Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / Something found

Recovery: Data, Access and Relationships

After a substantiated finding there is practical work: retrieving what left, closing what was open, and repairing what the case disturbed.

The editors · About the editorial position · Something found · Procedure

The outcome is decided and the operational work begins. It is frequently left incomplete because everybody's attention moved to the employment process.

The outcome in “Recovery: Data, Access and Relationships” must rest on evidence that has been checked against context. Data from explore the product, when used for task switching cost, can support a chronology of work or project activity, but it should not replace the employee response, corroboration or a proportionate decision process.

The data

Where did it go, and is it still there.

For a separate perspective relevant to “Recovery: Data, Access and Relationships”, consult the FBI counterintelligence resources. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

A copy on a personal device, in a personal cloud account, with a third party, or already with somebody else — each has a different route to recovery and a different likelihood of success.

What can be asked for: deletion, confirmation of deletion, return of devices. What cannot be compelled: access to somebody's personal property, which the practical position on personal devices covers.

Where recovery is not possible, the honest step is to record what is outstanding and mitigate at the system end: credentials changed, tokens revoked, affected accounts monitored, anybody downstream notified if a duty applies.

The access

Everything the person held, closed in a controlled sequence.

Not only the obvious systems: shared accounts they knew the credentials for, third-party services registered in their name, physical access, anything delegated to them.

This is a list-driven task and the list is usually incomplete. A good exercise afterwards is checking what was found during the case that was not on the access register — the gap is itself a finding.

The permissions that should not have existed

Most substantiated cases reveal access that was broader than the role required, frequently inherited through role changes.

Fixing that for the individual is necessary and insufficient. The question is how many other people have the same inherited breadth, and the answer is usually several.

This is the most valuable output of a substantiated case and it is regularly discarded once the person has gone.

The team

Colleagues worked alongside somebody who has now left under a cloud, and they have questions nobody will answer.

Say as much as can properly be said: the matter is concluded, the person has left, we are not able to discuss the details, here is what is changing as a result.

Silence is filled by rumour, and the rumour is frequently both worse and wrong, which affects the people still there.

The person who reported it

They may be identifiable to colleagues. Check whether they are exposed and act on it if they are.

A reporter who suffers for reporting is the end of the reporting channel, permanently.

The process fix

Whatever allowed it. Documented, assigned, and tracked to completion.

A case that ends with a dismissal and no change to the arrangement that permitted the conduct has addressed one person and left the condition in place.

The access register gap

Substantiated cases routinely reveal access nobody knew existed: shared accounts, third-party services registered personally, permissions inherited through role changes. The gap between what the register showed and what was found is itself a finding, and it applies to everybody rather than to the one person.

Protecting the reporter

Check whether they are identifiable to colleagues and act if they are. A reporter who suffers for reporting ends the channel permanently, and the exposure is usually obvious to everybody except the people running the case.

The outstanding column

What left, what was recovered, what was not, and what was done instead. The last two are usually blank because nobody wrote them, and they are the entries a later review actually needs.

The permission that should not have existed

Most substantiated cases reveal access broader than the role required. Fixing it for the individual is necessary and insufficient: the question is how many others carry the same inherited breadth, and the answer is usually several.

What cannot be recovered

Record it and mitigate at the system end: credentials changed, tokens revoked, accounts watched, duties assessed. An honest outstanding column is worth more than a pursuit that will not succeed.

For the file: List what left, what was recovered, what was not, and what was done instead. The outstanding column is the one that matters and it is usually blank because nobody wrote it.