What should happen when an employee leaves the company, security-wise?
Access to email, business applications, shared drives, and any accounts tied to that employee should be revoked the same day they leave, not at the next convenient opportunity. Any shared passwords they knew should be rotated, and their devices should be wiped or returned before final pay is processed.
Offboarding gets overlooked because it doesn't feel urgent in the moment — there's no fire to put out, so it's easy to deprioritize. But a former employee with lingering access is one of the most common, least dramatic ways businesses get breached, especially after a difficult departure. Most security assessments specifically check how fast access is actually revoked, not just whether a policy exists on paper.
See how your offboarding process scores in a free Cybersecurity Assessment.