forumNew topic

When is digital forensics required: How should the process work for a suspicious employee computer?

MMusaNew member
Job title
Intercity freight
Joined
Oct 2024
Message
34
#1

We are a 25-person machinery manufacturing and design firm. Our head of R&D resigned last week, and we noticed in our server logs that around midnight right before leaving, roughly 40 GB of technical drawings and client portfolio files were copied to an external drive. When we called him in to discuss the matter, he refused to meet, stating he had officially severed ties with the company. Our legal counsel advised us to file a formal criminal complaint directly with the public prosecutor's office for unfair competition and trade secret misappropriation.

Right now, that computer is sitting on a desk in the office, powered off. Our internal IT admin wanted to boot it up, look through the files, and browse the folders to list exactly what was taken, but I didn't let him touch it out of concern that the chain of custody would be broken. At this point, what exactly does a digital forensics investigation entail, and is it genuinely necessary for us to bring in an outside specialist?

Should we report it to the prosecutor's office without turning the machine on at all, or should we get a technical report from an independent expert first and attach it to the file before going to court? I want to know what exact steps we need to take so our evidence isn't deemed inadmissible in court.

ÖÖzgür K***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
8-person team
Joined
May 2025
Message
79

Doki · Mobile app · 2023

Most Helpful#2

Short answer: Digital forensics is the process of examining digital evidence by acquiring an untampered, verifiable copy using cryptographic hashes so that it holds up in court. In your situation, booting up the machine and browsing files will alter access and modification timestamps; you must not touch the device and should have a professional forensic image taken before making any formal filings.

The moment you boot up a computer normally, the OS creates hundreds of temporary files, updates the registry, and overwrites logs relevant to the incident. If opposing counsel argues in court that "internal IT staff copied or altered these files," you won't be able to prove otherwise. A digital forensics expert will not connect the drive directly; they use hardware write-blockers to take an exact forensic image of the drive. Then they generate an MD5 or SHA-256 hash value for that image. This hash serves as technical proof that not a single character of the evidence was altered.

You have two paths here: First, seal the device as-is, file a criminal complaint with the prosecutor's office, and wait for a court-appointed expert witness. This costs nothing, but an expert review through the prosecutor's office can drag on for months, during which the suspect could exploit that data commercially. Second, petition the court for urgent "determination of evidence" or obtain an expert legal opinion (under HMK 293) from a qualified digital forensics specialist and attach that report to your complaint. If those stolen drawings represent your core business capital, having an independent expert pull an image and draft a report will speed up the process significantly.

İİlknur A***New member
Job title
General coordinator
Sector
Textile
Organization type
early-stage startup
Joined
Jun 2026
Message
59
#3

Pull the plug, close the lid and do not touch that power button under any circumstances. Draft an official incident report signed by two authorized employees and lock the device in the company safe or a secure cabinet. Clearly document the computer's make, model serial number, and the condition of the tamper-evident security tape on the report.

NNergisMember
Job title
Compliance Officer
Joined
Jan 2024
Message
104
#4

To run an investigation on company machines, the information security policy and disclosures signed by the employee during onboarding are critical. If you don't have an asset assignment form stating the hardware was allocated strictly for business use, your investigation could be turned back on you in a countersuit claiming a violation of personal privacy.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#5

We went through a similar thing last year. We hired an independent firm to image two computers and provide a forensic report, and they billed us 32.000 TL in total. But thanks to that report, the prosecutor's office issued a seizure warrant for the digital materials at the suspect's home within 3 weeks. In my opinion, it was totally worth the money.

DDamla Y***MemberCommunity member
Joined
Sep 2022
Message
131
#6

USB connection logs are examined to detect unauthorized copying. By analyzing the USBSTOR keys in the Windows Registry, the 'setupapi.dev.log' file, and 'Shellbags' data, it can be established with 100% technical certainty which external drive (by serial number) was plugged in, when it was connected, and which folders were viewed.

CCansu K***MemberCommunity member
Joined
Jun 2023
Message
61
#7

On the computer the employee used was there a personal email account or personal session logged in outside of company ownership? Also, regarding the 40 GB transfer log you mentioned on the server side, is that specifically network traffic logs or file server access permission logs?

edit: I wrote something wrong above, sorry about that.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Textile
Organization type
workshop
Joined
Feb 2022
Message
76
#8

Even if you pour a fortune into a private digital forensics firm, the court won't base its judgment solely on that report. The moment the opposing party objects, the case will be sent to an official court expert anyway. If your company budget is tight it might make more sense to hand it directly over to the prosecutor's office and have it taken into evidence storage.

ÜÜmit Ş***MemberCommunity member
Joined
Apr 2022
Message
81
#9

Three years ago in a similar case, our company manager turned on the computer plugged in a USB drive, and copied screenshots. During the trial the opposing counsel argued "Files were accessed at this hour, my client was not at the company at that time and the evidence has been tampered with," which got the report thrown out and we lost the lawsuit. That's why you should never touch it.

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#10

definitely dont let the it guys touh the device... back when we had this a guy turned on the pc saying he'd check the logs and the whole case blew up in court, best to leave it to the pros.

İİsmail Ş***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Apr 2024
Message
32
#11

To get into the details: When you try to change everything at once, nothing settles.

Proven by experience.

YYasemin Ö***MemberCommunity member
Joined
Apr 2023
Message
20
#12

You're right.

YYağmur S***MemberCommunity member
Joined
Jun 2023
Message
13
#13

Quick summary for newcomers: The answer varies greatly by industry; there is no one-size-fits-all rule.

That's all, sorry if I went on too long.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#14

I feel the same way. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Hope this helps.

MMehmet G***Member
Job title
Accounting clerk
Sector
Education
Organization type
boutique agency
Joined
Sep 2023
Message
78
#15

Let me write how it's done in practice. If 2FA is on, a stolen password alone is useless.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection. If I were you, I'd go this route.

AAyşe Y***MemberCommunity member
Joined
Jun 2024
Message
10
#16

let me clarify the techniacl side. start with a small trial; don't commit to everything at once.

if I were you, I'd go this route.

AAlper B***MemberCommunity member
Joined
Jul 2022
Message
304
#17

Good call starting this thread.

GGizem K***Member
Job title
Human Resources Manager
Sector
Logistics
Organization type
workshop
Joined
Nov 2022
Message
49
#18

Thanks that was the answer I was looking for... honestly the real issue isn't the number but what it's based on.

The biggest time-waster for us was not knowing who had the final say. Hope this helps.

BBeyza B***MemberCommunity member
Joined
Aug 2024
Message
1
#19

Thanks, this was very helpful. Start with a small trial; don't commit to everything at once.

When making a decision, first look at what data you have on hand. If you have questions, write them; I'll answer as best I can.

TTuğçe M***Member
Job title
Software team lead
Sector
Education
Organization type
early-stage startup
Joined
Jul 2024
Message
217
#20

Noted thanks. Mistakes made on the what is digital forensics side are usually reversible but expensive.

Reply