Every business has an onboarding routine — email set up, laptop issued, logins shared. Far fewer have the reverse. Yet the day someone leaves is a bigger security moment than the day they arrive: they walk out knowing your passwords, holding sessions on their personal phone, and — in too many SMBs — keeping working access for months because nobody owned the job of removing it.
Why leftover access is such a rich target
- Dormant accounts are unwatched: nobody notices odd sign-ins on a mailbox nobody uses.
- Shared logins outlive people: the ex-employee still knows the office Wi-Fi, the supplier portal password, the social media account.
- Third-party apps are forgotten: the accounting add-on, the scheduling tool, the file-share link — each one a door that HR’s checklist never mentions.
- Most incidents involving ex-staff aren’t malicious — but the ones that are (a disgruntled exit, a move to a competitor) have keys already in hand.
The offboarding checklist that fits on one page
- Same day: disable the identity (Microsoft 365/Google account) — disabling one central login should cut email, files and most apps at once. Revoke active sessions, not just the password.
- Same day: remove MFA devices and app passwords tied to the person; reclaim or remotely wipe company devices.
- Within a week: rotate every shared credential they knew — the password manager’s sharing report makes this a ten-minute job instead of a guessing game.
- Within a week: sweep third-party apps and integrations for their accounts; transfer ownership of anything the business needs (domains, social accounts, MYOB/Xero access).
- Every quarter: list all active accounts across your core systems and challenge every name you don’t recognise.
Make it a process, not a memory
The fix is ownership: one named person (office manager, IT provider) runs the checklist for every departure, friendly or otherwise, and files the completed copy. Centralising logins behind single sign-on and a team password manager turns offboarding from an archaeology project into a switch you flip — and it’s exactly the control insurers and auditors mean when they ask about “user access management”.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check