23/07/2026
When an employee leaves your business, the security gap is usually bigger than you'd think.
A typical 25-person business has dozens of cloud accounts per employee: email, payroll, file storage, CRM, accounting, internal tools, and other SaaS subscriptions.
When someone leaves, every one of those accounts should be disabled. In most businesses, only the obvious ones get touched — email, computer login. The rest sit dormant for months or years, still active with that person's old credentials.
That's how someone who left 18 months ago becomes the entry point for next year's breach — and if any of that dormant access involves customer or employee personal data, it's also a Data Privacy Act exposure you don't want to explain to the NPC.
The fix: build IT offboarding into your existing clearance process, not as a separate afterthought.
𝗗𝗮𝘆 𝗼𝗳 𝗱𝗲𝗽𝗮𝗿𝘁𝘂𝗿𝗲: Disable email, computer login, VPN, and any single sign-on (SSO) account that gates everything else.
𝗪𝗶𝘁𝗵𝗶𝗻 𝟰𝟴 𝗵𝗼𝘂𝗿𝘀: Revoke access on every SaaS tool by checking the actual admin panel of each one — don't rely on memory.
𝗪𝗶𝘁𝗵𝗶𝗻 𝟳 𝗱𝗮𝘆𝘀: Change any shared credentials the employee knew (shared logins, Wi-Fi passwords, group accounts).
𝗪𝗶𝘁𝗵𝗶𝗻 𝟯𝟬 𝗱𝗮𝘆𝘀: Sign-off is only complete once IT confirms all system access is revoked — make this part of the clearance form itself, alongside HR and finance sign-off.
Without a checklist, "what did this person have access to?" becomes impossible to answer a few months later.