TL;DR: Departing employees can quietly collect sensitive data before they leave, and Cyberhaven argues that AI-native insider risk management is needed to catch exfiltration earlier as workers prepare to depart. The deeper issue is not discovery alone but whether teams can turn data visibility into actionable context before data walks out the door.
NHIMG editorial — based on content published by Cyberhaven: Stopping Data Exfiltration: Departing Employees Pose Significant Risk
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when non-employee access is not removed at offboarding?
A: When non-employee access is not removed at offboarding, the organisation loses control of who can still reach admin, customer, or communications systems.
Q: Why do data classification labels often miss insider exfiltration risk?
A: Classification tells you that data is sensitive, but it does not show whether the movement is expected, excessive, or tied to a departure event.
Q: How can security teams tell whether a leaver is staging data for exit?
A: Look for repeated downloads, unusual compression or export activity, transfers to personal locations, and access patterns that change after resignation is known.
Practitioner guidance
- Tighten leaver monitoring before offboarding completes Create a dedicated monitoring tier for employees in notice periods, with increased review of downloads, transfers, shared-drive activity, and personal-email forwarding from the moment departure is known.
- Correlate activity with employment status changes Feed HR departure signals into insider-risk workflows so anomalous retrieval volume, off-hours access, or repeated exports are evaluated in the context of resignation or termination status.
- Use lineage to validate sensitive-data movement Track where sensitive records originate, how they are transformed, and where they are copied so investigators can distinguish ordinary work from suspicious staging for departure.
What's in the full article
Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:
- How Cyberhaven says Linea AI surfaces exfiltration behaviour during resignation periods
- The insider-risk workflow details behind early detection and escalation decisions
- Examples of how departing employees move sensitive data through common business tools
👉 Read Cyberhaven's whitepaper on stopping data exfiltration by departing employees →
Departing employees and data exfiltration: where insider controls fail?
Explore further
Departing-worker exfiltration is a lifecycle problem, not just an insider-threat problem. The decisive failure is often that access governance ends too late, after the employee has already had time to stage data for departure. That makes leaver management an identity lifecycle control issue as much as a detection issue. Practitioners should treat exit periods as a distinct governance state with tighter monitoring and shorter response windows.
A question worth separating out:
Q: Who is accountable when insider exfiltration occurs during offboarding?
A: Accountability is shared across security, HR, and the business owner for the affected data, but security teams need clear ownership for monitoring and response. Frameworks such as NIST CSF and NIST SP 800-53 support this by tying monitoring, access control, and auditability to operational responsibility.
👉 Read our full editorial: Data exfiltration by departing employees exposes the insider risk gap