
An employee resigns on a Friday. HR completes the paperwork, the team says its goodbyes, and by Monday everyone has moved on. Except their email account, VPN access, and shared drive permissions may still be active, sometimes for days or even weeks.
A strong employee offboarding checklist treats an employee’s departure as a security event, not just an HR process. Every account that remains active is another opportunity for a former employee, or someone using stolen credentials, to access company systems.
Why Offboarding Is a Security Event, Not Just an HR Task
Access that remains active after an employee leaves is one of the quieter risks in small business IT because nothing appears to be wrong. The accounts still work, files remain accessible, and there is no obvious sign that the business is exposed.
According to Verizon’s 2025 Data Breach Investigations Report credential abuse remained the leading way attackers initially gained access to organisations, accounting for 22% of breaches analyzed. Every account that remains active after an employee leaves is another credential that could be abused if it falls into the wrong hands.
A former employee’s active account is one of the easiest security risks to eliminate because the organisation decides exactly when access should end.
The Ponemon Institute’s 2026 Cost of Insider Risks: Global study found that organisations spend an average of $19.5 million annually responding to insider-related incidents. Among the different types of insider events, credential theft remained the costliest on a per-incident basis, highlighting the damage that can occur when attackers gain access using legitimate accounts.
That research focuses primarily on larger organisations, so the dollar figures won’t translate directly to every small business. The lesson, however, is universal: accounts that remain active after someone leaves create unnecessary risk. Disabling access immediately removes an opportunity that attackers frequently exploit.
Building Your Employee Offboarding Checklist
An effective employee offboarding checklist does not require complicated software. It requires a consistent process that is followed every time, regardless of how the employee leaves the organisation.
Cut core access on the employee’s last working hour
Email, VPN, and single sign-on access should be disabled as soon as employment ends, not hours or days later.
The Canadian Centre for Cyber Security recommends revoking account access and administrative privileges as soon as they are no longer required, making timely offboarding an important part of reducing insider threats and limiting unnecessary access.
Track every account tied to that person, not just email
Not every business application is connected to a single sign-on. Password managers, cloud storage platforms, accounting software, and industry-specific tools often require separate access to be revoked.
Without a current inventory of the systems each employee uses, it is easy for accounts to be overlooked and remain active after someone leaves. Much like vendor access management, keeping an up-to-date inventory is far more reliable than trying to reconstruct who had access after the fact.
Recover or wipe company devices and remote access tools
Collect company devices promptly and remove company data or remote-access software from personal devices where appropriate. Any device that still has access to business systems after an employee leaves represents an unnecessary security risk.
Document the offboarding for compliance purposes
The Office of the Privacy Commissioner of Canada notes that PIPEDA requires organisations to limit the collection, use, disclosure, and retention of personal information, and to establish documented policies and procedures for retaining and securely disposing of that information.
A well-defined offboarding process helps put those requirements into practice by ensuring access is removed and information is handled consistently when employment ends.
The Accounts Everyone Forgets
Shared accounts are one of the easiest things to overlook during offboarding. A former employee may still be able to use a shared password long after their individual account is disabled, especially when no one remembers to change credentials that were never assigned to a specific person.
Reviewing how shared credentials get handled across your organisation is worth doing before the next departure, not after.
When the Departure Isn’t Friendly
Not every employee leaves on good terms or with advance notice. Terminations, layoffs, and unexpected resignations leave little time to complete a full offboarding process.
That’s why every organisation should have a streamlined version of its offboarding checklist ready to use. The priority is to disable core accounts immediately, alert IT before the departure is complete, and recover company devices as quickly as possible.
Is Your Offboarding Process Actually Airtight?
An employee offboarding checklist is only effective when it is followed consistently, whether someone leaves on good terms or under difficult circumstances. The accounts most likely to be missed are often the ones that fall outside the standard process.
Combining a documented offboarding checklist with strong access management practices helps identify those gaps early and remove unnecessary access before it becomes a security incident.
Book an assessment with Data First Solutions. Call our sales team at 416-412-0576 or reach us online to review your current offboarding process.
Article FAQs
What should be the first step in an employee offboarding checklist?
The first priority is to disable access to core systems, including email, VPN, and single sign-on. Removing access as soon as employment ends reduces the risk of unauthorised access while the rest of the offboarding process is completed.
Why do shared accounts create such a big risk during offboarding?
Shared accounts for social media, vendor portals, and team inboxes are not linked to an individual employee account. Disabling a departing employee’s login does not prevent them from accessing shared accounts if they still know the password. Any shared credentials they used should be updated as part of the offboarding process.
How quickly should access be revoked when someone is terminated unexpectedly?
Immediately. Organisations should have a streamlined offboarding process for terminations, layoffs, and other unexpected departures so managers can disable core accounts, notify IT, and begin recovering company devices without delay.









