top of page

The Offboarding Gap: Why Every Employee Departure Is a Security Risk Event Your Firm Is Probably Mishandling

  • May 27
  • 6 min read

Someone on your team gave notice this morning. By Friday they will be gone. You will wish them well, collect their laptop, and move on. Unless Roark is your MSP, you will most likely forget to revoke every credential, deauthorize every device, close every application account, remove every shared inbox permission, and audit every file they touched in the last thirty days before their access window closes.


That gap between what firms intend to do when an employee leaves and what they actually do is one of the most consistently exploited vulnerabilities in the small business security landscape.


It does not make headlines the way ransomware does. It does not arrive with a ransom note or a breach notification. It shows up weeks or months later, when someone who no longer works for your firm still has access to systems, files, and data they have absolutely no business touching.


THE SCOPE OF THE PROBLEM

Employee offboarding is not a new concern, but the modern technology environment has made it dramatically more complex and dramatically more consequential than it was a decade ago. A staff member who joined your firm three years ago has accumulated access across a range of systems that would surprise most managing partners if they saw it written down in one place.

They have a Microsoft 365 account with access to shared inboxes, SharePoint sites, OneDrive folders, and Teams channels. They have credentials for your practice management or matter management system. They have access to your client portal. They are enrolled in your multi-factor authentication system with a registered personal device. They may have access to your accounting software, your HR platform, your payroll system, your document management environment, and a collection of SaaS applications that were provisioned over time without formal tracking. They may have administrative rights to systems that nobody remembers granting them.


When that person leaves, every one of those access points represents an open door. The door may never be used. Or it may be walked through the week after their departure, the month after, or the year after, by someone who is no longer subject to your firm's policies, no longer motivated to protect your clients, and no longer accountable for what they do with what they find


WHY FIRMS GET THIS WRONG

The offboarding failure in most small professional firms is not malicious neglect. It is the absence of a system. When someone leaves, the firm is typically focused on the operational transition: reassigning matters, notifying clients, redistributing workload. The technology side of the departure is treated as an afterthought, managed informally by whoever happens to think of it, and rarely completed in full.


The result is predictable. The Microsoft 365 account gets disabled. The laptop gets collected. And a dozen other access points remain open indefinitely because nobody has a complete list of what needs to be revoked, nobody owns the process, and nobody checks whether it was done.


The problem compounds in firms that rely heavily on SaaS applications, because SaaS provisioning is typically decentralized. Individual staff members or department heads sign up for tools independently, provision access to colleagues informally, and never report those accounts to IT. When the colleague leaves, the account lives on in a system that the firm does not formally track and may not even know exists.


WHAT THE THREAT ACTUALLY LOOKS LIKE

The insider threat that offboarding failures create takes several forms, and not all of them involve malicious intent.


  • The most benign scenario is accidental access. A former employee continues to receive client emails through a shared inbox they were never removed from. They see confidential information they have no right to see. Whether they act on it or not, your firm has a data governance failure with potential regulatory and professional responsibility implications.


  • The more serious scenario involves deliberate access. A departing employee, anticipating their departure or acting after the fact, downloads client lists, matter files, financial records, or proprietary business information before their access is revoked. For a law firm, that’s a potential breach of attorney-client privilege. For a financial advisory firm, it is a potential regulatory event. For a medical practice, it is a potential HIPAA violation. For an accounting firm, it is a potential exposure of client financial data that carries its own notification and liability obligations.


  • The most serious scenario involves a former employee whose credentials are compromised after their departure. Their account, still active in your environment, becomes the entry point for an external attacker who found those credentials in a breach database, purchased them on the dark web, or obtained them through a phishing attack targeting the former employee's personal email. The attacker logs in with legitimate credentials, moves through your environment without triggering anomaly detection, and operates undetected for weeks.


All three scenarios share a common root cause: access that was not revoked when it should have been.


WHAT A PROPER OFFBOARDING PROTOCOL COVERS

A complete technology offboarding protocol for a professional firm addresses several distinct categories of access, and it does so in a defined sequence with documented verification at each step.


Identity and authentication revocation comes first and must happen immediately, ideally before the departing employee's last day ends. Microsoft 365 account suspension, MFA device deregistration, and password resets for any shared credentials the employee had access to are non-negotiable first steps.


Application access revocation follows, and this is where most informal offboarding processes fail. Every application the departing employee accessed must be identified, and their access must be individually revoked. This requires a current, maintained application inventory. Firms without one discover its absence most painfully during this step.


Device management covers not just the return of firm-owned hardware but the removal of firm data and credentials from any personal device the employee used for work purposes. Mobile device management enrollment must be terminated and remote wipe capability exercised where appropriate.


Data access audit examines what the departing employee accessed, downloaded, or modified in the period leading up to their departure. For regulated firms, this audit is not optional. It is the difference between knowing your data is intact and hoping it is.


Email and communication management addresses shared inbox access, forwarding rules, and calendar permissions that persist after an account is nominally disabled.


Finally, access reviews for any systems where the departing employee held administrative or elevated privileges deserve particular attention. Administrative access does not simply disappear when an account is suspended if that access was granted at the application level rather than the directory level.


HOW ROARK ADDRESSES THIS FOR CLIENTS

Roark clients do not manage this process informally. Every Roark engagement includes a defined offboarding protocol that covers identity revocation, application access termination, device management, and data access auditing as a structured, documented process.


When a Roark client loses a staff member, the technology side of that departure executes from a playbook, not from memory. Every access point is identified, every revocation is verified, and every step is documented. The open door does not stay open because nobody thought to close it.


For firms without that structure in place, the gap between what they believe happens when an employee leaves and what actually happens is almost always wider than they expect. Discovering that gap after an incident is the most expensive way to close it.


THE EXECUTIVE TAKEAWAY

Every employee departure is a security event. Most firms treat it as an HR event with a technology footnote. The difference between those two postures is not theoretical. It is the difference between a clean transition and an access gap that sits open for months, waiting to become a problem your firm did not anticipate and cannot easily explain.


The protocol that closes this gap is not complicated. It requires a complete application inventory, a defined revocation sequence, documented verification, and ownership by someone who is accountable for completing every step. What it does not tolerate is informality, assumption, or the belief that collecting the laptop was sufficient.


It was not sufficient three years ago. In the current threat environment, it is not even close.

Since 1998, Roark Tech Services has delivered tailored, risk-managed IT solutions for small and mid-sized businesses in finance, legal, healthcare, and other regulated industries.


Our philosophy is simple: your business should own its IT infrastructure, its data, and its destiny. We are here to make sure that ownership is secure, resilient, and working for you every day of the year.


bottom of page