Organisations should remove physical access immediately, review application access, and confirm that monitoring is active across the systems where sensitive data lives. They should also enforce password protection, apply sanctions for misuse, and use training to reinforce acceptable use expectations. The goal is to close both digital and physical paths that could let an ex-employee remove company data.
Why departure access must be treated as both a physical and digital control problem
When an employee leaves, the risk is not just that they still know passwords or can reach a VPN. The practical issue is whether they can still enter a building, open a cloud app, or use a forgotten account path to reach sensitive data. Effective offboarding has to close every access route that could let a former employee act as a trusted insider.
That means the response should be coordinated across HR, IT, facilities, and the application owners who know where access still exists. If one team revokes badges while another leaves a SaaS account active, the organisation still has exposure. The real control objective is to make sure no standing path remains into systems or spaces that contain data, equipment, or operational leverage.
What has to be removed, reviewed, and verified
Physical access should be revoked immediately, because premises access can expose devices, paper records, meeting rooms, and unattended workstations. Digital access then needs a full review, not a single account toggle. That review should include cloud applications, privileged roles, shared accounts, local sessions, and any federated access that may persist after the employee record is closed.
Verification matters as much as revocation. Organisations should confirm that monitoring is active on the systems where sensitive data lives, so any attempted use after departure is visible. They should also ensure password protection is enforced on endpoints and applications, because an unlocked or weakly protected system can make a revoked user’s remaining access much more valuable than expected.
Where the organisation uses technical controls for access governance, this offboarding moment should also prompt a check for least-privilege drift, stale group membership, and access paths that were never formally owned. If the person had access to data stores, admin consoles, or collaboration tools, those permissions should be reviewed against current need, not left in place because they were inherited from an older role.
What good offboarding looks like in practice
Good offboarding is closed-loop, not just procedural. The organisation should be able to show that badge access is disabled, cloud entitlements are removed, high-risk accounts are checked, and any shared secrets or passwords the employee knew have been changed where necessary. If training and policy are part of the control set, they should reinforce that copying data on exit is misuse, not an acceptable last-day convenience.
- Remove physical access first when the departure is known, then complete the digital review without delay.
- Confirm whether the employee had access to cloud apps, shared drives, collaboration tools, admin consoles, or sensitive repositories.
- Check whether any passwords, recovery methods, or shared credentials could still open a path after account disablement.
- Validate logging and alerting on the systems that hold the organisation’s sensitive data.
- Document the final access status so HR, IT, and security all have the same closure point.
Risk and Threat Considerations
The main risk is that a departing employee can still exploit trust built during employment. Even a short delay in revoking access can allow data removal, policy bypass, or unauthorised viewing of records from cloud services, file shares, or the premises itself. The danger increases when the person knows where sensitive data lives and understands which controls are easiest to miss.
Failure mechanism: A stale badge, active cloud session, shared password, or overlooked role assignment leaves a live path into assets the employee should no longer reach. That path can be used deliberately or simply left available long enough for data to be copied before controls catch up.
Impact: The organisation can suffer data loss, confidentiality breaches, investigation overhead, and reputational harm, especially if monitoring or logging is weak and the departure was not handled as a coordinated access-removal event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Offboarding depends on timely account revocation and access review. |
| Recommendation — Revoke departed-user access and validate that no active accounts remain. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Departing-user access must be disabled, reviewed, and removed across systems. |
| AC-6 — Least Privilege | Residual access should be limited to the minimum needed until removal completes. | |
| Recommendation — Disable, remove, and audit accounts when an employee leaves. Restrict standing access and remove excess entitlements during offboarding. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights must be removed or adjusted when employment ends. |
| A.7.2 — Physical entry | Physical access is part of the same offboarding exposure as cloud access. | |
| Recommendation — Withdraw access rights promptly at termination and confirm completion. Remove physical access credentials and verify entry controls are disabled. | ||
Practitioner Guidance
What to prioritise: Treat the offboarding window as a time-bound access revocation process, not an administrative checklist. Physical access, cloud entitlements, and any shared secrets should be handled as one risk surface so that closure is complete enough to matter.
What to verify: Do not rely on “account disabled” alone. Verify that the former employee cannot still reach a cloud application through a second account, cached session, shared credential, or physical entry path, and confirm that logs will show any post-departure attempt.
Common mistake: Organisations often revoke the obvious identity first and assume the job is done. The higher-value failure is the hidden path, such as a shared workspace, a delegated admin role, or an application account that was never tied cleanly to one owner.
Practitioner takeaway: The goal is not simply to remove one login, it is to remove the departing person’s ability to reach sensitive data through any remaining trusted route, digital or physical.
Related resources from NHI Mgmt Group
- What happens when a departing employee or compromised user keeps active access to cloud applications?
- How should organisations modernise access management when they still need to protect on-premises applications in a hybrid IT environment?
- What happens when organisations keep separate access management tools for cloud and on-premises applications?
- What is the difference between protecting applications and protecting access?