Employee offboarding is often treated as a simple admin task.
Someone resigns.
HR updates the records.
A laptop is returned.
The team moves on.
But from a cyber security point of view, offboarding is much more important than that.
When an employee leaves your organisation, you need to close their access to business systems, files, email, devices, customer data and third-party platforms. If that process is rushed, informal or inconsistent, former employees may still be able to access business information after their final working day.
That access could come through:
In most cases, this does not happen because someone has bad intentions.
It happens because nobody has a clear process.
For small and medium-sized businesses, employee offboarding does not need to be complicated. But it does need to be structured, recorded and followed in the right order.
Employee offboarding matters because it is one of the few moments where you know, with certainty, that someone should no longer have access to your systems.
That makes it the right time to review and remove access before it gets forgotten.
If access is left in place, even for a short period, it creates a gap.
That gap may be harmless.
But it could also allow a former employee, contractor or supplier to access:
The risk is not limited to the main user account.
Many employees build up access across multiple tools over time. They may have been added to shared mailboxes, Teams channels, SharePoint folders, CRM systems, accounting software, social media accounts, supplier portals, website platforms or remote access tools.
If nobody checks those areas during offboarding, access can remain in place long after the person has left.
For businesses without a dedicated internal IT team, this is where problems often arise. Permissions may have been granted informally, shared passwords may have been used, and one person may assume someone else has handled the exit.
A quick conversation is not a reliable security process.
A structured employee offboarding checklist is.
The National Cyber Security Centre’s small organisations guide to cyber security is also a useful reference for the wider controls that support a secure exit process.
The first priority is access.
As soon as a departure is confirmed, start by removing access to the systems the employee uses most.
For a planned resignation, this can be scheduled carefully.
For an unexpected departure, the same controls need to happen immediately.
The first steps should usually include:
Identity and access should come first.
Disabling the main account is a good starting point, but it may not close every route into your systems. Some applications keep their own sessions active. Others may use separate logins. A user may also still be signed in on a laptop, mobile phone or browser session.
That is why active sessions should be reviewed and ended where possible.
A password reset alone may not sign someone out everywhere.
If the employee had administrator rights, access to finance systems, payroll, client records, HR information or security tools, the exit should be treated as higher risk. Those permissions should be removed before or at the point of departure, not during a later review.
One of the biggest weaknesses in offboarding is unclear responsibility.
HR may assume IT has handled access.
IT may assume the line manager has confirmed which systems were used.
The line manager may assume everything sits under the employee’s main Microsoft 365 account.
That is how steps get missed.
Every employee offboarding process should have a named person responsible for making sure the checklist is completed.
That person may need input from:
The important point is that one person owns the process and confirms the actions have been completed.
Clear ownership prevents offboarding becoming a collection of assumptions.
Once account access is under control, the next priority is devices.
Company equipment should be accounted for, including:
It is also important to check whether business data was stored locally, synced for offline use or saved in personal folders.
If a device cannot be returned, the business should consider whether it can be locked or wiped remotely. That decision needs to be made quickly, because a missing device may still contain business information.
Device management is one of the reasons managed IT support matters.
If devices are enrolled and controlled properly, it is much easier to protect company data when somebody leaves.
Shared passwords are one of the most common offboarding risks.
If the departing employee knew a password used by more than one person, that password should be changed.
This may apply to:
Where possible, businesses should avoid shared logins altogether.
Individual user accounts are easier to control, audit and remove. If your team needs a shared mailbox, access should be managed through named user accounts rather than one password passed between colleagues.
This makes offboarding much simpler.
When someone leaves, you remove their access.
You do not need to change a shared password everyone else still relies on.
Multi-factor authentication is essential, but it also needs to be managed properly during offboarding.
When someone leaves, businesses should remove any linked:
MFA only works if the registered devices and approval methods are current.
If an old device or personal phone remains linked to an account, it can create unnecessary risk.
This is especially important for administrator accounts, finance platforms, email systems and cloud services.
Access is not always obvious.
An employee may lose access to their main account, but still have permissions through group membership, shared folders, third-party systems or external platforms.
That is why employee offboarding should include a proper permissions review.
Pay attention to:
Permissions can build up slowly over time.
A staff member may have been added to a project folder two years ago and never removed. They may have access to a supplier portal because they once helped with a task. They may have admin permissions because it was convenient at the time.
Offboarding is the moment to clean that up.
Email forwarding can be useful during a handover.
It can help make sure customer queries are not missed and important messages still reach the business.
But it needs to be handled carefully.
Forwarding should be:
Unchecked email forwarding can create privacy and security problems.
A better option may be a managed mailbox handover, where the business preserves access to important messages without leaving unnecessary access in place.
This allows continuity without keeping the former employee connected to the account.
Before an account is closed, make sure important business information has been preserved in the right place.
Files should not be left sitting in:
The business should know where key documents now live and who is responsible for them.
This is especially important when the employee handled:
The goal is to protect continuity and confidentiality at the same time.
Delete too much, and the business may lose useful records.
Leave too much in the wrong place, and you may expose information unnecessarily.
A controlled handover avoids both problems.
Employee offboarding is much easier to manage when you can see what happened, when it happened and who carried it out.
A simple record gives you evidence if you ever need to investigate unusual activity or confirm how access was handled.
For each departing employee, record:
This does not need to be complicated.
It simply needs to be consistent.
A clear record makes future exits less stressful and gives your business a repeatable process rather than relying on memory or old email threads.
Many offboarding risks come from small mistakes that are easy to avoid with the right process.
The most common include:
This may not remove access to every system, especially third-party platforms or cached sessions.
Employees may still be signed in on phones, tablets or home computers.
If someone knew a shared password, they may still be able to access the account after leaving.
Forwarding may continue longer than intended or send information to the wrong place.
Supplier portals, CRM systems, website access and project platforms are often overlooked.
If nothing is recorded, nobody can easily confirm what was done.
The solution is not a complicated process.
It is a clear checklist that is followed every time.
For many SMBs, employee offboarding becomes stressful because access, devices and data are spread across too many places.
Managed IT support helps bring structure to that process.
At SOD-IT, we can help businesses review and improve how they manage:
We can also help create an employee offboarding checklist that fits your organisation, so your team knows what needs to happen when someone leaves.
The aim is to reduce the chance of something being missed when time is tight.
Your process should be clear enough for people to follow, detailed enough to protect important systems and flexible enough to work across different roles and applications.
Employee offboarding is not just an HR task.
It is a cyber security moment.
When someone leaves, your business needs to close access, recover devices, protect data and record what changed.
If your current process relies on memory, assumptions or scattered email threads, it may be time to tighten it.
SOD-IT can help you build a calmer, more consistent way to manage employee access, so every handover is controlled and complete.
Speak to our team to find out how our IT and cyber security services can help reduce risk during employee offboarding.