Skip to content
CIM-233 Cyber Incidents & Offender Methods

Does an employee account identify the employee who acted?

The practical answer

No. Activity recorded against an employee account does not automatically prove that the employee personally performed it.

The key evidential caution

The dangerous assumption is that account attribution equals personal attribution.

The account may have been:

Key points

  • shared
  • left logged in
  • used through remote access
  • compromised
  • accessed from a shared device
  • used by an administrator
  • operated by automation
  • used after employment ended

What investigators should establish

Investigators should establish:

Key points

  • which device and session used the account
  • what authentication occurred
  • whether multi-factor authentication was involved
  • whether the employee was present and working
  • whether the action matched their normal pattern
  • whether credentials were shared or exposed
  • whether another account or process controlled the activity

The employee’s explanation should be tested against technical records.

Evidential limits

Do not treat denial as proof of compromise.

Likewise, do not treat a successful login as proof the employee knowingly acted.

Relevant evidence

Relevant evidence may include device identifiers, session records, physical-access data, communications, remote-access logs, command history, browser records and witness evidence.

Where physical-access records are available, compare them cautiously with the digital timeline. Badge use may show entry to a building, not use of a particular device, and remote work may explain account activity without physical presence. Several weak indicators should not be presented as one decisive fact.

Also compare whether the employee’s normal device was itself compromised or remotely controlled. Evidence of malware, unusual remote sessions or token theft may explain apparently personal account activity and should be resolved before drawing an insider conclusion.

Operational takeaway

Treat employee-account activity as technical attribution to an identity, and require device, session, behavioural and contextual evidence before attributing it to the person.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.