A member of staff resigns or is dismissed, copies company data to a USB stick, personal email or cloud drive, then wipes the laptop before handing it back. We prove what left the business — for employers across Staines, Surrey and beyond. Free diagnostic, freephone advice.
Confidential and evidence-grade. A free diagnostic and a written scope come before any investigation begins.
If any of these match what you are seeing in your Staines or Surrey business, the device should be preserved and examined before it is wiped or reissued.
It is the scenario Surrey employers ask us about most: a member of staff resigns or is dismissed, spends their final days quietly copying documents, contacts and pricing to a USB stick, a personal email account or a cloud drive, then factory-resets or runs a wiping tool on the laptop before handing it back. The machine looks clean; the suspicion is anything but. Forensic examination is built for exactly this. Even after a reset or a dedicated eraser has run, a great deal survives — including which wiping tool was used and the precise moment it ran, the burst of file activity in the notice period, and deleted documents themselves, carved back from the drive.
Windows keeps a surprisingly complete record of removable media. Every USB storage device that has been connected leaves its make, model and unique serial number in the USBSTOR registry key, with first-connection times in the setupapi log and last-connection times in the registry itself. We tie that device back to the user through MountedDevices and MountPoints2, then show which of your files were touched: shortcut (LNK) files and jump lists pointing at a document on the E: or F: drive prove it was opened from removable media, shellbags show which folders were browsed on the stick, and the NTFS USN change journal records the file operations around those dates. Cross-referenced, these artefacts turn 'we think they took something' into a documented list of what and when.
Data does not only leave on a stick. We examine webmail and browser history for company files sent to a personal Gmail, Outlook or iCloud account, attachments uploaded to WeTransfer, and folders synced to a personal Dropbox, OneDrive or Google Drive. Deleted emails are carved from unallocated space, download and browsing history is reconstructed, and cloud-client logs reveal what was synchronised and when — building a single, honest picture of every route the data may have taken out of the business.
What makes this forensic rather than mere recovery is procedure. We work only from a hardware write-blocked image of the original drive, verified by MD5 and SHA-256 hash so anyone can prove the copy is identical and unaltered. Handling is logged as a documented chain of custody, our bench runs OSForensics from PassMark for the heavy lifting and Passware Kit Forensic where password-protected files stand in the way, and the report is split into plain-English findings and a technical appendix so it holds up before an employment tribunal or court. We are glad to work to directions agreed with your solicitor.
This is one of the scenarios covered by our wider forensic data recovery service — the hub page explains how write-blocked imaging, hashing and chain of custody underpin every case.
On a company laptop or PC, these are the artefacts that show whether data was copied — and where it went.
Every stick's make, model and serial, with first- and last-connected times.
LNK files and jump lists that tie your documents to a drive letter.
Shellbags showing which directories were opened on the removable media.
USN change-journal activity around the dates data went missing.
Browser history and sync traces for personal email, Drive and Dropbox.
Carved documents and emails — and the eraser tool's own footprint.
We examine company-owned equipment, or a personal device only where there is a lawful basis such as a signed company policy or a solicitor's instruction. We do not covertly access a former employee's private phone or home computer. Most important right now: preserve the laptop exactly as it is, powered off, and do not let IT re-image or reissue it — every reinstall overwrites the very evidence that proves what happened.
Forensic cases are preserved, not probed. Before sending anything, call 0800 689 0668 and we will agree exactly what to submit and how to keep it evidentially sound. Chain of custody is documented from the moment your device reaches our secure Guildford location.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Preserve the laptop, then start a free diagnostic or call the freephone — the sooner it is imaged, the more survives.