IT Forensics · Business

What role can MDM play in an internal IT forensic investigation?

Mobile device management can document device identity, compliance status, configurations and administrative actions, and can therefore be a valuable technical resource.

Enquire without obligation

Why this question is important for a business

In the case of internal incidents, commercial interests, the preservation of evidence and employees’ rights may all be affected simultaneously. A technically wide-ranging investigation is therefore not automatically a good one. What is crucial is a clearly defined question of evidence and a transparently limited scope of the investigation.

Technical investigative approach

We examine which MDM data have actually been collected in the specific system, what conclusions can be drawn from them from a technical perspective, and whether their use is legally permissible for the specific investigation.

Where the limits of what can be said lie

MDM provides technical means of administration, but does not confer a blanket right to monitor employees. Depending on how it is implemented, data protection and employee participation in company affairs may be relevant.

Why LanCologne?

Internal investigations involve a direct clash of several interests: the company must be able to protect its systems, data, trade secrets and commercial interests. At the same time, employee data protection, proportionality, co-determination and, where applicable, the protection of private data must be observed.

LanCologne therefore does not begin by collecting as much data as possible. The starting point is the specific technical question to be investigated. Only then is it determined which devices, accounts, time periods and types of data are actually required. This often allows an investigation to be carried out much more precisely than a blanket, comprehensive analysis would.

Technical availability and legal permissibility are deliberately kept separate. The fact that an administrator, MDM system or cloud tenant technically enables access to certain information does not in itself answer the question of whether that information may be processed for the specific purpose in question.

Key findings are validated against primary data where necessary. Automated reports and forensic software are tools; they do not replace the expert interpretation of the underlying artefacts. Alternative technical explanations are also examined.

Equally important: an internal investigation must take exonerating facts just as seriously as incriminating ones. If the analysis reveals that a suspicion cannot be technically confirmed, or that a notable incident can be explained by a standard system process, this must be explicitly stated in the findings.

How we work

1Define the specific circumstances and the technical issue to be established.
2Clarify the legal basis and internal responsibilities with the company or its legal advisers.
3Limit the systems, accounts, data types and time periods required.
4Prioritise the preservation of evidence and document variable data.
5Record device and data identity, as well as the security status, in a traceable manner.
6Separate raw data from reports and user interface interpretations.
7Do not confuse employee, device, account and session assignments.
8Check for standard system processes and alternative explanations.
9Document incriminating, exonerating and inconclusive findings equally.
10The scope of the investigation should only be extended where there are new, substantiated connecting facts.
11How to write a technical report that is clear and reproducible.
12Conclusions regarding labour law, data protection law, civil law and criminal law should be left to the relevant legal advisers.

No prejudgement of employees

An internal suspicion is not simply declared to be the outcome of the investigation. We examine which technical facts support it, which contradict it, and what alternative explanations exist. Even a finding that is unfavourable to the company or exonerates it is fully documented.

Comprehensible to senior management and the legal department – reproducible for forensic experts

The main body explains the key message without using unnecessary technical jargon. The technical section documents data sources, backup statuses, identifiers, integrity information, time references, artefact locations and validation steps. This ensures that the investigation remains traceable for subsequent technical cross-checking.

LanCologne: independent technical support for businesses

Where an internal incident requires technical investigation, LanCologne provides support in the form of an objective, unbiased and transparent IT forensic investigation. The focus is not on a desired outcome, but solely on what can actually be substantiated on the basis of the digital evidence within the permissible scope of the investigation.

Legal framework

In Germany, Section 26 of the Federal Data Protection Act (BDSG) must be observed in particular with regard to employees’ data. Personal data relating to employees may be processed for the purposes of the employment relationship if this is necessary for the purposes specified therein. Section 26(1) of the BDSG sets out specific conditions for the detection of criminal offences: There must be documented factual grounds justifying the suspicion that the data subject has committed a criminal offence in the course of their employment; the processing must be necessary for the detection of the offence, and the employee’s legitimate interests must not outweigh this. In particular, the nature and extent of the processing must not be disproportionate.

In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.

In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.

Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.

LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.

Frequently Asked Questions

Can a company-owned device be automatically analysed in full simply because it is owned by the company?+
Not automatically. Ownership of the device and the lawfulness of processing employees’ personal data are separate issues. The purpose, legal basis, necessity and proportionality must be taken into account.
Can Mobile Device Management (MDM) data be used without restriction for an internal investigation?+
MDM data can provide technically valuable information. However, it must be assessed on a case-by-case basis to determine what data is actually available and whether it may be used for the specific investigation.
Is an internal IT forensic investigation specifically looking for incriminating evidence against a particular employee?+
No. We address a specific technical question of evidence without prejudging the outcome. Exculpatory findings and standard technical explanations are documented to the same standard.
What happens if an action cannot be definitively attributed to a specific person?+
In that case, the statement is restricted accordingly. A user account, device or session must not be equated with a natural person without sufficient connecting factors.

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now