Insights › Passwords & MFA

Offboarding Staff Securely: The Forgotten Risk

Conceptual illustration of a departing employee access badge being revoked as a digital door closes on a navy background.

When someone leaves your business, the farewell card gets signed and the laptop usually gets handed back. What often does not happen is the quiet, unglamorous work of switching off every piece of access that person collected during their time with you. Email, cloud files, the accounting system, the customer database, the shared social media login: each one is a door that may still be open long after the desk is cleared.

This gap is one of the most overlooked risks in small business security. It rarely makes headlines the way ransomware does, but it is almost entirely within your control to fix. Here is how to offboard staff securely, so that leaving the business also means losing the keys to it.

Offboarding is a security task, not just an HR one

It is easy to think of offboarding as paperwork: final pay, the exit interview, the return of a swipe card. The security side gets left to whoever remembers, if anyone does. That is how accounts end up live for months after the person who owned them has moved on.

The numbers show why this matters. In 2025, Australian organisations reported 1,205 data breaches to the Office of the Australian Information Commissioner, an 8 percent rise on the year before. Most were malicious or criminal attacks, but human error caused a large share too: in the first half of 2025 it was behind 37 percent of breaches, up from 29 percent in the previous period. Forgetting to remove someone’s access sits squarely in that human error column.

Most departures are perfectly amicable, and this is not about assuming the worst of the people who leave you. An account that still works after someone has gone is a risk regardless of how the relationship ended. It might be used by the former staff member out of habit, or it might be quietly taken over by an attacker who finds a login that nobody is watching any more. Dormant accounts are attractive precisely because no one notices when they are used.

The access one person quietly accumulates

The hardest part of offboarding is simply remembering everything a person could reach. Over a few years, even a junior staff member gathers a surprising collection of logins and permissions. A departing employee may still have access to some or all of the following:

That last group of unofficial apps is worth a closer look. Staff often sign up for handy tools on their own, and those accounts rarely appear on any list, which is exactly the problem covered in our guide to shadow IT and the apps your team uses without telling you. If your business uses single sign-on, a good deal of this access can be switched off from one place, which is one of the quieter benefits explained in our piece on single sign-on for small business.

Your offboarding checklist

A written checklist turns offboarding from a memory test into a routine. Build one that fits your business, keep it with your other exit paperwork, and work through it for every departure. A solid starting point looks like this:

The final point matters more than it looks. If a question ever comes up later about whether access was removed, a dated record is the difference between knowing and hoping.

High-risk departures need a faster response

Not every exit is the same. A long-serving employee retiring on good terms is very different from a redundancy, a dismissal or a resignation made in anger. When a departure is tense, or when the person held sensitive access, the timing of your offboarding changes.

In these cases, cut access before or at the moment the news is delivered, not at the end of the day. Prioritise the things a person could use to cause harm or take data with them: email, remote access, administrator accounts, cloud file storage and the customer database. It is far easier to switch access back on for an hour if it turns out you moved too quickly than it is to undo data that has already walked out the door.

Handle this calmly and without drama. Cutting access promptly is a standard control, not an accusation, and framing it that way in your policy helps everyone treat it as normal.

Disable, do not delete, and mind the licences

There is a temptation to delete a leaver’s account entirely and be done with it. Resist it, at least at first. Deleting an account can wipe emails, files and history that the business may need for a handover, a customer query or a legal or tax obligation. The better approach is to disable the account so nobody can log in, then keep the data for as long as you actually need it before removing it.

Disabling rather than deleting also lets you convert the mailbox to a shared one or forward it, so nothing from clients slips through the cracks. Once the handover is complete, you can reassign or cancel the software licence to stop paying for a seat nobody uses.

Shared passwords deserve special attention, because they are the access that outlives an individual account. If a departing staff member knew the login for the social media page, the website or the office wifi, that credential should be changed, not just noted. A business password manager makes this manageable by keeping shared logins in one controlled place, as we cover in our guide to choosing a business password manager. Keeping the number of administrator accounts small also shrinks the problem, which is the whole point of restricting admin privileges.

Make it routine so nothing slips

Offboarding fails when it depends on one busy person remembering everything in the rush of someone’s final week. The fix is to make it a documented, repeatable process. Write down your checklist, agree who owns each step, and treat it as part of finishing up rather than an afterthought.

It also helps to look backwards from time to time. Once or twice a year, review your list of user accounts across your main systems and ask a simple question of each one: does this person still work here, and do they still need this access? You will often find dormant accounts, old contractor logins and access that was never switched off. Closing those is some of the cheapest security work you can do, and it keeps small gaps from becoming a breach.

Find out where you stand

Offboarding is one small part of a bigger picture: knowing who can reach your systems, and being confident those controls are working. If you are not sure how your business measures up, our free self-assessment is a fast way to find out.

It takes 5 to 10 minutes, asks 27 plain-English questions, and gives you an instant PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, with clear next steps. Take the free assessment at securityscore.com.au and see where you stand today.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading