A colleague may have taken files and data – how can I tell?

The scenario is one that causes companies a massive headache. A member of your team, perhaps disgruntled after an incident, may have taken files or data belonging to the company – or worse, to customers. For the admin team, this scenario is a nightmare. Fortunately, there’s some easy ways to if not prevent, then at least trace and mitigate this.

What is a chain of custody and why does it matter?

The main way to prevent a number of common misuses of authority, data theft or other problems is by establishing and following a clear chain of custody. In brief, the chain of custody is the chronological documentation of a given document or piece of data – the paper trail showing who accessed, moved, downloaded, or altered a given document.

Being able to establish a chain of custody for a given piece of data makes it less likely there will be any data leaks or misuse to begin with, since it helps maintain a greater degree of accountability. However, it is also not as simple as it sounds, especially for large organizations with potentially terabytes of data and dozens if not hundreds of individuals working with stored information.

by Matúš Koronthály