Onboarding and offboarding get treated as HR checklist items. The IT side of that process, provisioning and revoking access, is actually one of the most commonly overlooked security gaps in small business, and the data on how often it goes wrong is worse than most owners assume.
The Access That Never Actually Gets Revoked
One study found 89% of employees were able to access sensitive corporate applications well after their departure, and 83% of former employees actually did continue accessing accounts at a previous employer. Separately, 63% of businesses may currently have former employees retaining some access to organizational data without anyone realizing it. That’s not a rare edge case — it’s closer to the default outcome when there’s no formal process.
Why This Keeps Happening
Only 29% of organizations have a formal, documented offboarding process, which means the majority are relying on memory and ad hoc effort to revoke access every time someone leaves. This gap is exactly where breaches involving former employees originate — not from sophisticated attacks, but from an account nobody remembered to disable.
The Risk Window Starts Before Someone Even Resigns
Roughly 70% of intellectual property theft occurs within the 90 days before an employee’s resignation is even announced, meaning the risk window often starts before a business knows someone is leaving at all. This is part of why access monitoring and least-privilege principles matter continuously, not just at the moment of departure.
What a Complete Offboarding Checklist Actually Includes
At minimum: disabling email and single sign-on access, revoking access to every cloud application and SaaS tool the employee used, not just the obvious ones, retrieving or remotely wiping company devices, removing the employee from any shared accounts or distribution lists, and transferring ownership of any files or accounts they controlled. IT professionals report that identifying and deprovisioning all cloud and SaaS accounts alone often takes several hours per employee — a step that’s easy to shortcut when everyone’s rushed on someone’s last day.
What Poor Offboarding Actually Costs
Real incidents have resulted from exactly this gap. In one documented case, a former employee’s retained access at a financial institution led to the exposure of customer data for nearly 700,000 individuals. More broadly, nearly one-third of employers have experienced a security incident tied specifically to ineffective offboarding, and Verizon’s Data Breach Investigations Report found that over 22% of breaches involve insiders, with access mismanagement as a recurring root cause.
Good Onboarding Makes Offboarding Easier
Provisioning access correctly from the start, granting only what a role actually requires rather than broad access “to be safe,” makes offboarding faster and more complete later, since there’s a clear, documented picture of exactly what a departing employee had access to. Onboarding and offboarding are really two ends of the same access-lifecycle process, not separate problems that happen to share a name.
It’s Not Just Full-Time Employees
This applies at least as much to contractors, seasonal staff, and volunteers, who are often granted access quickly to get them productive fast and then forgotten about once their engagement ends — exactly the kind of access most likely to go unnoticed. Nonprofits and businesses with seasonal staffing patterns face this risk especially acutely; see our nonprofit and accounting guides for how this shows up in practice.
How CelereTech Helps
CelereTech maintains a documented access inventory for every client and follows a consistent onboarding and offboarding checklist covering every system and account a role touches, so access is provisioned correctly on day one and fully revoked the moment an employee, contractor, or volunteer departs.
Get your access management gaps assessed before they turn into an incident.