An employee is leaving. You suspect they’ve taken your data.
GCIT conducts forensic investigations across Microsoft 365, cloud storage, and endpoint systems to identify exactly what was taken, when, and how. Court-ready evidence reports delivered within days.
as standard
full report delivery
in our largest investigation
even after deletion
Every action leaves a digital trail
Microsoft 365 records every email sent, file downloaded, link shared, and item deleted. We know where to look and how to interpret what we find.
Email Forwarding to Personal Accounts
We trace every email sent to personal Gmail, Hotmail, or private domain addresses. Deleted sent items are recovered from the mailbox dumpster and litigation hold.
File Downloads & SharePoint Activity
Every FileSyncDownloadedFull event in the Unified Audit Log is captured and cross-referenced with email sends. We map which files were downloaded and where they went.
Cloud Storage & File Sharing
WeTransfer exports, Dropbox downloads, anonymous sharing links, and OneDrive sync activity are all traced. We identify what was exported and to whom.
Deletion & Concealment Patterns
Bulk deletion of sent items, targeted purging of evidence, and attempts to clean up trails are flagged. Litigation hold preserves items even after permanent deletion.
Sign-in & Location Analysis
Entra ID sign-in logs reveal login locations, device types, and access times. Anomalous sign-ins from unexpected locations or devices are flagged.
Endpoint & Device Forensics
Managed device software inventories, USB activity, and application usage are reviewed where endpoint management tools are deployed.
From suspicion to evidence in days
Our process is designed to preserve evidence integrity while delivering actionable findings quickly.
Engage
You brief us on the situation. We scope the investigation: which users, what timeframe, what data sources. We enable litigation hold to freeze all evidence before proceeding.
Collect
We extract the Unified Audit Log, message traces, mailbox content, cloud storage logs, and sign-in records using the organisation’s own Microsoft 365 administrative access.
Analyse
Cross-referencing multiple data sources reveals the full picture. File downloads are correlated with email sends. Deletion patterns are mapped. Timelines are reconstructed.
Report
You receive an executive summary, detailed per-user findings, an interactive evidence timeline, the full evidence package (preserved .eml files), and prioritised recommendations.
Real investigations. Real findings.
Names and identifying details have been changed. The patterns, data volumes, and findings are real.
The Departing Director
A managing director of a property firm announced he was leaving to start a competing business. The owner suspected data had been taken and engaged GCIT to investigate.
We found 42 confirmed file transfers of client deal folders to an associate’s personal Gmail via a file-sharing service. Financial documents including cash flow forecasts, tax reports, and engagement letters had been forwarded to personal Hotmail accounts. A second employee received all exports and had deleted her file-sharing account from her work email to shift the trail to an unmanaged personal address.
The exfiltration was still ongoing two days after we delivered the report.
The Quiet Exit
A senior employee at an industrial services company resigned and joined a competitor. The general manager asked GCIT to review what, if anything, had been taken.
We found 23 emails forwarded to a personal domain over three months – all deleted from Sent Items after forwarding. Content included client quotes from three major accounts, purchase orders, the full company contact list (taken on his final day), a colleague’s CV, and client site requirements documents. File download timestamps in the audit log matched the forwarding timestamps exactly: download from SharePoint, then forward to personal email, same day.
The pattern escalated from quotes and purchase orders in February to the full company contact list on his final day.
| Date | Subject | Risk |
|---|---|---|
| 02 Feb | FW: Purchase order for quote #SQ— | HIGH |
| 09 Feb | FW: Capability Statement | HIGH |
| 23 Mar | FW: Colleague’s CV | HIGH |
| 30 Mar | FW: Client survey reports | HIGH |
| 13 Apr | FW: Client estimates | HIGH |
| 14 Apr | FW: Full Contact List | HIGH |
The Business Buyout
A partner at a mid-sized consulting firm was exiting the business as part of a structured buyout. The remaining partners suspected sensitive documents were being copied to a personal account ahead of the settlement.
We found multiple emails forwarded to a personal address over several weeks. Content included signed commercial agreements, confidential client engagement letters, and key financial documents. All forwarded items were purged from Deleted Items in a single bulk session – targeted evidence concealment. A litigation hold preserved everything the departing partner believed they had permanently destroyed.
- Week 1First email forwarded to personal address (signed commercial agreement)
- Week 3Confidential engagement letters forwarded to personal address
- Week 4Key financial documents forwarded to personal address
- Week 5Last exfiltration email sent to personal address
- Week 6All forwarded emails purged from Deleted Items in single session
Microsoft 365 forensic investigation
We use multiple independent data sources within your Microsoft 365 tenant. Cross-referencing these sources produces a complete, corroborated evidence chain.
Unified Audit Log (UAL)
The primary forensic data source. Records every file download, email access, sharing link creation, deletion event, and admin action across all Microsoft 365 services. Up to 180 days of history. We extract, parse, and classify every event by risk level.
Exchange Message Trace
90 days of email routing metadata: every email sent and received, with sender, recipient, subject, timestamp, and delivery status. We identify forwarding to personal domains, unusual external recipients, and volume anomalies.
Mailbox Content Inspection
Using application-level Mail.Read permissions, we inspect Sent Items, Deleted Items, and the recoverable items dumpster. Items preserved by litigation hold are recovered even after the user has permanently deleted them.
Cloud Storage Audit
Dropbox Business audit logs, OneDrive activity, SharePoint file operations, and third-party file transfer services (WeTransfer, Google Drive) are traced where applicable. Anonymous sharing links are identified and mapped.
- 30-day assessment and notification window
- OAIC reporting requirement if serious harm is likely
- GCIT reports provide the forensic evidence to complete the assessment
- Evidence chain supports OAIC and legal proceedings
Common trigger scenarios
Employee Resignation
An employee has resigned and you suspect they may have taken client data, pricing, IP, or contact lists to a competitor. The days between resignation and departure are the highest-risk window for data exfiltration.
Suspicious Forwarding Detected
Your DLP policy, email gateway, or IT team has flagged emails being sent to personal accounts. You need to determine the scope: was it one email, or a systematic campaign?
Business Buyout or Partnership Dispute
A departing partner or director may be taking client records, financial documents, or legally sensitive materials to gain leverage. Evidence concealment is common in these scenarios.
Post-Breach Compliance
A data breach has occurred and you need to assess the scope for OAIC notification. Our forensic audit provides the evidence required to complete the 30-day NDB assessment and support any legal proceedings.
A complete evidence package
Every investigation delivers five core deliverables, designed to be immediately useful for legal counsel, HR, and board-level reporting.
Employee data theft investigation FAQ
Suspect an insider threat?
Contact GCIT for a confidential initial assessment. We can confirm whether exfiltration is occurring within hours.
Request a Confidential Assessment