People are much lazier than you think, especially when they think they're better than others and/or above the law.
One quick glance at wikileaks will tell you people don't think much when creating/storing/sharing files
Most workers aren’t involved in anything bad so most of them will not hide proof.
I would assume the French legal system has methods like most democracies to require a company to retain data and request a copy of that data. We're talking about a corporate office here, not a drug packaging center hidden in the basement of a suburban home where everyone hurries to flush narcotics.
In Ukraine, this is something that is assumed by default as a basic life hygiene.
A company I worked for had a few people at each site that had a kill switch that would lock all workstations and lock out all employees at that site. That would prevent the fishing expedition from succeeding.
Similarly, another company I worked for had a company policy that you should physically give up your corporate laptop and phone to customs, but speak to company counsel before giving any sign in credentials. Some countries like to data mine business travelers if they have a beef with the traveller's employer.
Edit: I should point out that every large company should have a rapid response security team. And even if there's no formal system or procedure for a police raid, it would only take a few minutes for that team to decide that they have an obligation to protect the company's data and network. They certainly wouldn't let non-employees sit at a terminal and do whatever they want for hours or days.
Other than an admission of doing something shady, what else could this be?
This is especially true if this authority intends to use the fishing expedition to build the case in the first place.
Every compliance training I had, covering everything from consumer goods to defense, told you to fully comply with authorities in case of a search. Call legal and site security, stay with the people conducting the search, but fully comply and NEVER try to hide stuff or hinder them in any way, shape or form. That's what legal councils are there for. And courts.
Precisely the people that have IT on speed dial to cut off site access, deactivate accounts and badges.
What can happen if you do, well, look no further than Mar-a-Lago. because all you do is adding charges of obstruction. But hey, if you think that you know better than legal departments of some of the biggest, and most scrutinized, companies in the western world, sure, go ahead.
1) An intruder enters the building, maybe armed, and tries to coerce an individual to do something on a console.
2) An insider threat is discovered and you need to hold the room for questioning without letting someone slip out the back and delete all the evidence.
Are you advocating that employees have the obligation to break the law to protect a business that might be doing illegal things? Are you an employee or an employer?
You misunderstand the law. The police can collect evidence in their jurisdiction. They are free to grab papers, phones, laptops, servers, etc. If the hard drives are encrypted, they can ask a judge to compel decryption, after presenting evidence and subject to rebuttal by legal counsel.
What the police often want to do is an extra-legal search of materials outside their jurisdiction, i.e. in the cloud, in remote servers, etc. I would posit that this is almost always the case, since raiding any tech company would otherwise yield a few printouts and a stack of encrypted laptops.
> Are you advocating that employees have the obligation to break the law
Absolutely not. The IT employee is probably several time zones away, and is just securing assets not on-site. His team mate will probably provide discovery if/when the police actually request things through a court process. The staff on site should cooperate, whether or not their cooperation has been rendered moot.
You aren't suggesting that the police should be able to sit in that office, accessing anything they want on remote servers, indefinitely, right? Why can't the police kick the IT guy's door in and demand an admin login?
Ok, my advice to anyone reading this is that if you find yourself in this situation, help the police get as much information they can about it. Nobody should get in the middle of law enforcers business for a wage, don't risk yourself.
> You aren't suggesting that the police should be able to sit in that office, accessing anything they want on remote servers, indefinitely, right? Why can't the police kick the IT guy's door in and demand an admin login?
I'm suggesting that if you create/operate a kill switch you might go to jail and it will be for a wage, something that a competent tech person can get anywhere, probably with a better work life balance than a place that is under risk of police raid.
Having everything online also means that you're at risk of being hacked, whereas if it's in a locked room, you have a lot more control over who accesses the sensitive data.