Employee Offboarding Security Checklist: What to Do When Someone Leaves

By J. Mesa

An employee gives two weeks’ notice. You plan the farewell lunch and post the job opening. Three months later, that person’s email account still works, still forwards to a personal address, and still holds the login to your customer database. Former employees with live accounts cause breaches at small businesses each year, through malice in a few cases and through neglect in most.

Why does offboarding matter for security?

Every account you leave active is a door nobody watches. The former employee may use it. More often, an attacker does. Dormant accounts rarely have anyone reading their alerts, their passwords never change, and nobody notices a strange login. An attacker who finds one works without interruption.

Departing employees also carry data out. Sales staff take customer lists. Others forward files to personal email “for reference.” Some of that is theft, and some is habit. Both leave your information outside your control.

When should I remove a departing employee’s access?

At the moment employment ends. For a planned resignation, schedule the removal for the end of the last shift. For an involuntary termination, remove access during the termination meeting, before the person returns to a desk. Coordinate the timing with whoever handles your IT, so the accounts close while the conversation takes place.

A delay of a day gives an angry former employee a day. Remove first, tidy up afterward.

What goes on an offboarding security checklist?

Accounts and access

  1. Disable the main login: Microsoft 365, Google Workspace, or your directory account. Disabling beats deleting at this stage, because it preserves the data.
  2. Sign the user out of all active sessions and revoke app tokens.
  3. Remove the user’s multi-factor authentication devices and registered phones.
  4. Disable remote access: VPN, remote desktop tools, and remote support software.
  5. Remove the person from each business application: accounting, payroll, CRM, records system, scheduling, project tools, and the website.
  6. Remove the person from the company password manager, and change each shared password the person could see.
  7. Remove access to bank accounts, credit cards, payment processors, and vendor portals. Notify the bank in writing if the person was a signer.
  8. Remove administrator rights on social media pages, advertising accounts, and the domain registrar.

Email and files

  1. Check the mailbox for forwarding rules and inbox rules, and remove them.
  2. Decide who receives the person’s incoming email. Forward it to a manager or convert the mailbox to a shared one.
  3. Set an automatic reply that directs contacts to the right person.
  4. Transfer ownership of the person’s files and shared folders to a manager.
  5. Review the files the person shared outside the company and remove the links.

Devices and physical access

  1. Collect the laptop, phone, tablet, security keys, and portable drives.
  2. Collect keys, badges, and parking passes. Disable the badge.
  3. Change the alarm code, door codes, and safe combination.
  4. Remove company data from the person’s personal phone.
  5. Wipe and rebuild returned devices before you assign them to anyone else.

Phone and communications

  1. Reassign the phone extension and change the voicemail PIN.
  2. Remove the person from group chats, shared calendars, and distribution lists.

Records

  1. Remind the person, in writing, of confidentiality duties that continue after employment.
  2. Record the date and time of each step and who performed it.

What about shared passwords and accounts?

Shared accounts create the largest offboarding gap. One login for the supplier portal, one for the social media page, one for the Wi-Fi, all known to the person who just left. You must change each one.

Find them all. Ask the departing employee and the manager for a list, and review the shared vaults in your password manager. Then reduce the problem for next time: give each person an individual login wherever the service allows it, and store the few shared ones in the password manager, where you can see who had access.

How do I handle a departing employee’s email?

Keep the mailbox. Do not delete it on the last day. You may need its contents for customer follow-up, legal reasons, or an investigation.

In Microsoft 365, convert the mailbox to a shared mailbox and give a manager access. In Google Workspace, transfer the data or keep the account suspended until you archive it. Set a retention period in your policy, such as 90 days for routine roles and longer for regulated records, then archive or delete on schedule.

Check the forwarding rules first. A rule that sends a copy of every message to a personal address keeps running after the person walks out.

What about personal devices?

If the employee used a personal phone or computer for work, you need a way to remove company data from it. With mobile device management or app protection policies, you can wipe the work apps and leave the personal content alone. Without those tools, you depend on the employee’s cooperation. Sit down together on the last day, remove the work accounts from the device, and confirm that company files are gone from personal cloud storage.

A written device policy that the employee signed at hiring gives you the right to do this. See our post on smartphone security.

What about contractors and vendors?

Apply the same checklist. Contractors, temporary staff, interns, and vendor technicians often hold access with no end date. Set an expiration date on each account at the time you create it. When a vendor’s technician leaves that vendor, ask the vendor to confirm that the technician’s access to your systems ended. Our guide to vendor risk management covers the contract terms.

How do I handle an IT administrator who leaves?

With extra care. An administrator knows where everything is and may hold access that appears on no list.

  • Change the passwords on every administrator and service account, including the firewall, the router, the backup system, the domain registrar, and the cloud admin consoles.
  • Search for accounts the administrator created, and disable the ones you can’t explain.
  • Check for remote access tools installed on servers and workstations.
  • Review scheduled tasks, automation scripts, and API keys.
  • Confirm that the company, and not the individual, owns the domain name, the cloud tenant, and the software licenses.
  • Have a second administrator or an outside firm review the environment.

Avoid a single point of knowledge. At least two people should hold administrator access, and the documentation should live where the owner can reach it.

Does compliance require an offboarding process?

Yes.

  • HIPAA requires procedures for ending access to patient information when employment ends.
  • PCI DSS requires you to revoke access for terminated users at once.
  • The FTC Safeguards Rule requires access controls with periodic review.
  • Cyber insurers ask how you remove access for former employees.

Keep the completed checklist for each departure. It is your evidence.

How do I make offboarding easier?

Start at hiring.

  • Keep an access record for each person. List the accounts, devices, keys, and shared passwords you issue, as you issue them.
  • Use single sign-on where you can. One disabled login then closes many applications.
  • Assign access by role. A standard set for each job simplifies both granting and removing.
  • Give HR and IT one shared process. HR tells IT about each departure in advance, in writing.
  • Review access every quarter. Compare the active account list against the current staff list. Remove the accounts that match nobody.
  • Use company-owned accounts. Register social media, domains, and software under a company email address, never an employee’s personal one.

What are the most common offboarding mistakes?

  • Waiting days or weeks to disable accounts
  • Forgetting the applications that sit outside single sign-on
  • Leaving shared passwords unchanged
  • Letting email forward to a personal address
  • Deleting the mailbox and losing the records
  • Forgetting the door code and the alarm code
  • Skipping contractors and interns
  • Keeping no record of what you did

Your next step

Print the checklist above and run it against the last person who left your business. Each account you find still active is a gap to close today. Cerberus Cybersecurity writes access control and offboarding procedures and reviews account hygiene in our risk and compliance assessments. Contact us for help building yours.