When an employee leaves an organisation, there’s usually a familiar checklist to work through. Laptops are returned, payroll is updated, exit interviews take place, and managers start planning how work will be handed over. Before long, everyone has moved on and attention turns to filling the vacancy.
Behind the scenes, though, another process should be taking place. User accounts need to be disabled, permissions removed, access to shared drives reviewed, and third-party applications updated. While these tasks rarely receive the same level of attention as the HR process, they’re just as important. Every account that’s left active and every permission that’s overlooked creates another opportunity for sensitive information to fall into the wrong hands.
Offboarding is often seen as an administrative task, but from a cyber security perspective it’s one of the most important controls an organisation has. The quality of that process determines whether former employees leave with nothing more than their memories, or whether they continue to have access to systems and information long after they’ve walked out of the door.

Access Has a Habit of Growing
Most employees don’t join an organisation with access to every system they’ll ever need. Permissions are added gradually as people change roles, join projects, take on extra responsibilities or cover for colleagues. Over the course of several years, it’s easy for someone to accumulate access to dozens of different applications, shared folders and cloud platforms without anyone stopping to review whether it’s all still necessary.
Excessive or outdated access is a security risk at any stage, which is why permissions should be regularly reviewed. When someone leaves without their access being removed, that existing risk becomes even greater.
Removing access is often far more complicated than granting it, particularly in organisations that rely on multiple business applications and collaboration tools. Some permissions are straightforward to revoke, while others are easily overlooked because they’re managed by different teams or sit outside central identity systems.
Research from IBM highlights why this matters. Its Cost of a Data Breach Report found that stolen or compromised credentials were the most common initial attack vector, responsible for 16% of breaches, underlining just how valuable legitimate accounts are to attackers. If an account hasn’t been properly disabled, or if permissions stay in place after someone leaves, those credentials can provide a direct route into the organisation.
What Happens When Access Isn’t Removed?
Offboarding gaps are usually the result of several small oversights that seem insignificant on their own, but become much more serious when they’re combined.
A Microsoft 365 account might be disabled, but access to a project management platform is forgotten. A contractor finishes their assignment, yet their account remains active because nobody remembers to remove it. A shared mailbox is left accessible, or administrator privileges granted during a short-term project are never revoked. None of these situations are unusual, particularly in larger organisations where employees use dozens of different systems every day.
If an attacker gains access to one of those forgotten accounts, they don’t have to work their way through multiple layers of security. They immediately inherit whatever permissions that user still has, whether that’s access to confidential documents, customer records, finance systems or internal communications. What began as a routine offboarding task can quicky become a much more serious security incident.
Insider Threats Aren’t Always Intentional
The phrase ‘insider threat’ often brings to mind someone deliberately stealing information before leaving an organisation. While those incidents do happen, they’re only one part of the picture.
Many insider risks develop because everyday processes haven’t been completed properly. A former employee may still have access to a shared drive because permissions were never removed, or a temporary contractor could retain access to cloud applications months after a project has finished. In some cases, nobody even realises an account still exists until unusual activity is detected.
That’s what makes offboarding such an important part of cyber security. The goal is to make sure that people only have access to the information they genuinely need, and only for as long as they need it.
Offboarding Is a Shared Responsibility
The most effective offboarding processes bring HR, IT, security and line managers together, meaning everyone understands their role in removing access, protecting data and reducing unnecessary risk.
HR is often the first to know when someone is leaving, making timely communication essential. Managers have the clearest understanding of the systems and information an employee has access to, while IT and security teams are responsible for disabling accounts, removing permissions and checking that access has been revoked across every platform. When those teams work in isolation, it’s much easier for something to be missed.
The challenge has become even greater as organisations have adopted more cloud-based applications. Employees now use a wide range of collaboration tools, customer relationship management systems, finance platforms and specialist software, many of which aren’t managed in the same way. Without a clear offboarding process, it’s easy for accounts to stay active because nobody realised they existed.
Building Better Offboarding Habits
Technology can automate parts of the offboarding process, but it can’t replace good governance. Organisations still need clear ownership of the offboarding process, consistent procedures for removing accounts and permissions, and regular access reviews to make sure user privileges continue to reflect current roles and responsibilities.
That starts with understanding what employees can access in the first place. Regular access reviews help identify permissions that are no longer needed, while maintaining an accurate inventory of applications makes it much easier to remove access when someone leaves. Automated workflows can also help ensure that tasks aren’t forgotten, particularly in larger organisations where multiple teams are involved.
Offboarding shouldn’t just be a task that’s completed on an employee’s final day. Periodic reviews of inactive accounts, privileged users and third-party systems can uncover accounts that have slipped through the cracks, reducing the likelihood that forgotten access becomes a future security problem.
Making Offboarding Part of Your Security Culture
Employees need to understand why offboarding matters and how seemingly routine processes can have lasting security implications.
Managers need to know the importance of notifying IT promptly before someone leaves. Project owners should regularly review who has access to shared workspaces and applications. Employees should feel comfortable flagging accounts or permissions that no longer seem appropriate, particularly after organisational changes or long-running projects.
Creating that awareness helps organisations move beyond seeing offboarding as an administrative process. Instead, it becomes another way of reducing opportunities for attackers and protecting sensitive information throughout the employee lifecycle.
That’s where regular security awareness training has an important role to play. Rather than relying on policies alone, employees need to understand how poor communication, forgotten permissions and incomplete offboarding processes can create real security risks.
Cyber Police is MetaCompliance’s live-action cyber awareness series that brings modern cyber threats to life through realistic workplace stories. Using professional actors, relatable characters and dramatised attacks, it shows how seemingly routine business processes, such as offboarding employees, managing user access and removing permissions, can create opportunities for cybercriminals, and how small oversights can quickly escalate into serious security incidents.
By seeing those situations unfold in context, employees gain a better understanding of why every stage of the offboarding process matters and how their own actions help keep the organisation secure.
Cyber Police turns security awareness into something employees genuinely engage with
Instead of relying on theory alone, each episode places viewers in realistic workplace situations, showing how everyday decisions, communication and business processes can influence cyber risk.
Covering everything from phishing and ransomware to insider threats, deepfakes and AI-enabled attacks, the series encourages discussion, reinforces secure behaviours and helps employees apply what they’ve learned in real-world situations.
Visit our Cyber Police page to watch a free episode, explore the full series or speak to our team about bringing story-driven cyber awareness training to your organisation.
Find out more about Cyber Police and discover how story-driven awareness training helps organisations build lasting security behaviours that go beyond compliance.
Offboarding FAQs
What is an insider threat?
An insider threat is any security risk that comes from someone with legitimate access to an organisation’s systems or data. This can include current employees, contractors, temporary workers or former employees whose access hasn’t been removed. While some insider threats are deliberate, many happen because accounts, permissions or access rights are left in place after they’re no longer needed.
Why is offboarding important for cyber security?
Offboarding is more than an HR process. It helps ensure that employees and contractors no longer have access to systems, applications and data once they leave an organisation. If accounts remain active or permissions aren’t removed, they can become an easy target for attackers or create opportunities for unauthorised access.
What are the risks of inactive user accounts?
Inactive accounts can provide attackers with a route into an organisation if they’re compromised. Because these accounts often receive less attention than active users, suspicious activity may go unnoticed while attackers use existing permissions to access systems, data or shared resources.
How can organisations improve their offboarding process?
A strong offboarding process should include disabling user accounts, removing access to all business systems, reviewing permissions, recovering company devices and regularly auditing inactive accounts.
Clear communication between HR, managers, IT and security teams also help to make sure that nothing is overlooked.
How does Cyber Police help employees understand insider threats?
Cyber Police uses realistic workplace stories to show how everyday business processes can create security risks. By bringing scenarios such as forgotten accounts, poor communication and incomplete offboarding to life through drama, employees gain a better understanding of how insider threats develop and why good security habits extend beyond preventing phishing emails.