home  /  insights  /  employee-left-with-files-what-to-do-first
Trade Secrets

An employee left and we think they took files. What do we do first?

Preserve, before you investigate and well before you decide whether to act. The devices go back into the reimaging pool on roughly a two-week cycle.

September 9, 2026 · 4 min read

The short answer

Pull their laptop and phone out of the reimaging queue and have them forensically imaged; suspend automatic deletion on their mailbox and accounts rather than closing them; and capture badge, VPN, file access and email logs for the preceding several months. Do not examine the device yourself first — it alters timestamps and hands the other side an argument about the integrity of your evidence. Everything else, including whether to send a letter or sue, can wait a fortnight. This cannot.

What this article establishes

  • Ordinary IT process destroys this evidence within weeks, with nobody doing anything wrong.
  • Examining the device before imaging is the most common self-inflicted wound.
  • Copying files proves acquisition, not misappropriation — pattern is what carries the inference.
  • A defendant with a contemporaneous development record has a genuinely strong answer.

What exactly should be preserved in the first week?

Four things, and all of them are administrative rather than technical. Take the departing person’s laptop and phone out of the reimaging queue and have them forensically imaged by someone who does this properly. Suspend automatic deletion on their mailbox, cloud storage and collaboration accounts rather than closing the accounts, because closure often triggers the deletion you are trying to prevent.

Capture badge, VPN, file access and email logs for at least the preceding several months while they still exist. And issue a written hold covering all of it. The whole exercise takes an afternoon of somebody’s time, costs almost nothing, and is entirely irreversible in the other direction.

Why not just look at the laptop first?

Because examining a device before it is forensically imaged alters it. Opening files changes access timestamps, connecting the machine to the network can trigger synchronisation, and booting it modifies dozens of artefacts that a forensic examiner would otherwise have relied on. The information you were hoping to find gets degraded by the act of looking for it.

The more serious cost is evidentiary. A defendant will argue that your own handling compromised the record, and that argument lands harder than it should because it is partly true. Image first, then examine the image. The order costs you a day and preserves everything.

Does evidence that someone copied files prove misappropriation?

It proves acquisition, which matters and is not the whole claim. Employees copy files for entirely mundane reasons — working from home, keeping portfolio material, personal photographs mixed into a work folder — and defendants make those arguments credibly because they are frequently true.

What carries the inference is pattern rather than the act itself. Breadth well beyond the person’s actual role. Timing that tracks the resignation date rather than their work. Material of no conceivable personal use. Deletion or wiping activity afterward, which often proves more than the copied material would have. One file copied three months before departure is noise; four hundred files copied the weekend before is a pattern.

How is an independent development defense assessed?

On its own evidence, and it is a complete defense when it holds. Reverse engineering a lawfully obtained product and independent development are both proper means of acquiring information, and neither is misappropriation — that is one of the fundamental trade-offs of trade secret protection as against a patent.

The question is whether the defendant’s record shows a path to the result that does not require the secret: dated design documents, version control history, test results, procurement records. A rich contemporaneous record is very persuasive. A thin one, or one that begins abruptly after the hire, is where comparison analysis does its work — because independent developers do not reproduce another organization’s mistakes. Shared errors, dead code, odd naming conventions and vestigial artefacts are the tell.

What if the information has already reached the new employer’s systems?

That raises exposure for the new employer and a set of time-sensitive questions that belong with counsel immediately, because the sensible responses — quarantine, forensic examination, sometimes voluntary disclosure — interact with privilege and with each other.

On the technical side, the useful work is establishing precisely what arrived, where it went inside the organization, and whether it was actually opened and used or sat unread in a folder. Those are materially different findings with materially different consequences, and they are distinguishable from the forensic artefacts. Assuming the worst before that analysis is done is a common and expensive reflex.

For informational purposes only. Not legal advice, not an opinion on the infringement or validity of any patent, and not an opinion on whether any information is a trade secret.

Related

The practice area

IP conciergeorientation · not an opinion on your patent
Happy to. Tell me roughly what is asserted, against what, and what stage the matter has reached. If it involves a recent departure, whether the devices have been reimaged yet is worth establishing first.