Security teams should combine access review, targeted monitoring, and consistent exit procedures before resignation becomes effective. The practical goal is to identify what sensitive information the person can reach, watch for unusual movement in the 30 days before and after notice, and terminate access promptly. A written departure process matters because insider theft is often fast, opportunistic, and tied to the resignation window.
What makes the resignation window a high-risk moment for IP loss?
The risk is not just that an employee still has access, it is that they often know exactly which repositories, design documents, customer files, roadmap decks, or source code areas matter most. Once notice is given, the window for opportunistic copying can be short, subtle, and hard to distinguish from normal work unless teams already know what “normal” looks like.
In practice, the highest-risk pattern is speed plus familiarity: a person can stage material through approved tools, personal storage, or ordinary collaboration paths without triggering obvious alarms. That is why pre-resignation controls should focus on known access paths and the specific assets most likely to be targeted.
For teams mapping those access paths to control priorities, NIST SP 800-53 Rev 5 Security and Privacy Controls provides the right control vocabulary for access, audit, and configuration oversight.
How do access review and monitoring work together before notice becomes effective?
Access review answers the question, “What could this person reasonably remove, copy, or misuse?” Monitoring answers, “What changed once resignation became likely?” Both matter because a broad review without telemetry can miss active staging, while monitoring without scoping can produce noise and miss the sensitive repositories that matter most.
Security teams should narrow review to the person’s actual data reach, then increase scrutiny on the behaviours that tend to precede theft: unusual downloads, repeated file enumeration, bulk sync activity, atypical compression, access from unfamiliar devices, or off-hours movement. The goal is not to watch everything equally, but to watch the few signals that are strongly tied to exfiltration.
That control pairing aligns well with MITRE ATT&CK Enterprise Matrix for thinking about credential access, collection, and lateral movement patterns, and with NIST Cybersecurity Framework 2.0 for combining identify, protect, detect, and respond activities.
What should a departure process change before the final day?
A written departure process should make resignation a trigger for immediate operational decisions, not a casual HR event. Once notice is known, teams should know who reviews access, who approves exceptions, when credentials are revoked, how shared accounts are handled, and how evidence of suspicious behaviour is preserved for follow-up.
The best processes reduce ambiguity around timing. If the employee has access to sensitive intellectual property, access changes should not wait for the final working day by default. In higher-risk cases, the process should also define what is removed first, what is observed until offboarding, and which business owners must confirm that the user no longer needs access to critical material.
For organisations that rely heavily on cloud collaboration or shared development platforms, CSA MAESTRO agentic AI threat modeling framework is less directly relevant than access control itself, but it reflects the broader principle that authority should be explicit, bounded, and revocable. The more practical complement for this subject is NIST Privacy Framework when the material includes personally sensitive data alongside proprietary information.
Risk and Threat Considerations
Insider IP theft is often a control failure rather than a single dramatic incident. The main exposure is not only exfiltration, but also delayed detection, because a departing employee may already understand logging gaps, approval routines, and the fastest path to move material without raising suspicion.
Failure mechanism: Excessive standing access, weak monitoring, and delayed offboarding let a trusted user copy or stage sensitive material during the resignation window, often through normal business tools.
Impact: Source code, designs, bids, customer lists, pricing, and strategic plans can leave the organisation before the exit is complete, creating competitive, legal, and operational harm.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Restricts pre-exit access to the minimum needed for sensitive IP handling. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Supports targeted monitoring for suspicious pre-exit downloads and staging. | |
| PS-4 — Personnel Termination | Directly governs exit procedures and timely access revocation at offboarding. | |
| Recommendation — Reduce standing access before resignation and remove any excess privileges immediately. Review audit trails for unusual access and bulk movement during the notice window. Execute termination and offboarding steps promptly when resignation becomes effective. | ||
| MITRE ATT&CK | T1020 — Data Exfiltration | Covers the collection and transfer patterns behind insider IP theft. |
| Recommendation — Map suspicious file movement and staging behaviour to exfiltration techniques. | ||
| NIST CSF 2.0 | ID.AM-01 — Inventory of Physical Devices and Systems | Asset visibility is needed to know where sensitive IP resides and who can reach it. |
| Recommendation — Maintain an inventory of systems and repositories holding sensitive intellectual property. | ||
Practitioner Guidance
What to prioritise: Start with the highest-value assets and the smallest set of people who can reach them. If the employee can access crown-jewel material, treat the notice period as a controlled risk period and tighten review, logging, and access removal in that order.
What to verify: Confirm that every sensitive repository, shared drive, and collaboration space has an owner, a current access list, and a removal path that works on short notice. If you cannot prove who can reach the asset, you cannot credibly manage the resignation risk around it.
Practitioner takeaway: The objective is not to guess who might steal intellectual property, it is to shrink the opportunity window, make staging harder, and ensure the organisation can prove exactly what access existed before resignation became effective.
Related resources from NHI Mgmt Group
- How should security teams detect offboarding risk before an employee formally resigns?
- How should security teams reduce insider threat risk before investing in monitoring tools?
- How should security teams reduce insider risk by tightening access before people leave?
- How should security teams reduce identity theft risk when customer or employee credentials are used to open accounts or move money?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org