Legal Cyber Academy
All insights

Departing Employee Investigations: The First 72 Hours

By the Legal Cyber Academy editorial team ·

The first 72 hours in a departing-employee investigation

A departing-employee investigation is the forensic and legal work an employer does in the days after a resignation to determine whether confidential information left with the employee. In the first 72 hours, counsel stops IT from reimaging the returned laptop, exports cloud and endpoint audit logs before vendor retention windows close, scopes the examination to employer-controlled systems, and gathers the dated, act-specific facts a court will require before it enjoins anything.

Hour zero: stop the reimage

The most common evidence loss in these matters is not spoliation by the employee. It is the helpdesk ticket that wipes and redeploys the returned laptop to the next hire before anyone calls counsel. The first move is a written preservation directive naming specific assets — laptop asset tag, phone serial, the mailbox, the cloud drive — sent to whoever actually holds the reimaging queue, together with suspension of the automated deprovisioning that deletes the mailbox and cloud storage on a timer.

Then image before you analyze. NIST's Guide to Integrating Forensic Techniques into Incident Response provides that if evidence may be needed for prosecution or disciplinary actions, the analyst should get a bit stream image of the original media, label the original media, and store it securely as evidence, with all subsequent analysis performed on the copied media so the original is not modified. Data integrity verification typically consists of computing the message digest of the original and copied data and comparing them, under a clearly defined chain of custody. Volatile data, NIST notes, is data on a live system that is lost after a computer is powered down or due to the passage of time — so if the machine is still running, the memory-capture decision has to be made now.

The preservation duty runs against the employer too. Rule 37(e) applies where ESI that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it and it cannot be restored or replaced through additional discovery. On a finding of prejudice the court may order measures no greater than necessary to cure the prejudice; only on a finding that the party acted with the intent to deprive another party of the information's use may the court presume the lost information unfavorable, so instruct the jury, or dismiss the action or enter default judgment. An employer that issues a hold letter Monday and reimages the laptop Wednesday has drafted the other side's motion.

The logs that expire while you deliberate

Endpoint artifacts sit still. Cloud audit logs do not.

In Microsoft 365, default retention for Audit (Standard) is 180 days for records generated on or after October 17, 2023, and 90 days for logs generated before that date. Audit (Premium)'s default policy retains Exchange Online, SharePoint, OneDrive, and Microsoft Entra audit records for one year, but only for users assigned an E5-class or Microsoft Purview add-on license; audit records for all other activities are retained 180 days by default, as are records for non-E5 and guest users.

In Google Workspace, Drive log events, Admin log events, and Login/User log events are retained for six months, and administrators cannot delete log event data or change the length of time it is available. Email log search reaches back 30 days.

Those windows are exported to files in the first days, under a documented process.

What USB, cloud-sync, and access artifacts actually show

Windows records external device attachment through the Audit PnP Activity subcategory; Microsoft describes a PnP audit event as one that will be logged on the machine where the change took place. Event 6416, "A new external device was recognized by the System," generates every time a new external device is recognized — for example, when a device is connected or enabled — and carries the device instance path (Device ID), device description (Device Name), class GUID (Class ID), hardware IDs (Vendor IDs), compatible IDs, and location information: enough to tie a particular device to a particular machine at a particular time. Microsoft notes the event is typically triggered by the SYSTEM account, so the account name in the record is usually not the employee's.

Attachment is not exfiltration: 6416 establishes that a device was recognized, not that a file was copied to it. The subcategory that speaks to file movement is Audit Removable Storage, which allows you to audit user attempts to access file system objects on a removable storage device and generates a security audit event for all objects and all types of access requested, with no dependency on the object's SACL, through events 4656, 4658, and 4663. Both are advanced audit policy subcategories that record only while they are configured; where they were not configured on the machine before the relevant period, the honest finding is device recognition and host-side traces, and what left the building remains open.

Increasingly the copy never crosses a USB port at all. In Microsoft 365 the operations to pull are FileDownloaded ("User downloads a document from a site"), FileCopied ("User copies a document from a site" — the copy may be saved to another folder on the same site, so the event is not by itself evidence of an off-network transfer), and FileAccessed, which carries a caveat that matters the moment someone puts a number in a declaration: after a user accesses a file, the system doesn't log the FileAccessed event again for the same user and file for the next five minutes, so raw counts understate access. In Google Workspace, most downloads are logged, including when files are copied between Drive and a local device using Google Drive for desktop, and when a file is copied, Create and Copy events are logged for the new file and a Source Copy event is logged for the original. Our guide on how to read a forensic report separates what an artifact proves from what a summary asserts.

The CFAA is narrower than it looks after Van Buren

In Van Buren v. United States, 593 U.S. 374 (2021), decided June 3, 2021, the Supreme Court held that an individual "exceeds authorized access" under 18 U.S.C. § 1030(e)(6) when he "accesses a computer with authorization but then obtains information located in particular areas of the computer — such as files, folders, or databases — that are off limits to him." The provision "does not cover those who, like Van Buren, have improper motives for obtaining information that is otherwise available to them." Liability under both the "without authorization" and "exceeds authorized access" clauses "stems from a gates-up-or-down inquiry — one either can or cannot access a computer system, and one either can or cannot access certain areas within the system." In footnote 8 the Court expressly declined to address whether that inquiry "turns only on technological (or 'code-based') limitations on access, or instead also looks to limits contained in contracts or policies."

The practical consequence: a sales manager who downloads the customer list she was permitted to open, then resigns, is a weak CFAA case however the acceptable-use policy is worded. The claims with more to work with are about gates — access after credentials were revoked, access to a share the employee never had rights to, use of a colleague's account. Because the Court reserved the contract-and-policy question, how far a written restriction alone can close a gate remains a matter of developing lower-court law.

The civil mechanics have thresholds too. Section 1030(g) allows any person who suffers damage or loss by reason of a violation to maintain a civil action for compensatory damages and injunctive or other equitable relief, but only if the conduct involves one of the factors in subclauses (I) through (V) of § 1030(c)(4)(A)(i) — for employers, almost always loss to one or more persons during any one-year period aggregating at least $5,000 in value. Two limits ride along: where the conduct involves only that loss factor, damages are limited to economic damages, and no action may be brought more than two years after the act complained of or the discovery of the damage. "Loss" is defined in § 1030(e)(11) as any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense. Investigation hours logged as they are incurred are easier to defend than a $5,000 figure reconstructed nine months later.

DTSA civil seizure, and the order you will more likely seek

Section 1836(b)(2) of the Defend Trade Secrets Act permits a court, upon ex parte application but only in extraordinary circumstances, to order the seizure of property necessary to prevent the propagation or dissemination of the trade secret. The court may not grant the application unless it finds it clearly appears from specific facts that a Rule 65 order or other equitable relief would be inadequate because the party would evade, avoid, or otherwise not comply with it; that an immediate and irreparable injury will occur if seizure is not ordered; that the harm to the applicant of denying the application outweighs the harm to the legitimate interests of the target and substantially outweighs harm to third parties; that the applicant is likely to succeed in showing the information is a trade secret and that the target misappropriated it by improper means or conspired to do so; that the target has actual possession of both the trade secret and any property to be seized; that the application describes with reasonable particularity the matter to be seized and, to the extent reasonable, identifies its location; that the target would destroy, move, hide, or otherwise make the matter inaccessible to the court if proceeded against on notice; and that the applicant has not publicized the requested seizure. The order must provide for the narrowest seizure necessary, give guidance to the law enforcement officials executing it, require the applicant to post security against a wrongful or excessive seizure, and set a hearing at the earliest possible time and not later than seven days after the order has issued.

That is a demanding record to assemble in 72 hours; most matters become a Rule 65 application instead. A temporary restraining order without notice requires specific facts in an affidavit or a verified complaint clearly showing that immediate and irreparable injury, loss, or damage will result to the movant before the adverse party can be heard in opposition, plus the movant's attorney certifying in writing any efforts made to give notice and the reasons why it should not be required. Such an order expires at a time the court sets, not to exceed 14 days, unless the court extends it for good cause for a like period or the adverse party consents to a longer extension. Rule 65(c) conditions a TRO or preliminary injunction on the movant giving security in an amount the court considers proper to pay the costs and damages of a party found to have been wrongfully enjoined.

Two DTSA constraints shape the investigation. Section 1836(b)(3)(A) provides that an injunction may not prevent a person from entering into an employment relationship, that conditions placed on such employment shall be based on evidence of threatened misappropriation and not merely on the information the person knows, and that it may not otherwise conflict with an applicable state law prohibiting restraints on the practice of a lawful profession, trade, or business — so the record is built around acts, not around what the employee carries in her head. And § 1839(3) requires that the owner has taken reasonable measures to keep the information secret and that it derives independent economic value, actual or potential, from not being generally known to, and not being readily ascertainable through proper means by, another person who can obtain economic value from its disclosure or use: the NDA, the access-control configuration, the classification labels, and the offboarding checklist belong in the same 72-hour collection. That record either hardens the claim or shows there is nothing to file.

Where the investigation has to stop

Company ownership of a device is not authorization to open the personal accounts reachable from it. Under 18 U.S.C. § 2701(a), it is an offense to intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access that facility, and thereby obtain, alter, or prevent authorized access to a wire or electronic communication while it is in electronic storage in such system. The § 2701(c) exceptions run to conduct authorized by the person or entity providing the service, or by a user of that service with respect to a communication of or intended for that user — not to the owner of the hardware. Section 2707 gives an aggrieved person a civil action where the conduct constituting the violation was engaged in with a knowing or intentional state of mind; recovery is the plaintiff's actual damages plus any profits made by the violator, and in no case shall a person entitled to recover receive less than $1,000, with punitive damages available if the violation is willful or intentional and reasonable attorney's fees and litigation costs recoverable.

A personal webmail session left logged in, or a password saved in a browser profile, is a technical opportunity, not consent. State law adds its own limits, and they are state-specific. California Labor Code § 980 bars an employer from requiring or requesting that an employee or applicant disclose a username or password for accessing personal social media, access personal social media in the employer's presence, or divulge any personal social media — and § 980 defines "social media" broadly, reaching email, text and instant messages, and online accounts, not only social networks. Subdivision (c) is a savings clause rather than a grant of investigative authority: nothing in the section affects an employer's existing rights and obligations to request that an employee divulge personal social media reasonably believed to be relevant to an investigation of allegations of employee misconduct or employee violation of applicable laws and regulations, provided the social media is used solely for that investigation or a related proceeding. Subdivision (d) separately provides that nothing precludes an employer from requiring or requesting a username, password, or other method for the purpose of accessing an employer-issued electronic device — the device, that is, not the personal accounts reachable through it.

So the forensic protocol is written before the examiner touches the image: which containers are in scope, which search terms run, who reviews hits, and what happens to obviously personal or privileged material. A neutral can set it where the parties cannot agree — see working with a discovery special master.

Building a record that supports relief

Rule 65(d)(1) requires every order granting an injunction and every restraining order to state the reasons why it issued, state its terms specifically, and describe in reasonable detail — and not by referring to the complaint or other document — the act or acts restrained or required. That works backward into the investigation: relief has to name systems, repositories, and categories of material, so the examiner's declaration should state which artifact, on which system, at which timestamp, in which time zone, and what it does not show. Where the conduct also touched external accounts or messaging platforms, authentication is its own exercise; see authenticating social media evidence.

Rule 34(a)(1) permits a request to inspect, copy, test, or sample designated electronically stored information, but the 2006 Committee Note cautions that adding testing and sampling "is not meant to create a routine right of direct access to a party's electronic information system, although such access might be justified in some circumstances," and that courts "should guard against undue intrusiveness resulting from inspecting or testing such systems." A demand to image the new employer's machines needs specific predicate facts; suspicion plus a device-recognition event will not carry it.

Learn more

Faculty on the platform include Claude M. Stern, a neutral at JAMS and former Chair of IP Litigation at Quinn Emanuel; Katherine Charonko, Partner and ESI Practice Group Leader at Bailey & Glasser; Gail Gottehrer, VP, Global Litigation, Labor & Employment, and Government Relations at Fresh Del Monte Produce, Inc.; and JAMS neutrals Gregory M. Sleet and James Orenstein.

This article is general information, not legal advice; consult counsel about your specific matter.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.