Back to Catalog

The Small Business IT Offboarding Checklist: Protecting Your Data When Employees Leave

Hand holding out a set of keys

When an employee departs your business—whether amicably or unexpectedly—most management teams focus on final paychecks, returning keycards, and delegating active customer files. Too often, technology offboarding is treated as an afterthought. Days or weeks pass before someone remembers to shut down email accounts, revoke cloud access, or wipe corporate files from a personal phone.

Forgotten accounts create dangerous blind spots. Dormant logins are prime targets for automated credential stuffing attacks, and former staff may retain access to confidential pricing records, trade secrets, or patient charts long after departure. The NIST Special Publication 800-53 security controls (PDF) specifically mandate prompt account termination and credential revocation to prevent unauthorized data exfiltration.

"A company account without an active owner is an open back door into your business. Systematic offboarding must happen before departing staff leave the building."

Phase 1: Immediate Identity & Cloud Revocation

Within the first hour of employee departure, coordinate these fundamental identity safeguards:

  • Terminate Central Directory Sessions: Immediately revoke active Microsoft 365, Google Workspace, or domain sessions. Changing the password alone is insufficient; you must force-terminate all active browser tokens and mobile OAuth grants.
  • Revoke Multi-Factor Authentication Devices: Unbind the employee's personal mobile phone from your corporate two-step login portal so they cannot approve push notifications or generate authenticator codes.
  • Convert Email to a Shared Mailbox: Do not immediately delete the user mailbox. Convert it into a read-only shared mailbox routed to their supervisor. This preserves audit trails and ensures incoming customer inquiries are never lost.

Phase 2: Hardware Retrieval and Drive Cleansing

Physical devices pose equal risk. If departing employees take work laptops home or sync work folders to personal machines:

  • Collect All Physical Hardware: Retrieve laptops, tablets, company smartphones, and external backup drives before conducting the exit interview.
  • Execute Remote Wipe on Mobile Devices: If you allow employees to check email on personal smartphones (BYOD), use your centralized mobile device manager to execute an enterprise wipe. This deletes corporate databases and mail sync folders without erasing personal family photos.
  • Reimage Before Reassignment: Never hand a former employee's laptop directly to a replacement hire. Always sanitize the drive, reinstall a clean operating system, and apply fresh device encryption keys.

Phase 3: Audit Shared Credentials & Third-Party Portals

Many offices share logins for social media, shipping accounts, web hosting, or vendor portals. Whenever a team member leaves, audit your corporate password manager and rotate all shared credentials. Adhering to baseline CISA Insider Threat Mitigation guidance (PDF) by maintaining unique passwords per user eliminates shared administrative vulnerabilities.

Protect Your Operations from Internal Exposure

Standardized checklists prevent costly oversights during stressful organizational transitions. Take our quick 60-second IT Health Quiz to identify security gaps in your account management workflows, or reach out to James Hatch to design automated user provisioning rules for your office.