Avoid premature confrontation

Preserve data before alerting the subject, as routine deletion or deliberate destruction may follow.

Identify legitimate access

Understand the person’s role, permissions, devices and ordinary workflow before interpreting activity.

Correlate sources

Review endpoint, email, cloud, removable-media, print, file-transfer and physical-access evidence together.

Protect privacy

Use a defined, proportionate scope and controlled handling of personal or privileged material.

Test alternative explanations

Technical activity can have innocent causes. Findings should consider automation, shared accounts and system processes.

Important: This is general guidance. Legal authority, privacy, employment law, privilege and evidential requirements should be considered for the specific matter.