IT Forensics · Business
What role can MDM play in an internal IT forensic investigation?
Mobile device management can document device identity, compliance status, configurations and administrative actions, and can therefore be a valuable technical resource.
Why this question is important for a business
In the case of internal incidents, commercial interests, the preservation of evidence and employees’ rights may all be affected simultaneously. A technically wide-ranging investigation is therefore not automatically a good one. What is crucial is a clearly defined question of evidence and a transparently limited scope of the investigation.
Technical investigative approach
We examine which MDM data have actually been collected in the specific system, what conclusions can be drawn from them from a technical perspective, and whether their use is legally permissible for the specific investigation.
Where the limits of what can be said lie
MDM provides technical means of administration, but does not confer a blanket right to monitor employees. Depending on how it is implemented, data protection and employee participation in company affairs may be relevant.
Why LanCologne?
Internal investigations involve a direct clash of several interests: the company must be able to protect its systems, data, trade secrets and commercial interests. At the same time, employee data protection, proportionality, co-determination and, where applicable, the protection of private data must be observed.
LanCologne therefore does not begin by collecting as much data as possible. The starting point is the specific technical question to be investigated. Only then is it determined which devices, accounts, time periods and types of data are actually required. This often allows an investigation to be carried out much more precisely than a blanket, comprehensive analysis would.
Technical availability and legal permissibility are deliberately kept separate. The fact that an administrator, MDM system or cloud tenant technically enables access to certain information does not in itself answer the question of whether that information may be processed for the specific purpose in question.
Key findings are validated against primary data where necessary. Automated reports and forensic software are tools; they do not replace the expert interpretation of the underlying artefacts. Alternative technical explanations are also examined.
Equally important: an internal investigation must take exonerating facts just as seriously as incriminating ones. If the analysis reveals that a suspicion cannot be technically confirmed, or that a notable incident can be explained by a standard system process, this must be explicitly stated in the findings.
How we work
No prejudgement of employees
An internal suspicion is not simply declared to be the outcome of the investigation. We examine which technical facts support it, which contradict it, and what alternative explanations exist. Even a finding that is unfavourable to the company or exonerates it is fully documented.
Comprehensible to senior management and the legal department – reproducible for forensic experts
The main body explains the key message without using unnecessary technical jargon. The technical section documents data sources, backup statuses, identifiers, integrity information, time references, artefact locations and validation steps. This ensures that the investigation remains traceable for subsequent technical cross-checking.
LanCologne: independent technical support for businesses
Where an internal incident requires technical investigation, LanCologne provides support in the form of an objective, unbiased and transparent IT forensic investigation. The focus is not on a desired outcome, but solely on what can actually be substantiated on the basis of the digital evidence within the permissible scope of the investigation.
Legal framework
In Germany, Section 26 of the Federal Data Protection Act (BDSG) must be observed in particular with regard to employees’ data. Personal data relating to employees may be processed for the purposes of the employment relationship if this is necessary for the purposes specified therein. Section 26(1) of the BDSG sets out specific conditions for the detection of criminal offences: There must be documented factual grounds justifying the suspicion that the data subject has committed a criminal offence in the course of their employment; the processing must be necessary for the detection of the offence, and the employee’s legitimate interests must not outweigh this. In particular, the nature and extent of the processing must not be disproportionate.
In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.
In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.
Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.
LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.
Frequently Asked Questions
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can a company make use of MDM reports without overestimating their significance?
- How can a company use endpoint and EDR telemetry in an internal investigation?
- How can a company properly examine an employee’s email data as part of an internal investigation?
- How can a company use Microsoft 365 or Google Workspace data in an internal investigation?