retention policy is in place, deleted items are preserved indefinitely – even items that the user has permanently deleted. GCIT routinely recovers evidence from these hidden folders, including emails that employees believed they had destroyed. We recommend enabling litigation hold before notifying an employee of any investigation.

What should I do if I suspect an insider threat?

+
First, do not alert the employee. Second, enable litigation hold on their mailbox immediately to preserve all current and deleted items. Third, contact GCIT for an initial assessment – we can review sign-in logs and recent audit activity within hours to confirm whether exfiltration is occurring. Fourth, consult your employment lawyer about your obligations and options. Acting quickly is critical: data exfiltration often accelerates in the days after an employee gives notice.

Suspect an insider threat?

Contact GCIT for a confidential initial assessment. We can confirm whether exfiltration is occurring within hours.

Request a Confidential Assessment

GCIT · 1300 369 111 · 1/16 Dover Drive, Burleigh Heads QLD 4220


Ready to secure and simplify your IT? Talk to a GCIT expert today.