Guide · Offboarding

Employee offboarding checklist: how to cut off a former employee's access the same day

Published 2026-09-29 · 6 min read

Two days after a New York credit union fired a part-time employee, she logged back in from home and deleted more than 20,000 files, because her remote access still worked.[1] This guide shows how to shut off a departing employee's or contractor's access on their last day, in the right order, with a checklist a small office can actually follow.

Why same-day offboarding matters

Offboarding is the set of steps you take when someone leaves: collecting equipment, closing accounts and changing anything they knew. Most small offices do some of it. The trouble is the gaps between "some" and "all," and the days between the last day and the day someone gets around to it.

The Federal Trade Commission uses exactly this failure as a lesson in its guide for businesses. In one enforcement case it describes, a company shared a master cloud login among employees and outside contractors and did not change it when a contractor left. The former contractor later used it to take personal information on about 40 million users.[2] Nobody had to break in. The door was simply never locked behind them.

Most people who leave never do anything wrong. Same-day offboarding is not an accusation. It is the same kind of routine as returning the office keys, and it protects the person leaving as well, because nothing can later be blamed on an account that was closed.

Three cases, one missing step

The credit union. Juliana Barile was fired on May 19, 2021. On May 21 she connected remotely and, in about 40 minutes, deleted over 20,000 files and about 3,500 directories, roughly 21.3 gigabytes, including mortgage loan applications and the folder holding the credit union's anti-ransomware software. Cleanup cost about $10,000. She pleaded guilty to computer intrusion.[1] Court papers described a request to the outside IT firm to disable her access that was never carried out.[3] Our case file on the fired employee's 40 minutes covers the details.

The cloud engineer. Sudhish Kasaba Ramesh resigned from Cisco in April 2018. In September 2018 he got into the company's cloud environment and deployed code that deleted 456 virtual machines running its Webex Teams app. More than 16,000 accounts were shut down for up to 2 weeks, and Cisco spent about $1.4 million on restoration and more than $1 million on customer refunds. He pleaded guilty and was sentenced to 24 months in prison.[4] See the Cisco Webex deletion.

The competitor. An engineer who left a Tennessee engineering firm to co-own a rival kept reading a former colleague's mailbox for nearly 2 years, and used it to pick up new passwords for the firm's document system each time they were changed. He pleaded guilty and was sentenced to 18 months in prison.[5] Read how a shared mailbox kept the door open.

Different people, different motives, the same gap: access that should have ended on the last day did not.

Before anyone leaves: build the access list

You cannot close what you do not know about. The single most useful thing an office manager can do is keep a simple access list for every role, before anyone resigns. For each person, write down:

Where you can, have staff sign in to business apps with their company email account (often called single sign-on). Then disabling one account closes most doors at once.

The last day: the order that works

For a planned departure, do this on the last afternoon. For a firing, do it during the meeting, not after. The credit union case shows what 2 days can cost.

Contractors, temps and IT providers

Contractors are where offboarding most often slips, because there is no HR exit meeting. Put an end date on every contractor account when you create it, so it switches itself off. When a contract ends early, run the same checklist the same day.

If an outside IT company does the work, get written confirmation that each account is disabled, then test it by trying to sign in yourself. A joint advisory from CISA, the FBI, the UK's NCSC and other agencies makes the same point about managed service providers themselves: disabling their accounts when a contract ends is commonly overlooked.[6] Our vendor access guide covers that side in more detail.

After the day: confirm and review

The credit union had asked for access to be removed. What was missing was a check that it had happened.[3] So finish every offboarding with proof: a signed checklist with names and times, and a test login that fails.

Then, every quarter, pull the user list from email, remote access, banking and your main business apps, and compare it with your current staff and contractors. Anyone who is gone, or who no longer needs access, comes off. This review also catches old accounts nobody remembers. Colonial Pipeline was shut down through an old remote-access profile that was no longer supposed to be in use; see the Colonial Pipeline case.

Your same-day offboarding checklist

Common questions

Should I delete a former employee's email account?

Usually not right away. Disable it so nobody can sign in, and keep the mailbox and files for as long as your records rules require. Health, legal, tax and financial offices often have retention duties. Forward new mail to a colleague, and delete the account only when you are sure nothing in it is still needed.

What if the person is leaving on good terms?

Do the same checklist anyway. Two of the three cases above involved people who left on their own. Same-day offboarding is not about trust; it is about making sure no account outlives its owner, which also protects the person leaving if their old password later turns up in a data leak.

How fast is fast enough?

For a firing, access should be off before or during the conversation. For a planned departure, by the end of the last working day. Longer gaps are how the cases above happened. If you use an outside IT provider, agree on this timeline in writing so it does not depend on someone reading an email.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. U.S. Attorney's Office, Eastern District of New York: Brooklyn woman pleads guilty to unauthorized intrusion into credit union's computer system
  2. FTC: Start with Security: A Guide for Business
  3. The Register: Fired credit union employee deletes 21GB of data
  4. U.S. Attorney's Office, Northern District of California: San Jose man sentenced to two years imprisonment for damaging Cisco's network
  5. U.S. Department of Justice: Tennessee man sentenced for unauthorized access of former employer's networks
  6. CISA, FBI, NSA, NCSC-UK and partners: Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)