Employee Offboarding: Reduce Cyber Security Risk | SOD-IT

Employee Offboarding: How to Reduce Cyber Security Risk

Employee offboarding is often treated as a simple admin task.

Someone resigns.

HR updates the records.

A laptop is returned.

The team moves on.

But from a cyber security point of view, offboarding is much more important than that.

When an employee leaves your organisation, you need to close their access to business systems, files, email, devices, customer data and third-party platforms. If that process is rushed, informal or inconsistent, former employees may still be able to access business information after their final working day.

That access could come through:

  • Active passwords
  • Email forwarding
  • Shared accounts
  • Cloud storage
  • Personal devices
  • Cached logins
  • Third-party applications
  • Old administrator permissions

In most cases, this does not happen because someone has bad intentions.

It happens because nobody has a clear process.

For small and medium-sized businesses, employee offboarding does not need to be complicated. But it does need to be structured, recorded and followed in the right order.


Why Employee Offboarding Is a Cyber Security Issue

Employee offboarding matters because it is one of the few moments where you know, with certainty, that someone should no longer have access to your systems.

That makes it the right time to review and remove access before it gets forgotten.

If access is left in place, even for a short period, it creates a gap.

That gap may be harmless.

But it could also allow a former employee, contractor or supplier to access:

  • Email accounts
  • Client records
  • Cloud storage
  • Finance systems
  • Internal documents
  • Project management tools
  • Supplier portals
  • Shared folders
  • Business applications

The risk is not limited to the main user account.

Many employees build up access across multiple tools over time. They may have been added to shared mailboxes, Teams channels, SharePoint folders, CRM systems, accounting software, social media accounts, supplier portals, website platforms or remote access tools.

If nobody checks those areas during offboarding, access can remain in place long after the person has left.

For businesses without a dedicated internal IT team, this is where problems often arise. Permissions may have been granted informally, shared passwords may have been used, and one person may assume someone else has handled the exit.

A quick conversation is not a reliable security process.

A structured employee offboarding checklist is.

The National Cyber Security Centre’s small organisations guide to cyber security is also a useful reference for the wider controls that support a secure exit process.


The First Steps in Employee Offboarding

The first priority is access.

As soon as a departure is confirmed, start by removing access to the systems the employee uses most.

For a planned resignation, this can be scheduled carefully.

For an unexpected departure, the same controls need to happen immediately.

The first steps should usually include:

  • Confirming the departure date and time
  • Disabling or suspending the main user account
  • Revoking access to core business systems
  • Ending active sessions
  • Removing administrator or elevated permissions
  • Reviewing access to shared inboxes, files and applications
  • Removing any third-party access

Identity and access should come first.

Disabling the main account is a good starting point, but it may not close every route into your systems. Some applications keep their own sessions active. Others may use separate logins. A user may also still be signed in on a laptop, mobile phone or browser session.

That is why active sessions should be reviewed and ended where possible.

A password reset alone may not sign someone out everywhere.

If the employee had administrator rights, access to finance systems, payroll, client records, HR information or security tools, the exit should be treated as higher risk. Those permissions should be removed before or at the point of departure, not during a later review.


Assign Clear Ownership of Employee Offboarding

One of the biggest weaknesses in offboarding is unclear responsibility.

HR may assume IT has handled access.

IT may assume the line manager has confirmed which systems were used.

The line manager may assume everything sits under the employee’s main Microsoft 365 account.

That is how steps get missed.

Every employee offboarding process should have a named person responsible for making sure the checklist is completed.

That person may need input from:

  • The business owner
  • The employee’s line manager
  • HR
  • IT support
  • Finance
  • Operations

The important point is that one person owns the process and confirms the actions have been completed.

Clear ownership prevents offboarding becoming a collection of assumptions.


Recover Company Devices

Once account access is under control, the next priority is devices.

Company equipment should be accounted for, including:

  • Laptops
  • Desktop computers
  • Mobile phones
  • Tablets
  • Security keys or tokens
  • External hard drives
  • USB devices
  • Access cards
  • Any other company-owned equipment

It is also important to check whether business data was stored locally, synced for offline use or saved in personal folders.

If a device cannot be returned, the business should consider whether it can be locked or wiped remotely. That decision needs to be made quickly, because a missing device may still contain business information.

Device management is one of the reasons managed IT support matters.

If devices are enrolled and controlled properly, it is much easier to protect company data when somebody leaves.


Review Passwords and Shared Accounts

Shared passwords are one of the most common offboarding risks.

If the departing employee knew a password used by more than one person, that password should be changed.

This may apply to:

  • Shared email accounts
  • Social media accounts
  • Supplier portals
  • Wi-Fi passwords
  • Booking systems
  • Finance tools
  • Website access
  • Document approval systems
  • Industry-specific platforms

Where possible, businesses should avoid shared logins altogether.

Individual user accounts are easier to control, audit and remove. If your team needs a shared mailbox, access should be managed through named user accounts rather than one password passed between colleagues.

This makes offboarding much simpler.

When someone leaves, you remove their access.

You do not need to change a shared password everyone else still relies on.


Check Multi-Factor Authentication

Multi-factor authentication is essential, but it also needs to be managed properly during offboarding.

When someone leaves, businesses should remove any linked:

  • Mobile phone
  • Authenticator app
  • Security token
  • Backup email address
  • Personal device
  • Recovery method

MFA only works if the registered devices and approval methods are current.

If an old device or personal phone remains linked to an account, it can create unnecessary risk.

This is especially important for administrator accounts, finance platforms, email systems and cloud services.


Review Permissions Properly

Access is not always obvious.

An employee may lose access to their main account, but still have permissions through group membership, shared folders, third-party systems or external platforms.

That is why employee offboarding should include a proper permissions review.

Pay attention to:

  • Cloud storage and document libraries
  • SharePoint and Teams sites
  • CRM systems
  • Finance and accounting platforms
  • HR and payroll systems
  • External partner portals
  • Supplier platforms
  • Website, domain and hosting accounts
  • Backup tools
  • Security tools
  • Remote access platforms
  • Project management systems

Permissions can build up slowly over time.

A staff member may have been added to a project folder two years ago and never removed. They may have access to a supplier portal because they once helped with a task. They may have admin permissions because it was convenient at the time.

Offboarding is the moment to clean that up.


Be Careful with Email Forwarding

Email forwarding can be useful during a handover.

It can help make sure customer queries are not missed and important messages still reach the business.

But it needs to be handled carefully.

Forwarding should be:

  • Approved
  • Time limited
  • Reviewed
  • Documented

Unchecked email forwarding can create privacy and security problems.

A better option may be a managed mailbox handover, where the business preserves access to important messages without leaving unnecessary access in place.

This allows continuity without keeping the former employee connected to the account.


Preserve Business Files Properly

Before an account is closed, make sure important business information has been preserved in the right place.

Files should not be left sitting in:

  • A personal OneDrive folder
  • A local desktop
  • A laptop that may not be returned
  • A personal cloud account
  • An old email inbox nobody will monitor
  • A project folder nobody owns

The business should know where key documents now live and who is responsible for them.

This is especially important when the employee handled:

  • Customer records
  • Contracts
  • Financial documents
  • Supplier information
  • Project files
  • Proposals
  • HR information
  • Internal processes

The goal is to protect continuity and confidentiality at the same time.

Delete too much, and the business may lose useful records.

Leave too much in the wrong place, and you may expose information unnecessarily.

A controlled handover avoids both problems.


Keep an Employee Offboarding Record

Employee offboarding is much easier to manage when you can see what happened, when it happened and who carried it out.

A simple record gives you evidence if you ever need to investigate unusual activity or confirm how access was handled.

For each departing employee, record:

  • Name, role and final working day
  • Systems and accounts disabled or removed
  • Devices returned, locked or wiped
  • Shared passwords changed
  • MFA methods removed
  • Active sessions revoked
  • Email forwarding started, stopped or reviewed
  • Files and business data transferred
  • Third-party access removed
  • Outstanding actions
  • Person responsible for each step

This does not need to be complicated.

It simply needs to be consistent.

A clear record makes future exits less stressful and gives your business a repeatable process rather than relying on memory or old email threads.


Common Employee Offboarding Mistakes

Many offboarding risks come from small mistakes that are easy to avoid with the right process.

The most common include:

Only disabling the main account

This may not remove access to every system, especially third-party platforms or cached sessions.

Forgetting personal devices

Employees may still be signed in on phones, tablets or home computers.

Leaving shared passwords unchanged

If someone knew a shared password, they may still be able to access the account after leaving.

Not checking email forwarding

Forwarding may continue longer than intended or send information to the wrong place.

Missing third-party tools

Supplier portals, CRM systems, website access and project platforms are often overlooked.

No written record

If nothing is recorded, nobody can easily confirm what was done.

The solution is not a complicated process.

It is a clear checklist that is followed every time.


How Managed IT Support Helps with Employee Offboarding

For many SMBs, employee offboarding becomes stressful because access, devices and data are spread across too many places.

Managed IT support helps bring structure to that process.

At SOD-IT, we can help businesses review and improve how they manage:

  • User accounts
  • Microsoft 365 access
  • Devices
  • Passwords
  • MFA
  • Permissions
  • Email handovers
  • Shared mailboxes
  • Cloud storage
  • Third-party applications
  • Business data
  • Access reviews

We can also help create an employee offboarding checklist that fits your organisation, so your team knows what needs to happen when someone leaves.

The aim is to reduce the chance of something being missed when time is tight.

Your process should be clear enough for people to follow, detailed enough to protect important systems and flexible enough to work across different roles and applications.


Is Your Employee Offboarding Process Secure Enough?

Employee offboarding is not just an HR task.

It is a cyber security moment.

When someone leaves, your business needs to close access, recover devices, protect data and record what changed.

If your current process relies on memory, assumptions or scattered email threads, it may be time to tighten it.

SOD-IT can help you build a calmer, more consistent way to manage employee access, so every handover is controlled and complete.

Speak to our team to find out how our IT and cyber security services can help reduce risk during employee offboarding.

📞 0141 488 1533
📧 [email protected]
🌐 www.sod-it.co.uk