Employee offboarding checklist: how to cut off a former employee's access the same day
Two days after a New York credit union fired a part-time employee, she logged back in from home and deleted more than 20,000 files, because her remote access still worked.[1] This guide shows how to shut off a departing employee's or contractor's access on their last day, in the right order, with a checklist a small office can actually follow.
Why same-day offboarding matters
Offboarding is the set of steps you take when someone leaves: collecting equipment, closing accounts and changing anything they knew. Most small offices do some of it. The trouble is the gaps between "some" and "all," and the days between the last day and the day someone gets around to it.
The Federal Trade Commission uses exactly this failure as a lesson in its guide for businesses. In one enforcement case it describes, a company shared a master cloud login among employees and outside contractors and did not change it when a contractor left. The former contractor later used it to take personal information on about 40 million users.[2] Nobody had to break in. The door was simply never locked behind them.
Most people who leave never do anything wrong. Same-day offboarding is not an accusation. It is the same kind of routine as returning the office keys, and it protects the person leaving as well, because nothing can later be blamed on an account that was closed.
Three cases, one missing step
The credit union. Juliana Barile was fired on May 19, 2021. On May 21 she connected remotely and, in about 40 minutes, deleted over 20,000 files and about 3,500 directories, roughly 21.3 gigabytes, including mortgage loan applications and the folder holding the credit union's anti-ransomware software. Cleanup cost about $10,000. She pleaded guilty to computer intrusion.[1] Court papers described a request to the outside IT firm to disable her access that was never carried out.[3] Our case file on the fired employee's 40 minutes covers the details.
The cloud engineer. Sudhish Kasaba Ramesh resigned from Cisco in April 2018. In September 2018 he got into the company's cloud environment and deployed code that deleted 456 virtual machines running its Webex Teams app. More than 16,000 accounts were shut down for up to 2 weeks, and Cisco spent about $1.4 million on restoration and more than $1 million on customer refunds. He pleaded guilty and was sentenced to 24 months in prison.[4] See the Cisco Webex deletion.
The competitor. An engineer who left a Tennessee engineering firm to co-own a rival kept reading a former colleague's mailbox for nearly 2 years, and used it to pick up new passwords for the firm's document system each time they were changed. He pleaded guilty and was sentenced to 18 months in prison.[5] Read how a shared mailbox kept the door open.
Different people, different motives, the same gap: access that should have ended on the last day did not.
Before anyone leaves: build the access list
You cannot close what you do not know about. The single most useful thing an office manager can do is keep a simple access list for every role, before anyone resigns. For each person, write down:
- Core accounts. Email, office suite, file storage and computer login.
- Business apps. Practice management, electronic health records, tax or accounting software, case management, CRM, scheduling and phone system.
- Money access. Online banking, payroll, credit cards, payment processors and purchasing accounts.
- Remote access. VPN, remote desktop tools and any vendor portal.
- Shared secrets. Shared mailboxes, shared passwords, Wi-Fi password, alarm codes, door codes and safe combinations.
- Public accounts. Social media, website host, domain registrar and review sites.
- Physical items. Laptop, phone, security keys, badges and building keys.
Where you can, have staff sign in to business apps with their company email account (often called single sign-on). Then disabling one account closes most doors at once.
The last day: the order that works
For a planned departure, do this on the last afternoon. For a firing, do it during the meeting, not after. The credit union case shows what 2 days can cost.
- 1. Remote access first. Disable VPN, remote desktop and any way in from outside. This is the door a departing person can use from home that evening.
- 2. Email and the main account. Disable the account rather than deleting it, so records and mail are kept. Sign out all active sessions on phones and browsers, which most office suites let an admin do in one click.
- 3. Money. Remove the person from bank, payroll and card accounts, and tell your bank if they were an authorized signer.
- 4. Business apps and cloud consoles. Work through the access list. Cloud admin consoles and access keys are the ones most often forgotten, as the Cisco case shows.
- 5. Shared passwords. Change every shared password and code the person knew, and send the new ones through a channel they cannot see. Rotating a password does nothing if the new one lands in a mailbox they can still read.
- 6. Devices and keys. Collect equipment. Remove the person's phone from company email and wipe work data if it was a personal device.
- 7. Forward and hand off. Set up mail forwarding or an auto-reply to the right colleague, and move ownership of files they created.
Contractors, temps and IT providers
Contractors are where offboarding most often slips, because there is no HR exit meeting. Put an end date on every contractor account when you create it, so it switches itself off. When a contract ends early, run the same checklist the same day.
If an outside IT company does the work, get written confirmation that each account is disabled, then test it by trying to sign in yourself. A joint advisory from CISA, the FBI, the UK's NCSC and other agencies makes the same point about managed service providers themselves: disabling their accounts when a contract ends is commonly overlooked.[6] Our vendor access guide covers that side in more detail.
After the day: confirm and review
The credit union had asked for access to be removed. What was missing was a check that it had happened.[3] So finish every offboarding with proof: a signed checklist with names and times, and a test login that fails.
Then, every quarter, pull the user list from email, remote access, banking and your main business apps, and compare it with your current staff and contractors. Anyone who is gone, or who no longer needs access, comes off. This review also catches old accounts nobody remembers. Colonial Pipeline was shut down through an old remote-access profile that was no longer supposed to be in use; see the Colonial Pipeline case.
Your same-day offboarding checklist
- An access list exists for every role. Written before anyone leaves, updated when access is added.
- Remote access is cut first. During the termination meeting, or by the end of the last day.
- Accounts are disabled, not deleted. Sessions are signed out on every device.
- Money access is removed. Bank, payroll and cards, with the bank told about signers.
- Every shared password the person knew is changed. The new ones are shared through a channel they cannot see.
- Contractor accounts have end dates. Set when the account is created.
- Your IT provider confirms in writing. And you test the login yourself.
- A quarterly user review happens. Compare every key system's user list with your staff list.
Common questions
Should I delete a former employee's email account?
Usually not right away. Disable it so nobody can sign in, and keep the mailbox and files for as long as your records rules require. Health, legal, tax and financial offices often have retention duties. Forward new mail to a colleague, and delete the account only when you are sure nothing in it is still needed.
What if the person is leaving on good terms?
Do the same checklist anyway. Two of the three cases above involved people who left on their own. Same-day offboarding is not about trust; it is about making sure no account outlives its owner, which also protects the person leaving if their old password later turns up in a data leak.
How fast is fast enough?
For a firing, access should be off before or during the conversation. For a planned departure, by the end of the last working day. Longer gaps are how the cases above happened. If you use an outside IT provider, agree on this timeline in writing so it does not depend on someone reading an email.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How to verify callers before password resets, and protect your phone number from SIM swaps
- How a small business keeps software and devices patched, and why default passwords must go
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- Which two-step login actually stops phishing, and how a small office rolls it out
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- U.S. Attorney's Office, Eastern District of New York: Brooklyn woman pleads guilty to unauthorized intrusion into credit union's computer system
- FTC: Start with Security: A Guide for Business
- The Register: Fired credit union employee deletes 21GB of data
- U.S. Attorney's Office, Northern District of California: San Jose man sentenced to two years imprisonment for damaging Cisco's network
- U.S. Department of Justice: Tennessee man sentenced for unauthorized access of former employer's networks
- CISA, FBI, NSA, NCSC-UK and partners: Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)