The quiet exits are the risky ones
When people picture insider risk, they picture a furious ex-employee doing sabotage. That happens, but it is rare. What I actually see is quieter: an ex-employee whose email still works six months later, a shared Instagram password nobody changed, a personal phone still syncing the company inbox.
Most of the damage from these gaps is accidental. Old accounts get compromised because nobody is watching them, forwarded email exposes customer conversations, and a vendor portal login floats around in a former employee's password manager. The fix is not suspicion. It is a 30-minute routine you run the day anyone leaves, on good terms or bad.
The first 30 minutes: email and core accounts
Do these the same day, and within the hour for an involuntary exit.
- Disable their email sign-in. Do not delete the mailbox, because you will need the history. Disabling blocks access while keeping everything.
- Set their email to forward to a manager, and add an auto-reply pointing customers to the right person, so nothing from clients falls into a void.
- Sign them out everywhere. Most business email systems have a revoke sessions option that kicks all logged-in phones and laptops off at once. Use it, because disabling a password does not always end sessions that are already open.
- Disable their sign-in on your other core systems: scheduling, payroll, POS, project tools, and cloud file storage.
Shared passwords: the gap everyone forgets
Individual accounts are easy because you disable them once. Shared passwords are the leak that keeps leaking, because the person who left still knows them.
Make a list of everything the business shares a login for. In a typical small business that means social media accounts, the website admin, the bank or bookkeeping portal, supplier and vendor sites, the wifi password, and whatever PIN unlocks the register tablet. Rotate every one the departed person knew.
If that sounds exhausting, that is the argument for a password manager, a tool that stores logins in a shared vault and lets you change and re-share them in minutes. Business plans generally run a few dollars per user per month, and they turn this step from an afternoon into ten minutes.
Devices, door codes, and the physical list
Collect company laptops and phones before the goodbye handshake, and check them off a written inventory rather than memory.
Personal phones matter just as much. If the person read company email on their own phone, remove the account from the device, or use your email system's option to remotely remove company data, which wipes business email and files without touching personal photos.
Then the analog items: keys, alarm codes, door codes, and access to the security system app. Door codes are shared passwords in disguise; if the departed person knew the code, the code changes today. Same for the alarm company's verification word if they were on the authorized caller list.
Write the checklist while nobody is quitting
The reason offboarding fails is that it runs from memory on an emotional day. The fix costs one hour on a calm afternoon.
Write down every system with a login, every shared password, every device, and every physical code your business has. That document is your offboarding checklist; departures become a matter of walking the list. Keep it current by adding every new tool on the day you adopt it.
Run a lighter version for contractors and agencies too. The web freelancer from two years ago may still have your hosting login, and the marketing agency you dropped may still be an admin on your ad accounts. Third parties linger even longer than employees, because no exit interview reminds you they exist.
Next steps
- Run the checklist retroactively this week for the last two or three people who left. In my experience you will find at least one live account.
- Write your master list of systems, shared passwords, devices, and codes.
- Put a password manager in place so rotating shared logins takes minutes, not hours.
- Name one person who owns offboarding, and staple the checklist to your exit paperwork so it happens automatically every time.
Security work like this is unglamorous, and it is also the cheapest protection you can buy: the whole routine costs 30 minutes per departure and closes the door most small-business incidents walk through.
