Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does copying data prove malicious intent?

No. Casework, backup, analysis, migration, handover and remote work can all require copying. The destination, authority, selection and later use - not size alone - determine its evidential meaning.

Explain the copy event

Identify source data, destination, account, process, time, approval and business purpose. A large authorised export may be routine; a small targeted copy can be significant.

Synchronisation or backup may continue automatically after a person enables a service or selects a folder. Separate that initiating decision from each later automated transfer while preserving responsibility for the setup where supported.

Build evidence of purpose

Personal storage or removable media can breach policy without proving a plan to steal or harm. Examine communications, concealment, retention, sale, disclosure or later use.

Deletion or movement after copying may support improper purpose, but legitimate cleanup and policy compliance remain alternatives to test. State copying, authority breach and malicious intent as separate conclusions.

Key takeaway

Treat copying as an action requiring explanation and infer malicious purpose only from destination, authority, concealment, communication and later use.

Reference: CIM-236Cyber Incidents & Offender Methods