Avoid premature confrontation
Preserve data before alerting the subject, as routine deletion or deliberate destruction may follow.
Identify legitimate access
Understand the person’s role, permissions, devices and ordinary workflow before interpreting activity.
Correlate sources
Review endpoint, email, cloud, removable-media, print, file-transfer and physical-access evidence together.
Protect privacy
Use a defined, proportionate scope and controlled handling of personal or privileged material.
Test alternative explanations
Technical activity can have innocent causes. Findings should consider automation, shared accounts and system processes.
Important: This is general guidance. Legal authority, privacy, employment law, privilege and evidential requirements should be considered for the specific matter.
