Sicc Media // Break the Mold \\ DARE TO BE EXTRAORDINARY.

Tag: Offboarding Security

  • Building an Automated Off-Boarding Security Protocol

    Building an Automated Off-Boarding Security Protocol

    Most small businesses have former staff with live access to something. Usually nobody has checked, and usually nothing happens, and occasionally something does.

    TL;DR Maintain an access register per role. Revoke everything the same day, not the same week. Rotate any shared credential the person knew. Recover assets against a checklist and record what came back.

    The access register

    You cannot revoke what you have not recorded.

    Build a register listing every system, per role

    System Who has it Revocation method
    Email All Admin console
    Field service app Field, office Admin console
    Accounting Office, owner Admin console
    Payment processor Office, owner Admin console
    Google Business Profile Marketing, owner Often forgotten
    Social accounts Marketing, owner Often forgotten
    Domain registrar Owner Frequently a single point of failure
    Password manager All Vault removal, then rotation
    Supplier trade accounts Field, office Phone the supplier
    Vehicle tracking Managers Admin console
    Building alarm and key safe Varies Physical, needs recoding
    Customer site keys Field Physical recovery

    The bottom half of that list is where the gaps are. Software access gets revoked because it is visible in an admin panel. Supplier accounts, alarm codes and physical keys do not appear anywhere and are routinely missed.

    Audit the register twice a year against reality. Access accumulates.

    Same-day revocation

    The window between notice and revocation is the risk.

    For a normal resignation: revoke on the final day, at the end of it.

    For a dismissal or an acrimonious exit: revoke before or during the conversation. This is not paranoia, it is standard practice, and it protects both parties from an accusation later.

    Sequence

    1. Disable, do not delete. Deletion loses records you may need.
    2. Forward email to a manager for a defined period.
    3. Reassign owned records: customers, open jobs, open conversations.
    4. Remove from all shared systems.
    5. Rotate shared credentials.
    6. Recover physical assets.
    7. Recode physical access.
    8. Confirm each step, with a date and a name against it.

    Automate the trigger. Marking somebody as leaving in your HR or payroll system should generate the full checklist as tasks, with owners and due dates.

    Rotate what they knew

    Revoking an individual account is not enough if there were shared credentials.

    Rotate

    • Any shared account password, always.
    • The Wi-Fi key, if it was shared.
    • Alarm codes and key safe codes.
    • Supplier account passwords.
    • Any API key they had access to.
    • Shared social account passwords, and remove them as an admin.

    Shared credentials are the underlying problem here. Every rotation is disruptive precisely because the account is shared.

    The better long-term fix: individual accounts everywhere, a password manager for anything genuinely shared, and no credential passed around in a message. Then offboarding is a removal, not a rotation.

    Asset recovery

    A checklist, signed by both sides.

    Typical list

    • Phone and charger.
    • Tablet or laptop.
    • Van and all keys.
    • Tools, itemised against what was issued.
    • Test equipment, with serial numbers.
    • Uniform and PPE.
    • Customer site keys and fobs.
    • Fuel card.
    • Building keys and access cards.
    • Any physical files or documents.

    Record condition and serial numbers. For test equipment particularly, because calibration records attach to serial numbers.

    Sign it, both parties, and give them a copy. This protects them as much as you, and it prevents the disagreement three months later about whether a tool came back.

    Deductions from final pay for unreturned items are regulated in most jurisdictions and often require prior written agreement. Check before assuming you can.

    Data on personal devices

    The awkward one, and increasingly common.

    If staff used personal phones for work

    • Customer contacts saved in the phone.
    • Work email in a personal mail app.
    • Work messaging apps with customer conversations.
    • Photos of jobs and sites.

    Ask for confirmation of deletion, in writing. That is usually as far as you can reasonably go without a prior policy.

    The fix is upstream. A bring-your-own-device policy signed at onboarding, stating what may be stored and what happens at exit, and preferably containerised work apps that can be remotely removed.

    If you have no policy, write one now and apply it to new starters. Retrofitting it to existing staff requires a conversation and probably consent.

    Customer notification

    For customer-facing staff, tell the customers.

    Just to let you know, Dave has moved on. Sarah will be looking after you from now on. Her number is below, and she has your full history so nothing is lost.

    Why it matters

    • Prevents customers ringing a number that no longer reaches you.
    • Prevents a departing employee taking accounts by default.
    • Reassures customers that continuity is handled.

    Do it promptly and neutrally. No commentary on why they left.

    If they have gone to a competitor, check your contracts on solicitation. Enforceability of non-solicitation clauses varies enormously by jurisdiction and many are unenforceable as drafted. Take advice before acting on one.

    The exit conversation

    Separate from the security process, and worth doing.

    • What worked and what did not.
    • Why they are leaving, actually.
    • What would have kept them.
    • Any knowledge only they hold, captured before the last day.

    The last point is operational, not sentimental. Every departure is a knowledge loss and the fortnight before the last day is your only chance to record it.

    Measure it

    • Time from last day to full revocation. Should be zero days.
    • Checklist completion rate. Every item, every time.
    • Access audit findings. Former staff with live access should be zero, and audit for it twice a year.
    • Asset recovery rate.
    • Knowledge capture completed before the last day.

    Build the access register this week, listing every system and who has it. Most owners find at least one former employee still holding access to something, and that discovery alone justifies the hour.

    Need a pro to build it? [BOOK A CALL]