CybersecurityMay 26, 2026Serdar YAMAN5 min read

Scenario Analysis: What Happens When a Departed Employee's Accounts Stay Open?

Scenario Analysis: What Happens When a Departed Employee's Accounts Stay Open?

TL;DR: Closing accounts on departure is not an HR courtesy step but a security operation: email, VPN, CRM, cloud files, SaaS subscriptions and shared passwords belong on one list, handled the same day. In this representative case, a single account left open for three months returned as a data-leak suspicion, legal proceedings and customer-trust repair. The lasting fix is a written offboarding checklist triggered by HR, plus an access inventory.

This account is a composite, anonymised blend of cases we have met repeatedly in the field.

At a twenty-five-person distribution firm, a sales representative leaves in early March; the parting is civil, the paperwork complete, the laptop returned. In the second week of June, a long-standing customer's purchasing manager says something odd: "Your former rep called from his new company — he had our entire purchase list from last year." The same week, the CRM's sign-in logs are checked — the departed rep's account has logged in seventeen times in three months. Most recently, two days ago.

Discovery: Not One Account — a Missing Arrangement

The first anxious review shows the picture is bigger than one account:

  • The CRM account was never closed — because the CRM was a SaaS subscription the sales manager had "set up himself"; IT's leaver list never contained it.
  • The email account was closed, but the corporate mail profile on the personal phone was not; in the three days before closure, the mailbox kept syncing.
  • The shared "sales@" account password was known to him, like everyone else — and was never rotated after he left.
  • In the file-sharing app, a never-expiring share link to the folder of customer price lists was still active.

So the question is not "who forgot this account?" but "which arrangement would have caught it?" — and there is no answer, because two foundation stones are missing: an access inventory (who can reach what) and a written offboarding checklist (what closes on departure).

Cleanup Week: the Retroactive Cost

The following week is a textbook on how cheap prevention is: accounts are swept across every system (and two former interns' active accounts surface), all shared passwords rotate, non-expiring share links close, SaaS subscriptions are consolidated onto a single list through a shadow-IT sweep. On the legal side, the matter proceeds with counsel and its possible data-protection dimension — customer data carried off by a former employee runs on two tracks, trade secrets and personal data, and the evidence for both is the sign-in logs being assembled that week. The good news: the CRM kept logs. The bad news: nobody had looked at them for three months.

The Lasting Fix: an Arrangement That Closes Same-Day

PieceContentWhat it would have prevented here
Access inventoryA person × system matrix: email, VPN, CRM, files, SaaS, physical access"Where did he have accounts?" taking three months to answer
Offboarding checklistWritten steps triggered by HR, closed by IT the same dayThe CRM missing from the list
Shared-account disciplineShared passwords in a vault, auto-rotated on departureThe sales@ password living on outside

The checklist's core: close the central identity account (how much one closure switches off is the maturity measure of your identity management), close or transfer SaaS accounts one by one, define mail forwarding and delegation, collect devices and MFA keys, remotely remove corporate profiles from personal devices, rotate shared passwords, strike the person from the access inventory.

Four Points That Usually Slip Through

  • The corporate profile on the personal phone: even with the account closed, cached data remains on the device; mobile device management (MDM) must be able to remove the corporate profile remotely.
  • Never-expiring share links: "anyone with the link" shares are not bound to a person; they do not close on departure. Make time-limited sharing the default.
  • Contact details saved by customers: the departed rep's mobile number lives in the customer's phone book as "your company". A handover email and a new-contact notice are the offboarding of customer ownership, if not of security.
  • Critical single-person access (domain, hosting): admin access bound to one person breeds crises on departure; critical accounts always run the second-administrator rule.

Onboarding's Mirror Twin

The elegant side of the arrangement: once the access inventory exists, joining speeds up too — a new hire receives the standard access set for their role within minutes, and on departure the same list closes in reverse. The investment does not just shut a risk; it saves time at every entry and exit.

How Yamanlar Bilişim Builds This

For customers under a maintenance agreement, the access inventory is drawn up at onboarding, and offboarding is a service step triggered by a single notice from HR: accounts close the same day, shared passwords rotate, a report goes to management. Where a departure is contentious, closure is scheduled before the notification — security precedes courtesy.

FAQ

Frequently Asked Questions

Should we delete a departed employee's email immediately?

Not delete — close immediately: the account is blocked from access, the mailbox stays available to a delegate or forwarding for a period (for work in flight), and it is archived at the end of the retention policy. Deletion is the last step, for both business continuity and possible legal needs.

We are a small team and everyone can reach everything — what does an inventory solve?

The "everyone everything" arrangement is itself the finding: everyone who leaves takes everything. The inventory makes that visible in step one; step two is narrowing access to roles at least on critical systems (finance, customer data). A small team means a short list — a convenience, not an excuse.

What can we possibly do if a former employee remembers passwords?

Exactly why the leaver list does not end with "close their account" — it continues with "rotate the shared passwords they knew". Personal accounts are protected by MFA, shared accounts by rotation; remembering is rendered useless.

Is routinely reviewing logs a privacy problem?

Security-purpose monitoring of access records, proportionate and disclosed, is a legitimate security measure; it belongs in the employee privacy notice and stays purpose-bound. The problem is not monitoring — it is covert, boundless monitoring. Put the framework in writing in your personnel policy.

How does the sequence change in a contentious departure?

Only the timing: access closure happens before or simultaneously with the termination meeting; the device is collected in the meeting room. The rest of the list is identical — the arrangement's value is that even on a tense day, nobody has to wonder "what were we supposed to close?"

Share:
SY

Author

Serdar YAMAN

Yamanlar Bilişim Expert

Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.

Professional Support

Get help on this topic

Let's design the Cybersecurity solution you need together. Our experts get back to you within 1 business day.

support@yamanlarbilisim.com · Response time: 1 business day