Join our Newsletter — 33% off our NHI Course

What are the best practices for reducing access-related breach risk when employees leave or passwords are shared?

The safest approach is to remove standing access quickly, enforce unique credentials, and centralise access governance so privileges do not persist after role changes. Organisations should also review who can reach sensitive systems, prohibit password sharing, and tie access approvals to current employment status. These controls reduce the chance that old entitlements become an easy path into critical applications.

Why leavers and shared passwords create breach exposure

When access outlives employment or credentials are reused by multiple people, the organisation loses accountability and control over who can reach sensitive systems. A departed employee may still have a valid path in, and a shared password makes it difficult to prove which user acted. That combination turns ordinary account hygiene into a breach path.

The core problem is not only “too much access”, but stale access plus weak attribution. If someone can still authenticate after role change or departure, the exposure depends on how quickly the organisation revokes access, rotates secrets, and removes shared credentials from business processes. Identity governance for leaver risk is especially important when former staff retain indirect access through privileged or shared accounts.

In practice, the highest-risk pattern is a credential that continues to work after the business relationship has ended. That can happen through delayed offboarding, service accounts left untouched, or passwords informally passed between teams. Password security guidance and real breach case studies both show how reused or exposed secrets often become the easiest entry point.

What good offboarding and credential separation look like

Effective offboarding starts before the final day. Access should be tied to current employment status, role, and business need, then removed or disabled as soon as those conditions change. The same principle applies to shared passwords: every person should have an individual account, so access can be revoked without breaking the whole team’s workflow.

Unique credentials matter because they make revocation precise. If one employee leaves, the organisation can disable that person’s access without changing everyone else’s login. Where shared access still exists for legacy or technical reasons, it should be treated as an exception with a clear owner, a documented justification, and a planned exit path to individual credentials or delegated access controls.

Centralised access governance is what keeps this from becoming a one-time cleanup exercise. Review current entitlements against active employment status, confirm who can reach sensitive systems, and ensure privileged access follows least-privilege rules rather than being inherited informally across teams. Breach reporting on exposed vault keys and backups is a reminder that secret sprawl and delayed revocation can turn a single compromise into broad access.

Why password sharing weakens attribution, monitoring, and response

Password sharing does more than violate policy. It breaks attribution, which means logs, approvals, and investigations no longer reliably identify the real actor. If one shared credential is used by multiple people, access reviews become less meaningful and suspicious activity is harder to separate from normal use.

It also weakens incident response. If a shared password may be known by former employees, contractors, or informal team members, the response is not just “change the password”, but “find every place that secret was used and every account it exposed”. That is why shared credentials should be phased out in favour of named accounts, MFA, and controlled delegated access where a business process truly needs it.

Identity and insider-threat guidance is useful here because the same controls that reduce leaver risk also improve detection and accountability for misuse. Password policy guidance further supports the operational point: unique, non-shared credentials are easier to review, rotate, and monitor than a single password spread across a team.

Risk and Threat Considerations

Leaver risk and shared-password risk are attractive to attackers because they create a low-friction path into live systems without needing a fresh compromise. A stale account, an unreleased privileged password, or a reused secret can provide persistence long after the original user has gone.

Failure mechanism: Access is not removed fast enough, or a shared secret remains valid across multiple users and systems, so an old credential still authenticates and bypasses intended separation of duties.

Impact: Attackers or insiders can reach sensitive applications, impersonate legitimate users, move laterally, and make investigation harder because the real actor is obscured by shared access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Leaver access that persists after departure is a direct offboarding failure.
NHI-02 — Secret Leakage Shared passwords and exposed credentials are the core breach path here.
NHI-05 — Overprivileged NHI Stale or shared access often leaves excessive privilege in place after role change.
Recommendation — Disable departed users and remove their secret-backed access immediately. Eliminate shared secrets and rotate any exposed credential immediately. Review entitlements and reduce standing privilege to the minimum needed.
NIST SP 800-53 Rev 5 AC-2 — Account Management Account lifecycle controls cover disabling users and managing shared accounts.
IA-5 — Authenticator Management Password sharing and rotation are authenticator management issues.
Recommendation — Enforce timely account disablement and periodic account review. Require unique authenticators and rotate credentials after exposure or departure.

Practitioner Guidance

What to prioritise: Make leaver processing and password sharing visible as access-risk controls, not just HR or user-experience tasks. The first thing to verify is whether every active login can be tied to a current person, service, or business owner.

What to verify: Confirm that offboarding disables access quickly across SSO, VPN, privileged systems, and any shared application accounts; then check that exceptions are documented, time-bound, and reviewed. If a shared password cannot be replaced immediately, treat it as a temporary risk acceptance, not a stable control state.

Common mistake: Rotating one password while leaving old entitlements in place. That may stop one path, but it does not solve the underlying problem if the same user still has another active account or if the shared secret remains embedded in workflows.

Practitioner takeaway: The strongest breach reduction comes from removing stale access first, then eliminating shared credentials so every remaining permission is attributable, reviewable, and revocable on demand.