The Security Risk Nobody Thinks About: When an Employee Leaves
When someone joins your team, there's usually a clear process — show them how things work, give them access to what they need. When someone leaves, there often isn't a matching process at all. In our research, this came up as a real, specific gap: staff turnover quietly leaving old access lying around long after someone's gone.
What this actually looks like in practice:
- A former employee's login to your business Instagram or shared email still works, months later.
- A shared password — for M-Pesa till management, a supplier portal, a shared drive — was never changed after they left.
- Nobody remembers exactly what access that person had in the first place, because it was never written down.
None of this requires the former employee to have bad intentions. The risk is simply that access nobody's tracking is access nobody can properly close.
A simple offboarding checklist, worth using every time someone leaves:
- List every account they had access to — email, socials, shared drives, payment systems, anything with a login.
- Change any shared passwords immediately, not "when we get a chance."
- Remove them specifically from shared systems, rather than assuming a password change alone covers it.
- Do this on their last day, not after — a gap of even a few days is a gap.
- Keep a simple running list of who has access to what, so this takes five minutes next time instead of a scramble.
This costs nothing and takes very little time — it's one of the highest-value, lowest-effort fixes available to any small business, precisely because it's so often skipped entirely.
Cybersentinel's assessment checks whether this kind of process exists in your business, and helps you build one if it doesn't.
See how your access controls score