Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Departing employees and data exfiltration: what controls actually work?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Departing employees create the highest-risk offboarding window because copy, sync, print, and transfer channels are often still open when access reviews are too late, according to Strac. The control gap is not visibility alone but content-aware enforcement that separates routine work from regulated data movement.

NHIMG editorial — based on content published by Strac: Solve Insider Risks When Employees Leave

Questions worth separating out

Q: What breaks when employees can still move data during offboarding?

A: The biggest failure is that access removal happens after the most dangerous behaviour has already occurred.

Q: When should organisations prioritise content-aware DLP over broad policy blocking?

A: They should prioritise it when users need to keep working while the organisation still has to stop high-risk transfers.

Q: What do insider risk teams get wrong about privacy and monitoring?

A: Many teams assume they must choose between privacy and detection.

Practitioner guidance

  • Tie leaver status to content-aware endpoint rules Apply stronger Block settings to USB, personal cloud sync, AirDrop, and print channels as soon as offboarding risk is identified, especially for users with access to regulated data.
  • Create a high-risk user watchlist Maintain a watchlist for privileged staff, contractors, remote workers, and employees showing behavioural changes near departure so monitoring and response can escalate before data leaves.
  • Classify sensitive data by exfiltration impact Separate regulated, confidential, and routine content so DLP actions can be stricter on customer lists, intellectual property, and other high-value records without blocking normal work.

What's in the full article

Strac's full article covers the operational detail this post intentionally leaves for the source:

  • Channel-by-channel endpoint DLP behaviour across USB, personal cloud, AirDrop, print, and other transfer paths
  • Examples of how Block, Warn, and Audit actions are applied differently by content type and user risk
  • Practical guidance for building a watchlist workflow around departing or high-risk employees
  • Implementation detail for reducing false positives while still stopping regulated data movement

👉 Read Strac's analysis of insider-risk offboarding and content-aware DLP →

Departing employees and data exfiltration: what controls actually work?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Offboarding is a data control problem, not just an HR control problem. The article reinforces a point identity teams often underweight: account disablement is only one part of leaver risk. If copy and transfer channels remain open during the notice period, the organisation has already lost the race. That is especially true in hybrid environments where endpoint, SaaS, and cloud sync paths all create separate exfiltration routes. The practitioner conclusion is clear: lifecycle control must extend beyond identity state changes.

A question worth separating out:

Q: Who is accountable when a fake employee exfiltrates data?

A: Accountability is shared across HR, identity verification, IAM, and security operations, because the failure spans hiring assurance, access provisioning, and monitoring. The right framework question is whether the organisation can show due diligence at each stage. If it cannot, the gap is governance, not just detection.

👉 Read our full editorial: Insider risk offboarding needs content-aware controls, not generic DLP



   
ReplyQuote
Share: