Offboarding in most workplaces is a straightforward process, but some crucial practices are often overlooked when employees resign, retire, or are terminated from the company. Typical steps include knowledge transfer, returning company property, conducting exit interviews, and processing final pay, but some organizations do the bare minimum when it comes to revoking digital access. One survey has found that about 47 percent of 1,000 US workers are still using their employer's passwords after leaving the company. While more than a quarter of respondents said that they only used their old passwords to access paid tools or subscriptions, 56.2 percent admitted that they opened their previous accounts to access information that they can use to their advantage.
A poorly executed employee offboarding can lead to security or data breaches that can harm a company's finances and reputation. To protect critical corporate accounts, employers should execute a swift and thorough offboarding workflow that eliminates all digital and physical access. Here's what your business should do to prevent your former employees from becoming a major cybersecurity risk.
Why Access Persists
You may have revoked your former employee's access to corporate email accounts, but there are other ways that they can access these to keep tabs on your company, poach clients, or disrupt operations. For instance, if they used their personal smartphones to access emails, note that mobile mail apps like Apple Mail or Outlook often use auth tokens that do not instantly terminate when the main password is changed or when the account is terminated. This creates a risk for business email compromise, and disgruntled employees may start a BEC attack chain, which involves mining email content for information to commit financial fraud. They could also send phishing emails to internal users, erase important data, or plant malware in key systems.
Another reason why access persists is due to failure to update group or team passwords. When a team member resigns or is terminated, the current password remains active. Unless it's manually changed, ex workers may continue to log in to these platforms, which could lead to backdoor access to sensitive data. Those that are particularly high risk include Meta Business Suite, LinkedIn, or X log ins managed by a marketing team using one common password, shared email inboxes accessed through webmail log ins, and accounts for premium software or stock photo sites.
Shared log-ins to cloud storage create even greater risks as digital repositories contain a wealth of sensitive information, making them high-priority targets of disgruntled employees. In September 2018, a former Cisco engineer who retained access to the company's cloud infrastructure was able to wipe over 450 virtual machines hosting core Webex Teams functions. This caused a major operational outage that resulted in $2.4 million in operational and recovery damages. This incident clearly emphasizes the need for rapid offboarding and immediate revocation of all systems and platform access, whether you're running a new business or an established company.
Implement an Effective and Thorough Offboarding Workflow
To prevent former employees from accessing corporate platforms, deactivate all accounts across email, SaaS, cloud storage, and internal networks the moment they depart. Be sure to revoke active VPN sessions, cloud tokens, and remote desktop tools immediately, then remove their names from contact lists, internal directories, and public-facing websites and social media platforms to deter social engineering attempts.
Next, reset admin credentials and shared departmental passwords that the user can access. Be sure to collect all company-owned devices, and have your IT department perform data wipes on all tablets, laptops, and mobile phones before reissuing them to new employees. Ask your IT staff to monitor systems for suspicious activity. If there are active sessions by former employees, forcefully put a stop to them by using Google Space Admin to sign out all ongoing sessions. It's also a good idea to restrict all current employees to the least privilege necessary. This grants them access to only the necessary tools that they need to do their tasks, and this can help to protect your business from digital breaches.
Be on the Lookout for Pre-Offboarding Misbehavior
Before their official termination or resignation, some employees may engage in nefarious activities that could harm your company. For instance, they could steal data by downloading them to personal external drives or cloud accounts, so be on the lookout for unusual spikes in downloading files. You may also have to check if they've been accessing client databases more often than usual, or if they've been logging into sensitive corporate systems at odd hours.
Use data loss prevention tools and user activity monitoring tools to flag bulk file transfers or unauthorized device usage. Also, keep planned terminations or restructures confidential until the exact moment when employee access can be revoked.
Secure your vital corporate accounts before it’s too late. Be sure to properly offboard workers, and revoke their access across all platforms and systems immediately to protect your business from data theft and financial losses.