Peter Yapp, IT fraud and security specialist
6.40am: The alarm goes off. Feel two feet in the small of my back, and am projected out of bed at high velocity to turn off John Humphries before he has time to irritate my wife. Time for an invigorating shower, and then hone my negotiation skills to persuade my two daughters that it is time to get up.
7.55am: Into the car with my wife and daughters, then drive to the station. Walk halfway to school then dash for the train. Spot headline story that all e-commerce is insecure. Buy paper and start assessing the consequences for internet security and the impact on my clients.
8.55am: Arrive at office in central London. Log onto computer. Deal with email. Plough through the "snail" mail and then plan the day ahead.
9.30am: Start analysis on computer evidence secured yesterday. Work on a cloned hard disk that looks (and is) exactly like the original used by the suspect. The client has asked me to examine the disk forensically for any sign of a particular bank account number to check if an employee is paying somebody for a fraudulent activity. Start by searching all the user-created files. No sign of the account number. Retrieve all the files that the user has deleted. Search through the deleted files. Still no sign of the account number.
11am: Time for a cappuccino from our new drinks machine to act as a break to stop my eyes going square!
11.10am: Inspired again I look through the non-file areas of the disk and find what I am looking for. Whoops of success ring around the office as I try and involve my colleagues in the celebrations. Immediately phone the client with my good news which prompts a call for a full-scale investigation now we have established a direct link between the client's employee and a competitor. Arrange a meeting with the client, myself and a couple of investigators from our investigation division for tomorrow.
11:30am: Off to the City of London for a meeting with a large financial institution to discuss the scope for an IT security review. Many client companies have taken steps to prevent unauthorised access from users on the outside but have not fully considered the issue of their own employees and procedures on the inside. In our experience more than 70% of fraud is committed by insiders, and the risks are rising as the IT revolution increases the number of employees with access to corporate data.
12 noon: Meeting explores the number of sites to be covered, the number of file servers and the number of users/computers. The review will cover fraud, IT security and all misuse/abuse risks but not those risks from terrorism/sabotage, fire, flood and natural disaster as these were covered in a recent disaster recovery review. We also agree that the client will work with our colleagues in the pre-employment screening division to implement a programme that will reduce the risk of employing potential fraudsters, so minimising internal risk at source.
1pm: Head back to office, picking up sandwich on the way.
1.30pm: Lunch at my desk as I deal with the second post and the recent batch of emails that has arrived.
2pm: Phone call from this morning's client giving me some more words and phrases to search for. Key them and their variants in and start further forensic analysis on them all simultaneously. Start writing up report on my findings.
3pm: Call for the electronic dice (a program written in-house by one of my colleagues) to be rolled in order to determine whose turn it is to collect the coffees. This program has certainly injected some fun into the daily chore!
3.05pm: Start preparing PowerPoint slides for a presentation I am making about the need for email and internet policies if firms want to avoid expensive litigation in libel, sexual discrimination and internet abuse cases.
4.15pm: Receive phone call from a client in distress who believes they have uncovered multiple occurrences of a Trojan Horse (a computer program) called Back Orifice on their system. Back Orifice is a program that will enable somebody else to remotely control your PC. They want immediate action to determine the extent of their exposure and to secure evidence that they may be able to use later. I say I will phone them back in 15 minutes. Log onto the internet to check train timetables and get information about local hotels. Phone my wife to warn her I won't be home tonight and ask one of my colleagues to book the two of us into a hotel. Check in emergency drawer for clean shirt, pants and socks - yes, in luck.
4.30pm: Phone client back to explain that myself and my colleague will be with them in time for a 8pm briefing. Prepare two travelling forensic computer kits.
5pm: Leave office a full hour earlier than normal, in order to catch the 5.30 train armed with portable computer, overnight bag and a portable forensic computer kit.
5.30pm: Fire up portable computer and continue work on PowerPoint slides for the presentation on email and internet policies. Rail supper consumed on the go, as we are unlikely to get a chance to eat later.
7.30pm: Jump in taxi and go straight to client's main building ready for briefing.
8pm: Briefing with client and a team of 10.
9pm: Start work on tracing source of Trojan Horse outbreak. Identify two machines that definitely need to be evidentially secured.
11.30pm: Return to hotel for the night, exhausted and wondering what tomorrow will bring.