Between August and December of 2022, a former TD Bank employee held onto access to the bank's systems and used it to view and share sensitive customer information: names, birth dates, account numbers, and transaction records. The bank didn't catch it until months later. Customers found out even later than that, when notification letters started arriving in January 2025.
It wasn't a one-time lapse. TD Bank disclosed similar insider access incidents again in 2023, and again in filings made in 2026, each involving an employee who had access to customer data they should not have had. This is a bank with a massive compliance department, dedicated security staff, and regulatory obligations most small businesses never have to think about. If a gap like this can happen there, repeatedly, it's worth asking a blunt question about your own business: when someone leaves your company, what actually happens to their access?
For a lot of small and mid-sized businesses, the honest answer is "we're not entirely sure." Offboarding tends to focus on the visible parts, like collecting a laptop and disabling an email account. The access that lives everywhere else, in SaaS tools, shared logins, cloud storage, forwarding rules, and old sessions that never got logged out, often sticks around far longer than anyone realizes.
Why This Gap Is So Common
Research on this problem tends to land on the same uncomfortable numbers. In a survey by Beyond Identity, the large majority of former employees surveyed said they still had access to at least one account or system from a previous employer after leaving, and a meaningful share admitted to actually using that access. A separate OneLogin study found that roughly a third of organizations take more than a week to fully deprovision a departing employee across all their accounts, and a fifth of former employees' accounts remain active for up to a month after they're gone.
The reason isn't usually negligence. It's structure. Most small businesses provision access to a new hire's role over time, a login here, a shared drive folder there, an app added six months in when a new project starts. Nobody keeps a running master list. So when that person leaves, IT is left trying to reconstruct, from memory, everything they were ever given access to. Anything that isn't remembered doesn't get revoked.
Where the Access Actually Lives
Email and calendar systems. A disabled inbox doesn't always mean the access is gone. Forwarding rules set up months earlier can quietly route incoming mail to a personal address. Shared calendars, delegated mailbox permissions, and distribution list memberships often survive the account deactivation entirely.
Cloud storage and file shares. Someone who spent years accumulating access to shared drives, client folders, and internal documentation frequently keeps personal copies synced to a laptop or phone well after their last day, especially if that device was never company-managed.
SaaS applications. This is where most orphaned access hides. CRM platforms, project management tools, accounting software, HR systems: each one is a separate login that has to be found and closed individually unless single sign-on is in place. A company using twenty or thirty SaaS tools, which is normal for even a small business today, is relying on someone remembering every single one.
Shared and service credentials. Generic logins for a shared social media account, a vendor portal, or a piece of legacy software rarely get rotated when an employee leaves, because doing so means updating it everywhere it's used. These are some of the longest-lived exposure points in a typical offboarding process.
VPN and remote access. If remote access credentials aren't tied to a central identity system, a departed employee can sometimes still reach the internal network from home long after they've stopped showing up to the office.
What This Actually Costs
This isn't only a security question, it's a financial and compliance one. Under the FTC Safeguards Rule, businesses that handle certain types of financial data are required to maintain access controls and regularly review who has access to what, including removing access when it's no longer needed. Auditors reviewing SOC 2, ISO 27001, or similar frameworks routinely flag active accounts belonging to former employees as a documented control failure, not a minor oversight. There's also a quieter cost: businesses keep paying for SaaS licenses tied to people who no longer work there, simply because nobody closed the account. For a company with normal turnover, that adds up over a year without anyone noticing.
Building an Offboarding Process That Actually Works
None of this requires enterprise software or a dedicated security team. It requires a checklist that gets followed every single time, without exception, regardless of whether someone leaves on good terms or bad ones.
- Keep a running access inventory per employee. Every account, app, and shared credential someone is given should be logged at the time it's granted, not reconstructed later from memory.
- Cut access at the identity layer first. If you use single sign-on, disabling the central identity account should be the very first step, since it cuts access to every connected app at once. This is the single biggest thing a small business can do to shrink the offboarding gap.
- Revoke active sessions, not just passwords. Resetting a password doesn't always log someone out of a session that's already active on a phone or home computer. Sessions and tokens need to be explicitly terminated.
- Time IT and HR together. Access should be cut off on the employee's last working day, not "sometime that week." For involuntary terminations, IT should be ready to revoke access at the moment the employee is notified, not after.
- Check for forwarding rules and delegated permissions. Before closing an email account, look for forwarding rules, shared calendar access, and mailbox delegation that might otherwise be missed.
- Rotate any shared credentials the employee knew. Generic logins for vendor portals, social accounts, or shared tools should be changed, not just for the departing employee's own accounts.
- Reclaim or wipe devices. Company laptops and phones should be collected and wiped. If the employee used personal devices for work (email, Slack, file access), those need to be checked and disconnected too.
- Do a 30-day access review. A short follow-up check a few weeks after departure catches anything that slipped through the first pass, before it becomes a long-term blind spot.
A managed IT provider can build and run this process consistently, which matters more than any individual step. The businesses that get burned by this aren't usually the ones without a checklist; they're the ones with a checklist that only gets followed some of the time.
Frequently Asked Questions
How quickly should access be revoked after someone leaves?
Ideally, the same day, and for involuntary terminations, at the moment the employee is notified rather than afterward. CISA's Cyber Essentials guidance treats prompt access removal as a baseline control, not an advanced one.
What's the single biggest gap in most small business offboarding processes?
SaaS applications outside of single sign-on. Email and core file systems usually get closed reliably. The tools added over time, project management apps, niche vendor portals, industry-specific software, are the ones most likely to be forgotten.
Do we need a different process for someone who's fired versus someone who resigns?
The end result should be the same, full access removal, but the timing differs. For a resignation with notice, you have time to plan the transition. For a termination, access should be cut at or before the conversation happens, not after.
What about employees who used their personal phone or laptop for work?
This should be part of the offboarding checklist, not an afterthought. Confirm that company email, Slack, shared drives, and any other access has been removed from personal devices, and that no local copies of company files remain.
Is a formal offboarding process actually required by law?
It depends on your industry and what data you handle. Businesses subject to the FTC Safeguards Rule, HIPAA, or similar frameworks are generally required to maintain and document access controls, which includes timely removal of access when employment ends. Even outside a specific regulatory requirement, insurers increasingly ask about this during cyber insurance underwriting.
About ITGuys
ITGuys is a Managed IT Support company that has been helping businesses solve technology problems since 2009. We work with companies of all sizes to provide reliable, practical IT solutions that keep teams productive and secure.
Our services include managed IT support, network cabling, office onboarding and offboarding, email migration, IT consulting, wireless networking, infrastructure upgrades, and ongoing technical support for businesses across the United States.
We believe technology should make business easier, not more frustrating. Our goal is to provide straightforward IT guidance that helps businesses avoid downtime, improve reliability, and make smarter technology decisions.
Recent Comments