TCDI Talks | Episode 27

Departing Employee Data Preservation: Establish the Facts Before Escalating

About TCDI Talks: Episode 27

When a departing employee’s activity raises concern, how can legal teams protect potential evidence without turning every possible warning sign into a full-scale investigation?

In this episode of TCDI Talks,  Michael Gibeault sits down with Jake Brown, Senior Director of Legal Services at TCDI, to explore how organizations can respond when activity before a departure raises questions about whether company information may have walked out the door with an employee.

Waiting too long can allow devices to be reassigned and system logs to disappear, but immediately launching a broad investigation can create unnecessary cost and disruption. Jake explains how preserving a focused set of relevant data gives counsel time to assess the situation while keeping its options open, without presuming that misconduct occurred.

This 10-minute conversation examines how a targeted forensic assessment can help establish what happened and place individual digital artifacts in the proper context. Jake also discusses how early findings can guide a proportionate response and, when escalation is warranted, narrow the scope of a subsequent eDiscovery effort.

Most employee departures happen without incident. However, when concerns do arise, a disciplined preservation plan allows reliable facts to guide the response, helping organizations avoid using a sledgehammer when a flashlight will do.

Episode 27 Transcript

Welcome to TCDI Talks, where we spotlight the people and ideas driving innovation in legal services and technology. I’m your host, Michael Gibeault, and today employee departures are a routine part of business and most happen without incident.

Occasionally, however, unusual downloads, access to sensitive folders, or the use of external devices or personal cloud accounts can raise concerns about whether company information may have left with an employee. When that happens, legal teams face a difficult question.

How do they protect potential evidence and establish the facts without overreacting or launching unnecessary broad investigations?

Today, I’m joined by my teammate Jake Brown, senior director of legal services at TCDI and author of the most recent article, When an Employee Leaves: How to Preserve Data and Assess Potential Misuse. Jake, thanks for joining us.

1:08 – Jake Brown

Hey, happy to be here. Thanks for having me.

1:08 – Michael Gibeault

So, Jake, most employee departures happen without incident. What warning signs might prompt an organization per to preserve data or conduct an initial assessment?

1:23 – Jake Brown

Well, most departures are routine. But unusual activity can raise questions such as large downloads, access to sensitive folders, personal cloud uploads, connected USB devices, mass deletions, or a move to a direct competitor. The employee’s role and access to confidential information also matter.

1:44 – Michael Gibeault

Well, Jake, in-house council, you know, they must avoid responding either too slowly or too broadly. What risks arise when an organization waits too long to act?

1:57 – Jake Brown

Well, potential evidence can disappear quickly. Devices may be wiped or reassigned. Accounts deactivated. System logs overwritten leaving council with fewer facts just when the stakes begin to rise.

2:10 – Michael Gibeault

Jake, tell me what can happen when an organization goes to the other extreme and immediately launches a full forensics investigation or broader eDiscovery project.

2:22 – Jake Brown

Well, a full investigation can be expensive, disruptive, and disproportionate to the initial concern. It may also collect unnecessary personal or business information and create a much larger review project before council knows what actually matters.

2:37 – Michael Gibeault

So, your recommendation approach is to preserve first. What does that mean in practice? And, why is preservation not the same as accusing an employee of misconduct?

2:51 – Jake Brown

Yeah. It means protecting the most relevant devices, accounts, and records before information can change or disappear. Preservation is not an accusation. It simply keeps the organization’s options open while council determines whether there is a real issue.

3:06 – Michael Gibeault

Well, you mentioned devices. So, what which devices, accounts, or other data sources should an organization consider preserving when a concern arises?

3:17 – Jake Brown

Possible sources include company computers, mobile devices,  obviously email, cloud storage, collaboration platforms like Slack or Teams, external drives in relevant access or security locks. The right sources will vary with the employee and the concern.

3:35 – Michael Gibeault

Jake, tell me how should the employee’s role, the access to sensitive information, timing of the activity, and even the nature of the concern influence the scope of the preservation?

3:49 – Jake Brown

Preservation should be risk-based. A senior employee with access to trade secrets who joins a competitor may justify a broader response than an employee with limited access and no unusual activity. 

4:01 – Michael Gibeault

Legal, HR, IT, and information security may all play a role in the response. How should those teams coordinate during the initial stages?

4:13 – Jake Brown

Legal should generally direct the response with HR providing employment contacts and IT and security helping identify and protect the relevant systems. One clear decision maker and a documented plan help prevent gaps, duplication, and accidental changes to evidence.

4:29 – Michael Gibeault

Okay. So tell me Jake, why are documentation, evidence integrity, the chain of custody important even if the organization has not decided whether a formally uh investigation will follow?

4:43 – Jake Brown

Well, even if the matter ends quietly, the organization should be able to explain what it preserved, how it was handled, and who had access. If the matter does escalate, that record helps demonstrate that the evidence remained reliable and defensible.

4:57 – Michael Gibeault

So, once the relevant evidence has been protected, if you will, what questions can a targeted forensic assessment help counsel answer?

5:07 – Jake Brown

It can help determine whether files were accessed, copied, uploaded, deleted, or transferred. Whether external drives or personal accounts were used, and when those activities occurred. We can also identify whether additional evidence should be preserved.

5:21 – Michael Gibeault

Jake, you caution against viewing individual digital artifacts in isolation. So, for example, connecting a USB device does not necessarily prove that the information was taken. How should organizations interpret forensic findings within the broader context, if you will?

5:42 – Jake Brown

Well, digital artifacts are clues. They’re not automatic conclusions. A USB connection or file access should be evaluated alongside timing, job responsibilities, normal work habits, company policies, and other corroborating evidence.

5:57 – Michael Gibeault

In your article, Jake, the example of a senior employee assessing sensitive folders shortly before leaving for a competitor. What might a focused initial assessment look like in that situation?

6:12 – Jake Brown

Yeah, the organization might preserve an employee’s laptop and relevant cloud accounts, then examine activity during the final days or weeks of employment. The review could focus on sensitive folder access, external drives, cloud uploads, file deletions, and the timing of those events.

6:30 – Michael Gibeault

So, what possible outcomes can follow the assessment, including, you know, circumstances which counsel may decide that no further action is necessary?

6:42 – Jake Brown

Yeah, I mean counsel might just close the matter. They might address a policy or security weakness, monitor the situation, request the return of information, something was stolen, preserve more sources, or even escalate to a deeper investigation. Sometimes the best outcome is confirming that the activity was routine and no further action is necessary.

7:04 – Michael Gibeault

So, Jake, where does eDiscovery fit if the matter develops into an internal investigation or demand or regulatory inquiry or even a lawsuit?

7:16 – Jake Brown

Well, digital forensics helps establish what may have happened. If the matter expands into an investigation, a demand injunction, regulatory inquiry, or even a lawsuit, eDiscovery helps collect, process, search, review, and produce the broader body of relevant information.

7:35 – Michael Gibeault

How can early forensic findings help council narrow the custodians, the data sources, the date ranges, and even the search criteria involved in a subsequent eDiscovery effort?

7:48 – Jake Brown

Yeah. Forensic findings can identify the people, systems, dates, file types, and activities that actually matter. That allows council to define more precise custodians, data sources, date ranges, and search criteria instead of starting with an unnecessarily broad collection

8:06 – Michael Gibeault

Jake, you talk about organizations should not wait for a high-risk departure to develop a response plan. What should an effective employee offboarding and data prevention protocol establish in advance?

8:21 – Jake Brown

That’s a good one. It should define which events trigger review, who must be notified, who makes decisions, which sources may require preservation, when outside council or forensic support should become involved.

A good protocol helps the organization act quickly, consistently, and proportionately without treating every departure like a five alarm fire.

8:43 – Michael Gibeault

So, Jake, tell me: you’ve got a lot of experience here. How does TCDI’s employee mobility forensics approach help legal teams preserve the right information, assess the highest risk activity, and even determine a proportionate next step?

9:00 – Jake Brown

At TCDI, we start by defensively preserving a focused set of relevant sources such as the employee’s computer, their mobile device, their email,  or even their cloud storage. We then assess the highest risk activities such as unusual file access, downloads, external devices being plugged in, cloud transfers or deletions, and organize the findings for counseling.

Those facts help the legal team decide whether to close the matter, monitor or remediate an issue, preserve additional evidence, or escalate to a full investigation, or even discovery, without using a sledgehammer when a flashlight will do.

9:41– Michael Gibeault

That’s a great takeaway, Jake.

9:44 – Jake Brown

The goal is not to treat every employee departure as a potential dispute. It’s to have disciplined process for protecting evidence, establishing reliable facts, and allowing those facts to guide the organization’s response.

10:00 – Micheal Gibeault

Jake, thank you so much for joining us today and providing your perspective.

10:04 – Jake Brown

It was a pleasure. I’ve enjoyed this very much. I hope to do another one soon.

10:08 – Michael Gibeault

Well, if you’d like to read Jake’s full article or keep up with what’s next at TCDI, visit tcdi.com or connect with us on LinkedIn. Thanks again for joining us and we’ll see you next time on TCDI Talks.

Meet the Expert Behind the Topic

Jake Brown | Senior Director, Legal Services | TCDI

Jake Brown is an experienced business development leader with deep experience in digital forensics, electronic discovery, managed document review, and technology-enabled investigations. He has also been recognized for a consultative, client-centered approach that helps law firms and corporate legal teams navigate complex matters with greater clarity, efficiency, and confidence.

Meet Our Host

Michael Gibeault | Senior Vice President, Legal Services | TCDI

As Senior VP, Legal Services, Michael Gibeault works closely with corporate legal and law firm clients alike, providing forensics, eDiscovery, and managed document review solutions while managing a team of Legal Services Directors.

Michael’s tenured career has focused on supporting law firms and corporate legal departments with creative and cost-effective solutions that rely on cutting-edge technology and highly skilled legal professionals. Prior to joining TCDI in 2017, he served in executive positions at DTI Global, Epiq, Robert Half International, LexisNexis, and Martindale Hubbell.

In Case You Missed It