What Happens to IT Access When an Employee Leaves?

Six months after a member of staff leaves, the login still works. Messages keep landing in an inbox no one reads, and the shared drive shows the same access it did on that final day.

Nobody decided this should happen; it just never got undone, and that is the gap most businesses carry without realising it.

When someone leaves, the energy goes into the handover and the goodbyes. The accounts, devices and permissions they leave behind rarely get the same attention, because nothing visibly breaks when they go.

For SMEs in Bishop’s Stortford and throughout Hertfordshire, managing employee access can easily be overlooked during a hectic week. Treating it as a cyber security and continuity issue, rather than an afterthought, is what closes that gap.

A Former Employee’s Account Is Still a Live Account

The thing to remember about a leaver’s login is that it doesn’t know its owner has gone.

Email, Microsoft 365, the CRM, shared folders, the accounting platform, and the various SaaS tools picked up along the way – all of these stay exactly as functional the day after someone leaves as the day before, unless somebody steps in to change that.

While an account stays open, it remains a route into business data. The exposure usually takes one of a few forms:

  • A former employee continuing to read company email or download files, whether out of habit, grievance or simple curiosity
  • Credentials being reused elsewhere, so a login tied to your systems gets caught up in an unrelated breach
  • An attacker finding a valid account that nobody is monitoring and using it as an easy way in

Attackers tend to look for the path of least resistance, and a live login that nobody is watching fits that description well.

The government’s Cyber Security Breaches Survey 2025/2026 found that the proportion of businesses reporting a breach that led to loss of revenue or share value rose from 2% to 5% over the year, with reputational damage climbing from 1% to 3%.

When incidents do bite, they increasingly cost real money and real standing, and unmanaged access is one of the simpler ways to hand an incident the opening it needs.

The Damage Goes Well Beyond Security

It would be a mistake to file unmanaged access purely under cyber security. The fallout reaches into parts of the business that have nothing to do with hackers:

  • Productivity: Nobody can find the files a leaver was working on because they sat in a personal OneDrive that has since been locked or left untouched
  • Client communication: Enquiries land in a mailbox no one is monitoring, so they go unanswered, and the client assumes you aren’t interested
  • Compliance: Data protection rules expect you to know who can reach personal data and to be able to show that access is controlled
  • Data ownership and lock-out: If a departing salesperson held the only login to a key supplier portal or the only admin rights to your social media, their exit can leave you shut out of your own tools

These are continuity issues as much as security ones. A business that cannot reliably account for who holds access to what is a business carrying hidden operational risk.

Cloud Tools Have Made This Harder, Not Easier

A decade ago, removing someone’s access mostly meant disabling their network account and collecting their laptop. The perimeter was the office. Today it’s far less tidy, for a few reasons:

  • Remote and hybrid working means staff connect from home, from personal devices, and through tools the central IT function may not have set up
  • Microsoft 365, SharePoint and Teams sprawl across shared sites and folders, each with its own separate permissions
  • SaaS platforms get adopted team by team, sometimes signed up for with a work email and a personal password and sometimes on a free tier that never appears on any invoice

The result is that the question “what does this person actually have access to?” has become difficult to answer. It’s that difficulty which is exactly why access control deserves more attention now.

You cannot remove access you don’t know exists, and the modern toolset makes it very easy for access to exist in places nobody is tracking.

Offboarding Is Also a Data Ownership Question

There is a part of leaving that often gets missed entirely, which is making sure the business keeps what belongs to it.

Important emails, working files, client records and shared documents need to be transferred into the right hands before or immediately after someone goes. If that does not happen, the knowledge simply leaves with the person.

Think about what tends to sit only in one place:

  • A half-finished proposal saved to a personal drive
  • The only written record of a client’s specific requirements
  • Running notes on a long negotiation that nobody else has seen

All of it can vanish into a deactivated account or an unreturned device. Treating handover as a data exercise means deciding in advance where a leaver’s files should end up and who becomes responsible for them.

This protects continuity and keeps you on the right side of your data protection obligations at the same time.

Where Proactive IT Support Changes the Picture

The reason access lingers is often because offboarding gets handled differently each time, depending on who is around and how busy the week is.

Proactive IT support closes that gap by making access management an ongoing discipline rather than a scramble at the point of exit. That means keeping a clear view of who has access, managing permissions, and removing access promptly when someone leaves.

At 4TC, we work with businesses across Bishop’s Stortford and Hertfordshire to keep this consistent as teams grow and change so a departure is handled to the same standard, whoever happens to be managing it that week.

The goal is straightforward. When someone leaves, their access should leave with them, and your data should stay where it belongs.

Speak to 4TC to Protect Your Business

Former employee access should not become a hidden security risk.

Speak to 4TC about managed IT support that helps keep your systems, data, and users under control. Get in touch today.

FAQs

  1. Why is employee access management important for SMEs?
    Because an open account is a live account. Strong employee access management means former staff cannot reach email, files or business applications after they leave, which is a core part of IT security for SMEs and a basic expectation under data protection rules.
  2. What are the biggest cloud access security risks when someone leaves?
    The main cloud access security risks are accounts that stay active across Microsoft 365 and SaaS platforms, shared logins that never get changed, and files saved in personal cloud storage that the business cannot see or recover.
  3. How does managed IT support help control access?
    Managed IT support gives you a consistent process for monitoring accounts, managing permissions and removing access when roles change. It also keeps a clear record of who can reach what, so nothing slips through when a team member moves on.
  4. Does 4TC provide cyber security support in Hertfordshire?
    Yes, 4TC offers IT support in Bishop’s Stortford and cyber security in Hertfordshire, helping local businesses secure company data and keep their IT processes consistent as their teams change.

The Employee Exit IT Checklist for Bishop’s Stortford Businesses

When an employee leaves, most businesses know how to handle the paperwork. Final pay is calculated, the P45 goes out, and the leaving card is organised. What happens to their accounts, devices and access rights is usually less organised, and it is the part that creates the most risk.

The window between a resignation date and a fully closed-out account is where former employees, lost devices and forgotten logins can still reach business data. For SMEs in Bishop’s Stortford and across Hertfordshire, where IT teams are often small or outsourced, employee IT offboarding can stretch out longer than anyone intends. The Information Commissioner’s Office expects employers to “document the leavers’ process and regularly check to confirm compliance” as part of basic data protection accountability. In practice, very few small businesses can show what good looks like.

The checklist below sets out the IT steps worth getting right every time someone leaves.

Remove access to business systems on day one

The single most important step is also the most delayed. Every system the leaver touched needs its access revoked on or before their final day – email, Microsoft 365, cloud platforms, CRMs, shared drives, VPNs, accounting tools and any line-of-business applications. That includes the smaller subscriptions as well as the obvious central accounts: design tools, marketing platforms, and anything where someone signed up using their work email.

ICO guidance on access control puts this in straightforward terms: businesses should keep records to demonstrate they “remove access rights in a timely fashion”. The UK government’s Cyber Security Breaches Survey 2024 shows that half of UK businesses experienced a breach or attack in the previous twelve months, and the most disruptive ones tend to involve credentials being misused rather than systems being broken into. Closing accounts promptly is one of the few entirely free controls a business has.

A useful practice is to disable accounts on the last day rather than deleting them immediately. That gives IT time to forward email, archive files and assign ownership of anything that needs to move on, without leaving access open.

Recover devices and equipment before they walk out the door

Laptops, phones, tablets, monitors, security keys, dongles, chargers and the small mountain of accessories sent out during the hybrid-working era all need to be tracked back in. Without a record of what was issued and to whom, it is difficult to know whether anything is missing until somebody else needs it.

Two things make device recovery less painful. The first is keeping an up-to-date asset register, ideally linked to the standard staff lifecycle process so any new kit is added at the point of issue. The second is having the ability to remotely lock or wipe a device if it is not returned, which is now standard with most modern mobile device management platforms.

This is also the right point to make sure encryption is enabled and verified. A returned laptop with no encryption configured is still a meaningful data risk.

Secure files, shared folders and anything in personal storage

Most leavers will have created or saved files in a mix of locations such as their OneDrive, Teams sites, SharePoint, network shares, sales platforms, or the occasional Dropbox folder. A structured offboarding step should review every shared area the person had access to, transfer ownership of business-critical files, and check that nothing important is sitting somewhere only they could see.

The harder question is what to do about personal storage. If a leaver has used a personal device or a personal cloud account to handle business data, the business needs to know. The ICO’s employment records guidance makes clear that data protection accountability covers all the places business data ends up, not just the ones the employer chose. Asking the question as part of the exit conversation, and following up if anything is found, is part of doing this properly.

Review passwords, shared logins and admin permissions

Shared logins are a fact of life in small businesses. The marketing inbox, the company social media account, and the supplier portal nobody else has set up a profile for. When somebody leaves, every shared password they knew needs to be changed, and any admin rights they held need to be reviewed and reassigned.

Two specific areas to check: saved passwords in browsers, which can quietly preserve access long after an account is closed, and any password manager memberships the leaver had. If those are left in place, the business can find that the leaver still holds the keys to platforms IT thought had been locked down.

Permissions are worth a wider sweep at the same time. The ICO recommends auditing privileged accounts and assigning end dates to access where it is not needed permanently. Someone leaving is a good moment to look across the rest of the team and confirm nobody else is carrying access they no longer need.

Make offboarding a repeatable process

The reason so many small businesses end up with orphaned accounts and unaccounted-for laptops is rarely carelessness. It is that each exit gets handled slightly differently, depending on who is around and how busy the week is. A consistent, written process closes that gap.

A useful baseline is a single checklist that covers accounts, devices, data, passwords and confirmation that each step has been completed and by whom. The checklist should sit with whoever manages the IT function, whether that is an internal lead or an external partner, and trigger automatically when HR confirms a leaver.

The checklist at a glance

When an employee leaves, work through the following:

  1. Disable accounts across email, Microsoft 365, cloud platforms, CRMs, shared drives, VPNs and any line-of-business tools they used
  2. Recover laptops, phones, tablets, security keys and accessories, and verify encryption on returned devices
  3. Review every shared folder and platform they had access to; transfer ownership of business files and ask about any business data held in personal storage
  4. Change shared passwords, remove admin rights, and check saved logins in browsers and password managers
  5. Document the process so it runs the same way every time, with HR triggering IT and a named owner signing each step off

4TC supports businesses across Bishop’s Stortford and Hertfordshire in setting up structured leaver processes alongside the rest of their IT, so each exit is handled to the same standard without anyone having to remember the steps.

If your business needs a clearer process for removing access, securing devices and protecting company data when staff leave, speak to 4TC about proactive IT support.

CTA