When Talent Leaves in Bulk: What the Jarden–Barrenjoey Dispute Reveals About Insider Risk and Digital Forensics

A cybersecurity, insider-risk and technology-risk perspective on the current New Zealand Employment Court proceedings

There is a version of the Jarden–Barrenjoey story that has already been told several times in the New Zealand and Australian financial press: two investment banks, a wave of senior departures, a new competitor entering the New Zealand market, and a legal dispute over information and devices.

That is primarily a story about talent, governance, competition and employment law.

There is another version that is more relevant to anyone responsible for information security, technology risk or digital forensics.

It is a story about what happens when people who already have legitimate access to highly sensitive information decide to leave an organisation, particularly when they are senior, commercially significant, moving to a direct competitor, and potentially followed by a number of colleagues.

That is an insider-risk problem.

Importantly, insider risk does not mean assuming malicious intent. Nor does it mean concluding that confidential information was improperly taken or used. Those are matters for evidence and, where relevant, the courts.

The security question is different:

Can an organisation identify, contain, investigate and evidence what happened when a high-risk employee departure occurs?

There is also an earlier question that is arguably more important:

Can an organisation recognise that it has entered a period of elevated insider risk before the resignation or departure actually happens?

The Jarden–Barrenjoey proceedings provide a useful case study for thinking about both questions.

This article is not an assessment of what Jarden, Barrenjoey, Dan Reynolds, Silvana Schenone or any other individual did or did not do. The internal technology environments, security architectures and information-security controls of the organisations are not publicly known. The Employment Court proceedings are ongoing, and some evidence and submissions have been suppressed.

The analysis below focuses on what the publicly reported circumstances illustrate about insider-risk management, early alerting, digital forensics and forensic readiness in financial services.

What is actually known

Barrenjoey, the Australian investment bank, has been establishing its New Zealand operation and recruited Jarden’s former co-chief executive Dan Reynolds and former managing director and co-head of investment banking Silvana Schenone.

A number of other Jarden employees subsequently moved to Barrenjoey. Public reporting has put the number at at least 14. The court has also reportedly heard that at least 17 other Jarden employees discussed joining Barrenjoey but ultimately remained at Jarden. (The Australian)

That second number is interesting from an insider-risk perspective.

The potential risk population was therefore not necessarily limited to the people who ultimately left. During a period of organisational uncertainty, there may have been a much larger group of employees considering a move, creating a broader requirement for access monitoring, information governance and communications controls.

Jarden subsequently brought proceedings in the New Zealand Employment Court seeking deliver-up orders concerning devices and information associated with the departing executives. (The Australian)

The court has heard allegations concerning information on devices, including claims that data was erased. The defence has disputed the characterisation of the conduct and argued, among other things, that information had been copied to hard drives. Jarden has argued that access to the devices and data is necessary to establish what information may have been involved, including potentially identifying clients who were being targeted. (The Australian)

The court has also heard competing arguments about the status of Jarden’s devices, the application of its policies and the parties’ respective positions on privacy and access. Judge Kathryn Beck is presiding, with some evidence suppressed and the decision pending at the time of writing. (The Australian)

That distinction matters.

There is a significant difference between:

  • information being accessed;
  • information being copied;
  • information being transferred;
  • information being retained;
  • information being deleted;
  • information being used improperly; and
  • information being disclosed to another organisation.

Those are different forensic propositions, and each requires evidence.

The receiving organisation has an insider-risk responsibility too

One of the more interesting aspects of this situation is the risk on the other side of the employment transition.

When a competitor recruits experienced employees from another financial institution, the receiving organisation inherits a potential information-governance problem.

That does not mean the incoming employees have done anything wrong. It means the receiving organisation should recognise that people joining from a competitor will have knowledge, documents, contacts and working practices developed during their previous employment.

The objective should be:

Experience and relationships can move with the employee. Confidential information belonging to the former employer should not.

A mature receiving organisation could establish a clean-environment onboarding process for particularly sensitive hires.

That might include:

  • new corporate devices;
  • prohibition on connecting former-employer devices;
  • explicit confidentiality briefings;
  • documented acknowledgements;
  • restrictions on importing external files;
  • DLP controls;
  • monitoring of unusual external transfers;
  • escalation procedures for potentially confidential material.

For particularly sensitive roles, it may also be appropriate to apply enhanced monitoring during the initial period of employment.

The objective is not punitive.

It is protective.

It protects the new employer, the employee, the former employer and potentially the clients whose information is involved.

It also creates an evidentiary record demonstrating that the receiving organisation took reasonable steps to prevent third-party confidential information from entering its environment.

That is a useful control regardless of what ultimately happened in this particular case.

Insider risk is not the same as malicious behaviour

The term “insider risk” is sometimes used as shorthand for a malicious employee stealing information.

That is too narrow.

From an information-security perspective, insider risk encompasses the possibility that someone with legitimate access may:

  • deliberately misuse information;
  • inadvertently disclose information;
  • move information to an unauthorised location;
  • retain information after their legitimate need for access ends;
  • transfer information between personal and corporate environments;
  • use an inappropriate communications channel;
  • access information for a purpose unrelated to their role; or
  • destroy information that an organisation subsequently needs to investigate.

The employee does not necessarily have to be acting maliciously for the organisation to experience a security, privacy, regulatory or legal problem.

The security objective should therefore not simply be:

“Stop employees doing bad things.”

It should be:

“Ensure that access is appropriate, information movement is observable, risk can be detected early, and sufficient evidence exists to establish what happened.”

That is a much more mature security objective.

The warning signs often appear before the resignation

One of the less discussed aspects of insider risk is that the security event does not necessarily begin when someone resigns.

By the time an employee formally hands in their notice, a significant amount of preparation may already have occurred.

This is particularly relevant where multiple employees subsequently move to the same competitor.

The question is not whether an organisation could have known that specific individuals were going to resign.

The more useful security question is:

Were there observable changes in behaviour or access that should have increased the organisation’s risk posture before the resignation occurred?

That is a very different question.

Potential indicators might include:

  • unusual increases in file access;
  • access to information outside an employee’s normal client or business portfolio;
  • bulk downloads;
  • creation of local archives;
  • unusual searches across document repositories;
  • increased access outside normal working hours;
  • use of removable media;
  • access to personal cloud storage;
  • new or unusual devices;
  • unusual authentication locations;
  • new applications or services;
  • increased external sharing;
  • use of personal email for corporate information;
  • multiple employees displaying similar changes in behaviour.

None of these is evidence of misconduct.

The value comes from establishing a baseline and identifying meaningful deviations from it.

The organisational signal may be bigger than the individual

This is where the reported number of employees becomes particularly interesting.

If at least 14 employees ultimately left and the court heard that at least 17 others discussed joining Barrenjoey but remained at Jarden, the potential insider-risk population was considerably larger than the eventual group of leavers. (The Australian)

A mature insider-risk programme should therefore not necessarily look only at people who have formally resigned.

It should be capable of recognising clusters of related risk.

For example:

  • several employees accessing the same sensitive information;
  • unusual communication between employees who historically did not work closely together;
  • multiple people accessing similar datasets;
  • several employees suddenly using external storage;
  • simultaneous changes in data-access behaviour;
  • multiple resignations occurring within a short period;
  • several employees showing unusual activity around the same external organisation.

This is where correlation becomes important.

Individually, these events may be meaningless.

Collectively, they may indicate that the organisation has entered an elevated-risk period.

The most valuable alert may therefore not be:

“Someone is stealing data.”

It may be:

“The probability of inappropriate data movement has materially increased, and we should change our security posture.”

That is a much more useful concept for an enterprise security programme.

HR, security and management need an appropriate connection

This is where insider-risk programmes can fail.

Security may have excellent telemetry.

HR may know that a senior employee is considering leaving.

Legal may know that restrictive covenants or confidentiality obligations could become relevant.

Management may know that several employees are being approached by a competitor.

But if those signals remain in separate systems and separate conversations, nobody necessarily sees the overall picture.

A mature insider-risk process creates an appropriate mechanism for bringing relevant risk signals together.

That does not mean HR should provide unrestricted employment information to security.

It means that security-relevant risk indicators should be capable of triggering an appropriate change in security posture.

For example:

Senior employee + competitor recruitment + privileged access + unusual data movement

is a very different risk profile from:

Senior employee + routine data access + no unusual activity.

The first scenario might justify enhanced monitoring and preservation controls.

The second probably does not.

The challenge is avoiding employee surveillance

There is an important line here.

An organisation that monitors every employee aggressively will generate enormous volumes of false positives and potentially create its own privacy and employee-relations problems.

The answer is not to monitor everything simply because someone might leave.

It is to develop proportionate, risk-based controls.

The security team should be looking for indicators of information risk, not trying to predict people’s personal decisions.

Someone updating their LinkedIn profile is not a cyber incident.

Someone accessing a large volume of sensitive client information immediately after changing their employment profile is a different security signal.

Neither proves misconduct.

The second warrants context.

That distinction is important for both employee trust and security effectiveness.

What could early alerting actually look like?

The technology does not need to produce a definitive answer.

It needs to bring together multiple weak signals and provide enough context for a human decision.

For example, an insider-risk capability might correlate:

Signal Example
Employment risk Senior employee identified as joining a competitor
Access anomaly Significantly higher than normal document access
Data movement Large download of sensitive client material
Endpoint USB device connected
Cloud New personal storage service accessed
Identity New device authentication
Organisational Multiple related employees showing similar behaviour

No individual signal establishes misconduct.

The combined picture could, however, trigger a high-risk departure workflow.

That workflow might involve:

  1. increased monitoring;
  2. preservation of relevant logs;
  3. review of data classifications;
  4. review of access rights;
  5. restrictions on unnecessary access;
  6. legal and HR consultation;
  7. preparation for device preservation;
  8. increased DLP sensitivity;
  9. enhanced scrutiny of external transfers.

The organisation does not have to wait until someone resigns.

It can move from normal monitoring to heightened monitoring based on risk.

That is where early alerting becomes genuinely valuable.

The real question is not “what did they have access to?”

It is:

“What did they actually access, and what did they do with it?”

This is where conventional access-control thinking begins to fall short.

A senior employee may have legitimate access to:

  • CRM systems;
  • client records;
  • transaction documents;
  • research;
  • deal rooms;
  • financial models;
  • contact databases;
  • shared drives;
  • email;
  • collaboration platforms.

The fact that they accessed one of those systems does not tell us whether the activity was appropriate.

A better forensic question is:

Was the activity consistent with the employee’s legitimate business purpose at that point in time?

That is where User and Entity Behaviour Analytics (UEBA) and Data Loss Prevention (DLP) become valuable.

DLP is more than a blocking mechanism

Data Loss Prevention is sometimes reduced to the idea of stopping someone from emailing a confidential document.

In a sophisticated financial-services environment, it can be much more valuable as a visibility and evidence mechanism.

DLP can potentially identify:

  • sensitive files being copied;
  • bulk transfers;
  • external sharing;
  • uploads to personal cloud storage;
  • transfers to removable media;
  • printing;
  • unusual destinations;
  • sensitive data leaving controlled applications.

The appropriate response does not always have to be an outright block.

There is a balance between preventing legitimate work and controlling information risk.

In some circumstances, the better response may be:

Allow the activity, but record it, alert on it and preserve the evidence.

That distinction is important in environments where senior employees legitimately handle large volumes of sensitive information.

UEBA adds the missing context

DLP tells you that something happened.

UEBA can help answer whether the activity was unusual.

The value comes from establishing a baseline.

For example:

Employee normally accesses 50 documents a day.

versus:

Employee accesses 4,000 documents over two days immediately before joining a competitor.

Neither number, by itself, proves misconduct.

But the second pattern should be visible to a mature insider-risk programme.

The same principle applies to:

  • authentication;
  • applications;
  • devices;
  • locations;
  • file access;
  • downloads;
  • external sharing;
  • cloud services.

The objective is to move from isolated security events to an understanding of behavioural context.

Digital forensics: the device is only one piece of the puzzle

The reported dispute over devices highlights an important principle in modern digital forensics.

The endpoint should not be the only source of truth.

If an employee’s laptop or phone becomes unavailable, is wiped, damaged or otherwise difficult to examine, an organisation should ideally still have independent evidence.

Depending on the technology environment, that might include:

  • identity-provider logs;
  • authentication records;
  • Microsoft 365 audit logs;
  • SharePoint and OneDrive activity;
  • email records;
  • EDR telemetry;
  • DLP alerts;
  • cloud access logs;
  • VPN records;
  • proxy records;
  • firewall logs;
  • USB connection telemetry;
  • mobile-device-management records;
  • application logs;
  • backup systems;
  • document-management audit trails.

The forensic objective becomes reconstruction.

For example:

Identity → device → application → file → action → timestamp → destination

That sequence is much more powerful than relying on a single laptop.

What the reported device allegations illustrate about forensic readiness

The proceedings reportedly involve allegations that data was erased from devices. It is important to keep that wording exactly where it belongs: in the context of the allegations made in the proceedings, rather than treating it as an established technical fact. (The Australian)

From a forensic perspective, however, the scenario illustrates an important principle.

An organisation should not have to rely entirely on the condition of a returned device to determine what happened.

Deletion of a file does not necessarily mean that every trace of the activity has disappeared. Depending on the environment, investigators may have other sources of evidence, including:

  • filesystem metadata;
  • endpoint telemetry;
  • cloud versions;
  • backups;
  • synchronisation records;
  • application artefacts;
  • authentication logs;
  • USB history;
  • email records;
  • security-platform telemetry.

Forensic recovery should never be treated as guaranteed.

Modern storage technologies, encryption, cloud synchronisation and secure deletion mechanisms can make recovery unpredictable.

The better security strategy is therefore not:

“We can always recover deleted files.”

It is:

“We have independent, tamper-resistant records that allow us to establish what happened even if data on an endpoint is subsequently unavailable.”

That is the essence of forensic readiness.

Forensic readiness should exist before the incident

Digital forensics is most effective when the organisation has designed its environment with future investigation in mind.

That means deciding in advance:

  • what should be logged;
  • how long logs should be retained;
  • where logs should be stored;
  • who can access them;
  • how their integrity is protected;
  • how evidence is preserved;
  • when legal hold applies;
  • who authorises forensic acquisition;
  • how chain of custody is maintained.

Waiting until litigation begins to ask:

“What logs do we have?”

is a very different position from knowing the answer beforehand.

The strongest organisations build the evidence architecture before they need it.

The communications problem

The reported issue involving an allegedly irretrievable WhatsApp message also illustrates a broader information-governance challenge.

The key point is not whether that particular message was important to the proceedings.

The broader question is whether an organisation has control over business-relevant communications when those communications occur outside its formal communication and retention environment.

Financial-services employees increasingly operate across multiple channels.

Email is relatively straightforward.

Enterprise collaboration platforms can be governed.

Personal messaging applications are much more difficult.

The fundamental question is:

If a communication can contain business-relevant information, does the organisation have an authoritative record of it?

This is not about assuming employees are doing something wrong.

It is about recognising that important business decisions increasingly happen in informal channels.

If a significant business conversation exists only on an individual’s phone, the organisation may lose visibility at exactly the point when that conversation becomes relevant to an investigation, dispute, regulatory request or legal proceeding.

This is an established issue across financial services internationally. In 2025, the UK Financial Conduct Authority reported on off-channel communications at 11 wholesale banks and noted that robust record keeping and monitoring are important for detecting and investigating misconduct and for client disputes and litigation. The FCA also reported that 41% of identified internal policy breaches in its sample involved individuals at director grade or above. (FCA)

In the United States, the Securities and Exchange Commission has similarly taken extensive enforcement action over unpreserved off-channel communications, including communications conducted through WhatsApp and other personal messaging platforms. (SEC)

That is useful international industry context. It should not be read as suggesting that any New Zealand regulator is investigating the Jarden–Barrenjoey matter.

The technology lesson is simple:

If the business needs the record, the business needs to control the record.

Offboarding should be risk-based, not binary

Traditional offboarding often looks like this:

Resignation → disable account → collect laptop → delete account

That model is too simplistic for high-risk departures.

A more mature approach is risk-based offboarding.

Before departure

  • review access;
  • identify sensitive systems;
  • establish a baseline of normal activity;
  • identify privileged accounts;
  • review external-sharing permissions;
  • confirm device ownership;
  • establish preservation requirements.

When risk increases

  • increase monitoring;
  • review unusual access patterns;
  • apply appropriate DLP controls;
  • monitor bulk exports;
  • restrict unnecessary access;
  • preserve relevant communications;
  • increase scrutiny of external data movement.

At departure

  • revoke authentication sessions;
  • disable access;
  • rotate relevant credentials;
  • collect corporate devices;
  • preserve endpoint evidence;
  • preserve cloud evidence;
  • preserve communications;
  • document the sequence of actions.

After departure

  • review activity retrospectively;
  • investigate anomalies;
  • determine whether confidential information may have moved;
  • preserve evidence;
  • engage legal counsel where appropriate;
  • assess client, regulatory and privacy implications.

The important point is that the security response should begin before the last day when risk indicators justify it.

The ability to change security posture is itself a control

Security teams often spend enormous effort building detection capability but less effort designing what happens after an alert.

Suppose an insider-risk platform identifies an employee as high risk.

Can the organisation actually:

  • reduce their access within minutes?
  • disable unnecessary applications?
  • revoke active sessions?
  • restrict external sharing?
  • block removable media where appropriate?
  • increase DLP sensitivity?
  • preserve their mailbox?
  • preserve cloud activity?
  • capture endpoint evidence?
  • notify the appropriate legal and HR stakeholders?

If those actions require ten manual approvals and three different teams, detection may arrive too late to be useful.

The real maturity test is therefore:

How quickly can the organisation move from detection to controlled response without waiting for the event to become an incident?

That is where early alerting becomes genuinely valuable.

Zero Trust applies to people as well as networks

Zero Trust is often described in terms of infrastructure:

Verify explicitly.
Use least privilege.
Assume no implicit trust.

The same philosophy can be applied to insider risk.

An employee should not have persistent access simply because they were previously trusted.

Access should reflect:

  • identity;
  • role;
  • business need;
  • device;
  • location;
  • sensitivity of information;
  • current risk context.

A resignation does not necessarily mean that someone immediately becomes untrusted.

But it should cause the organisation to reassess whether their existing access remains appropriate.

That is particularly important when the person is moving to a competitor.

The question becomes:

Has the employee’s business purpose changed faster than their technical permissions?

If the answer is yes, there is a control gap.

The board-level question: can we prove what happened?

This is where cybersecurity and digital forensics meet governance.

Boards do not ultimately need a list of security products.

They need confidence that, if a high-risk departure occurred tomorrow, the organisation could answer:

Who accessed what?

When did they access it?

Was the access consistent with their role?

Was information copied?

Where did it go?

Was it transferred externally?

Was anything deleted?

Did we see warning signs before the departure?

Did we change our security posture when the risk increased?

Can we independently corroborate the evidence?

Can we preserve that evidence for legal or regulatory purposes?

How quickly can we contain further exposure?

That is a much more meaningful measure of cyber resilience than the number of firewalls, endpoint agents or security dashboards an organisation owns.

A practical insider-risk framework

For CISOs and technology-risk leaders, I would reduce the problem to seven capabilities.

1. Identity

Know exactly who has access to what.

Use least privilege, strong authentication, privileged-access controls and automated joiner, mover and leaver processes.

2. Data

Know which information matters.

Classify sensitive client, transaction, financial, strategic and commercially confidential information and apply appropriate controls.

3. Behaviour

Understand what normal activity looks like.

Use DLP and UEBA to identify unusual access and data movement, while recognising that an alert is a risk signal rather than a finding of misconduct.

4. Early warning

Detect changes in risk before the departure.

Correlate employment, identity, access, endpoint and data-movement signals so the organisation can identify when it has entered an elevated-risk period.

5. Evidence

Make security telemetry independently useful.

Maintain appropriate, tamper-resistant logs across identity, endpoint, cloud, communication and application layers.

6. Response

Have a documented high-risk departure process.

Know who makes the decision, what access changes, what evidence is preserved and how legal, HR, security and technology teams coordinate.

7. Recovery

Be able to reconstruct events.

If a device is unavailable, can you still determine what happened from independent sources?

That is the test of forensic readiness.

Eight questions every CISO should be able to answer

The Jarden–Barrenjoey proceedings provide a useful prompt for asking these questions internally:

Early warning: What signals would tell us that a group of employees has entered an elevated-risk period before anyone formally resigns?

Identity: If ten senior employees resigned to a named competitor tomorrow, how quickly could we change their access?

Data: Can we identify exactly what sensitive information those employees could access, rather than relying on their job titles?

Behaviour: Would we detect a significant change in their access or download patterns before departure?

Devices: Can we preserve relevant endpoint evidence without relying entirely on the returned device?

Communications: Are business-relevant conversations taking place in channels outside our retention and eDiscovery capability?

Evidence: Could we reconstruct a defensible timeline using independent logs?

Receiving environment: If a competitor hired our people, what controls would prevent our confidential information from following them?

If the answer to those questions is “we’re not sure”, the organisation has an opportunity to improve its insider-risk posture before it needs to test it under pressure.

The line that matters

The Employment Court will determine the legal questions in the Jarden–Barrenjoey proceedings. Technology commentary should not attempt to determine those questions in advance.

What the circumstances do provide is a useful reminder for security leaders:

Insider risk is not primarily about distrust. It is about control, visibility, early warning and evidence.

People leave organisations.

Senior people leave.

Teams move.

Competitors recruit.

Those are normal features of a competitive market.

The security challenge is ensuring that legitimate employee mobility does not create an unmanaged information-security risk.

It is also ensuring that the organisation can recognise when the risk is changing, respond proportionately while there is still time to act, and preserve sufficient evidence to establish what happened afterwards.

The most valuable insider-risk alert may not be the one that tells you someone has taken data.

It may be the one that tells you:

The organisation has entered a period in which the probability of inappropriate data movement has materially increased.

That is the point at which security should move from passive observation to proportionate control.

The most mature security architecture is therefore not simply the one that prevents information from leaving.

It is the one that can answer, with confidence:

What changed, what happened, what information was involved, what was authorised, what was not, and what evidence supports that conclusion?

That is where insider-risk management, information governance and digital forensics converge.

And it is a capability that should be designed long before the first resignation arrives.


Sources

Jarden and Barrenjoey proceedings

  • The Australian, “Jarden vs Barrenjoey: Device data row heard in NZ court”, 18 August 2026. Covers the Employment Court proceedings, allegations concerning data on devices, the competing arguments over the information, and evidence that at least 17 other Jarden employees discussed joining Barrenjoey but remained at Jarden. (The Australian)
  • The Australian, “Jarden launches legal action against departing Kiwi directors”, 14 August 2026. Covers the commencement of Jarden’s Employment Court proceedings and the recruitment of Dan Reynolds and Silvana Schenone by Barrenjoey. (The Australian)

Off-channel communications and financial-services context

Important qualification

This article is technology-risk commentary based on publicly available reporting as at 19 August 2026. The Employment Court proceedings are ongoing, some evidence and submissions have been suppressed, and no findings should be inferred from the allegations or submissions described above.

The article does not assert that any individual or organisation acted unlawfully, that confidential information was improperly taken or used, or that either organisation lacked particular cybersecurity controls.

The security controls discussed are examples of measures organisations operating in similar circumstances may consider as part of an insider-risk, information-governance and digital-forensics programme.

The references to early-warning indicators are likewise not suggestions that any particular indicator occurred at Jarden or Barrenjoey. They describe the types of signals a mature security programme could consider when assessing changing insider-risk exposure.