The notice period ends, the laptop comes back factory-fresh, and a month later your quotes start losing to a familiar name. For employers around Swindon — from the units at Kembrey Park and Cheney Manor to professional practices in Old Town — we retrieve the evidence a reset machine still holds. Freephone advice and a free diagnostic come first.
Quiet, methodical, defensible. Nothing starts until the free diagnostic is finished and you have approved a written scope; forensic fees are then settled upfront.
Any one of these is a reason to lock the machine away, unused, until it has been imaged — whether your firm sits in Swindon, Chippenham or Royal Wootton Bassett.
A laptop that comes back reset tells you something before any examination starts: ordinary leavers do not scrub their machines. The reset clears the desktop and the visible folders, but it seldom reaches the deeper record — registry hives that survive, the footprint of the erasing tool and the minute it ran, and unallocated space still holding a good proportion of the deleted documents, waiting to be carved back out. Around Swindon we see the same rhythm again and again: a fortnight of quiet copying, then one loud deletion on the final day.
Windows is an obsessive record-keeper. Each stick or portable drive ever attached is logged by make, model and serial number in the USBSTOR registry key; the setupapi log notes when it first appeared; MountPoints2 ties it to the user profile that mounted it. LNK shortcuts and jump lists then show named company documents being opened from a removable drive letter, shellbags keep the shape of the folders explored on the device, and Windows' change journal timestamps file operations minute by minute. Laid out in order, those artefacts read less like a suspicion and more like an itinerary.
Plenty of exfiltration happens in a browser tab instead. We reconstruct webmail sessions where attachments went to a private address, uploads pushed through transfer services, and folders synchronised into a personal OneDrive, Dropbox or Google Drive. Sync-client logs record what went up and when; deleted emails come back out of unallocated space. The finished timeline covers every exit the data could have taken, not just the one somebody happened to notice.
Everything is done on the assumption that the other side's expert will check it. The drive is imaged through a hardware write-blocker and the copy proven identical by MD5 and SHA-256 checksums; each handover of the exhibit is entered in the custody record. OSForensics carries the analysis, Passware Kit Forensic opens password-protected material where the law allows, and the report puts plain-English findings first with the technical workings in an appendix behind them. Directions agreed with your solicitor are followed to the letter.
The discipline underneath this page — write-blocked imaging, hash verification, logged custody — is walked through on our forensic data recovery hub. Fees on forensic cases are settled upfront: the standard investigation runs to £800 + VAT with its full written report, while the forensic binary-image and deleted-file option at £400 + VAT skips the report; the data recovery cost page lists the pair. Should the laptop come back encrypted, BitLocker recovery opens it first with the key your business holds.
Imaged properly, one company machine usually gives up all six of these threads at once.
Make, model and serial of every stick attached, with first and last dates.
LNK and jump-list entries pinning documents to a removable letter.
Shellbag records of the directories explored on the device.
USN change-journal activity across the weeks that matter.
Private-address sends, transfer uploads and cloud-client logs.
Recovered documents plus the wiping tool's own footprint.
Equipment the company owns and issued is legitimate ground; a personal device needs a proper footing such as a signed acceptable-use policy or a solicitor's instruction; covert access to an ex-employee's own phone or home computer is work we refuse, every time. While you decide next steps, treat the laptop as an exhibit rather than a spare: power it down, lock it away, and tell IT it must not be rebuilt or handed to the next starter — a reinstall grinds away precisely the traces the case needs.
An exhibit is not an ordinary parcel, so ring 0800 689 0668 before boxing anything up. We will agree the packaging and paperwork with you, and custody is recorded from the second the device is signed for at our Oxford location — under an hour up the A420, or next-day by tracked post.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Lock the machine away and pick up the phone — imaging early is what keeps the evidence intact.