Does an employee account identify the employee who acted?¶
The practical answer¶
No. Activity recorded against an employee account does not automatically prove that the employee personally performed it.
The key evidential caution¶
The dangerous assumption is that account attribution equals personal attribution.
The account may have been:
Key points¶
- shared
- left logged in
- used through remote access
- compromised
- accessed from a shared device
- used by an administrator
- operated by automation
- used after employment ended
What investigators should establish¶
Investigators should establish:
Key points¶
- which device and session used the account
- what authentication occurred
- whether multi-factor authentication was involved
- whether the employee was present and working
- whether the action matched their normal pattern
- whether credentials were shared or exposed
- whether another account or process controlled the activity
The employee’s explanation should be tested against technical records.
Evidential limits¶
Do not treat denial as proof of compromise.
Likewise, do not treat a successful login as proof the employee knowingly acted.
Relevant evidence¶
Relevant evidence may include device identifiers, session records, physical-access data, communications, remote-access logs, command history, browser records and witness evidence.
Where physical-access records are available, compare them cautiously with the digital timeline. Badge use may show entry to a building, not use of a particular device, and remote work may explain account activity without physical presence. Several weak indicators should not be presented as one decisive fact.
Also compare whether the employee’s normal device was itself compromised or remotely controlled. Evidence of malware, unusual remote sessions or token theft may explain apparently personal account activity and should be resolved before drawing an insider conclusion.
Operational takeaway¶
Treat employee-account activity as technical attribution to an identity, and require device, session, behavioural and contextual evidence before attributing it to the person.