Finding a confidential document or image somewhere it should not be is stressful. The natural reaction is to start messaging people, editing access or trying to prove what happened immediately.

A better first response is calm, consistent and evidence-led. Preserve what you found, limit further exposure and separate what you know from what you merely suspect.

1. Preserve the best available evidence

Save the file or image exactly as you received it. Record where it was found, when it was found and who had access to that location. If it appeared on a webpage or in a message, preserve the surrounding context as well as the content itself.

Avoid opening and resaving the evidence in several applications. Repeated conversion, compression or screenshotting can remove metadata and weaken hidden signals that might still be recoverable. Work from a copy and keep the original artifact untouched.

2. Contain the exposure without destroying context

Remove public access where you can do so safely, but document the location first. If the material is sitting in a shared folder, social post or public link, capture the relevant URL, account, timestamps and audience before requesting removal.

Containment is about stopping further spread—not deleting the record of what happened.

3. Check whether the file was protected

If your team created individual recipient copies with ExactMark Imprint, submit the surfaced PDF or image to Evidence Lab and choose the ExactMark Imprint search scope. This compares the evidence with the retained recipient-copy identities rather than unrelated Web Sessions.

Use the original surfaced artifact whenever possible. A screenshot may still be analysable, but it is usually better to provide the least-altered version available.

4. Read the complete result

A displayed name is not the whole finding. Review the confidence score, candidate ranking, signal quality and any supporting filename, hash or metadata information. Strong separation from other candidates is more informative than a narrow lead.

An inconclusive result means the surviving evidence does not support a reliable attribution. It does not prove that no marked copy was involved, and it is not a reason to force a conclusion.

5. Corroborate before confronting anyone

Compare the result with ordinary business records:

  • Was that recipient actually sent the material?
  • When was their copy created and delivered?
  • Did the surfaced content include later edits they never received?
  • Who else could access their mailbox, shared drive or device?
  • Could an internal process have copied or redistributed the file?

A recipient-linked result identifies the copy that appears to be involved. It does not automatically explain the recipient's intent or prove misconduct by a particular person.

6. Bring in the right people

Depending on the content, notify the colleague responsible for security, privacy, legal matters, communications or the affected client relationship. Sensitive personal data, regulated information and contractual confidentiality may trigger specific duties and deadlines.

Keep the response group small enough to protect confidentiality, but do not let a technical investigation delay required legal or regulatory advice.

7. Improve the next distribution

After the immediate issue is controlled, ask a practical question: what would have made this easier to investigate? Often the answer is clearer recipient lists, individual rather than group copies, better access records and marking the content before it left.

ExactMark Imprint cannot travel back in time to add identity to an unmarked file. Its value begins when sensitive material is prepared for sharing. Creating recipient-linked copies now gives a future response team evidence that ordinary attachments simply do not contain.

The goal is not to assume the worst about everyone receiving a document. It is to keep sensitive information accountable when trust alone is no longer enough.