When an employee leaves: what to arrange digitally
When someone leaves, their accounts, passwords and sharing links often keep working longer than you think. A practical checklist to close them off properly.
By Limburg Cyber Group
A colleague is leaving. The farewell cake has been eaten, the laptop is in the cupboard, and that seems to be that. But often the password still works months later, the business email is still on a personal phone, and the shared folder with client files can still be reached. Usually there is no bad intent, but an account nobody uses any more is also an account nobody notices when it is misused. With a fixed routine, you can sort it out quickly.
1. Block accounts, do not delete them straight away
Block the account at the agreed moment, usually at the end of the last working day. Do not delete it yet, because mail and files could be lost. Watch out for two things:
- End active sessions too. A new password does not always sign out devices that are already logged in. Most admin environments let you revoke all sessions in one go.
- Do not forget the separate services: accounting package, client system, scheduling software, social media and the website. These are often separate accounts outside your central management.
2. Shared passwords and MFA
Did the employee know passwords for shared accounts, such as the Wi-Fi, a supplier portal or the company’s social media profile? Change them. With a business password manager you revoke access to shared vaults in one go, and you can see which passwords they had access to.
Also remove the MFA methods from the account, such as the linked authenticator app, and collect any hardware keys. Did two-factor authentication for a shared account run through their phone? Move it to a colleague.
3. Laptop and phone
Collect company devices, check whether they still hold files you need, and wipe them before handing them out again. Did the employee use their own phone with business apps? With mobile device management (MDM, software that lets you manage business devices remotely) you can often wipe only the business data and leave the rest alone. Without such a system, ask the employee to remove the business apps and accounts, and remove the device from the list of linked devices.
4. Mailbox and forwarding
Clients will keep emailing the old address. Common solutions are an automatic reply that points to a colleague, or giving a colleague temporary access to the mailbox. Many mail platforms can convert a personal mailbox into a shared mailbox.
Also check whether any forwarding rules are active, for example to a personal address. Otherwise they quietly keep working. And bear in mind that a former employee’s mailbox contains personal data: look only at what is needed for the work, and agree how long you will keep it.
5. Files and sharing links
In cloud services such as OneDrive or Google Drive, files are often owned by the employee’s account. If you delete the account, those files may disappear with it. Transfer ownership first to a colleague. Also look at sharing links sent to outside parties: a link that is open to anyone who has it keeps working for as long as the file exists.
6. Bank, government and suppliers
This is the part most often forgotten. Withdraw authorisations at the business bank, remove the employee from supplier and wholesaler portals, and check authorisations to log in to government services on behalf of the company, such as eHerkenning, the Dutch business login. Do they have a company credit card or fuel card? Have it blocked.
Build it into your HR process
A checklist only works if someone uses it. Link it to the moment the leaving date is known, not just the last day, and make one person responsible. Use a fixed list for new starters too: give access only to what the job requires (the principle of least privilege) and record what you have given. Then, when someone leaves, you know exactly what to revoke. These agreements belong in your IT policy.
Help with your checklist?
We can work with you to draw up a joiners and leavers checklist that fits the systems you actually use. See our cybersecurity service or book a conversation.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.