Departing Employee Security: Offboarding and Access Removal
When an employee leaves, access that is not closed stays as an open door. A secure offboarding checklist, the most often skipped points (cloud accounts, shared passwords), the process in departures on bad terms and handover continuity.
Quick answer: When an employee leaves, the access they leave behind stays as an open door if it is not closed. A secure offboarding process should include: disabling all accounts and system access on the departure day, handing over email and cloud accounts to management, changing shared passwords, collecting company devices and revoking physical access cards. The most common mistakes are forgetting the departing person's account on a cloud service or a third party app, and never changing the shared passwords used across the team. If the departure was on bad terms, the process must be run even faster and more thoroughly.
Most organizations that prepare carefully for an employee's first day do not handle the last day with the same care. Yet in terms of security, offboarding can be more critical than hiring; because every active account left behind is a risk sitting outside the organization's control. Data leaks and sabotage through a departed employee's access are far more common than they appear. This article explains the steps of a secure offboarding process.
Why it matters so much
When an employee leaves, most organizations quickly close the HR and payroll side, but digital access stays open somewhere. Over the years the person has accumulated access to many systems, cloud services and apps; remembering all of them is hard. Even one forgotten account means access to the organization for the departed person (or an attacker who takes over their account). The risk rises especially in two cases: if the departure was on bad terms, and if the person held a position with access to sensitive data or critical systems.
Offboarding checklist
| Step | Timing | Priority |
|---|---|---|
| Disable all account and system access | Departure day | Very high |
| Hand over email and cloud account | Departure day | High |
| Change shared/common passwords | Departure day | High |
| Remove third party and cloud app access | First 24 hours | High |
| Collect and examine company devices | First day | Medium |
| Revoke physical access card | Departure day | Medium |
| Disable VPN and remote access | Departure day | High |
The most often skipped points
Organizations usually remember to close the main systems (email, domain account) but two points are constantly skipped. First is the cloud services and third party apps the departing person signed up for; a project management tool, a design platform, a code repository. These accounts are outside central management, so they are easily forgotten. Second is the shared passwords used across the team; when an employee leaves, these passwords remain as they knew them. Using shared passwords is already a risk; a password manager and role based access solves this problem at the root.
Departures on bad terms
If the departure was on bad terms, especially a dismissal, the process must be run even faster and more carefully. In such cases, closing access just before or at the same time as informing the person is important for security; otherwise the person can copy data or cause harm between the moment they learn they are leaving and the moment their access is cut. This is as much a security matter as a human resources one, and requires the two teams to work in coordination.
Handover and continuity
Offboarding is not just closing doors; it is also taking over the departing person's work and data in an orderly way. Their email account, files and ongoing work should be handed over to a manager or successor. If this handover is not done properly, the organization both loses information and creates orphan accounts, which over time are the most forgotten and most exploited accounts. Handling this process within an identity and access management discipline ensures both security and continuity.
The KAOS and DSET approach
DSET helps organizations build secure access management and offboarding processes. Our local AI engine KAOS scans an organization's external surface and open accounts to detect orphaned access, forgotten cloud accounts and exposed entry points, and reports every finding with a working proof. The goal is to be sure no open door is left behind after an employee leaves.
Frequently asked questions
Why is closing access immediately so important? Because a departed employee's still active account is a risk sitting outside the organization's control. The person can use this access to copy data, or someone else can take over their account. Email, VPN and cloud accounts in particular should be closed on the departure day; every delayed day increases the risk.
Why should I change shared passwords? If a team shares the same password, when one of them leaves the password stays as they knew it, and that is an open door. Changing all shared passwords after a departure is essential. Better still is to stop using shared passwords and give each employee their own account and a password manager.
Should the process be different in a dismissal? Yes. If the departure was on bad terms, access should be closed just before or at the same time as informing the person. This removes the chance of harm between the moment the person learns they are leaving and the moment their access is cut. It requires HR and security teams to work in coordination.
Sources
- NIST access management guides: https://csrc.nist.gov
- CISA insider threat measures: https://www.cisa.gov
- DSET Cyber Security and Access Management Services: https://dset.com.tr/hizmetler
To secure your organization's offboarding and access management processes, contact DSET. We provide security consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.