The situation
An IT services firm delivering client projects faced recurring fears of source code and credential exfiltration when engineers resigned.
Two confirmed exfiltration events in 12 months involved departing engineers using personal cloud uploads. Average internal investigation took 19 days because VPN and git logs lacked endpoint context.
Key Takeaway: Server logs without endpoint behavior tell you files moved, not how they left the laptop.
Solution
EnDetect with elevated monitoring for notice periods, cloud upload blocking, and forensic add-on for investigations. Shadow IT discovery surfaced 40+ unsanctioned SaaS tools in the first scan.
Roughly 30 engineers on active client IP projects received forensic depth during notice period. The remaining 120 ran attendance, idle, and USB/cloud alerts without full keystroke capture.
Key Takeaway: Forensic on notice-period and IP-heavy roles matches how ~20% of EnDetect customers deploy the module.
Results
Three departure-related incidents were detected before data left the environment: bulk repo archive, personal cloud upload attempt, and USB copy to unapproved drive.
Investigation timelines improved from 19 days to 6.5 days average using EnDetect forensic exports with chain-of-custody tags. Legal closed two cases with packaged evidence instead of disk imaging every laptop.
Key Takeaway: Stopping exfiltration beats post-leak forensics. Faster investigations reduce client notification risk.
Replicate this
Connect HR resignation dates to an elevated EnDetect policy this quarter. Run shadow IT discovery once before you block uploads. On the next notice-period exit, time how long forensic export takes versus your old manual log pull.
Key Takeaway: HR-triggered elevation plus one timed investigation drill proves ROI before the next resignation.
Want similar results for your team?
Book a Demo