Here is something uncomfortable: over half of former employees say they still have access to accounts at a company they no longer work for. That is not a stat from 2018. That is from current research, and it lines up with what we see on the ground in Southwest Florida every month.
A dental practice in Fort Myers. A property management firm in Naples. A construction company with 30 employees. They all have something in common: when someone leaves, the offboarding process is a scramble. HR handles the exit interview and final paycheck. IT gets looped in late—or not at all. And somewhere in the gap, a former employee walks out the door with access to email, cloud storage, client data, and sometimes the keys to the entire network.
According to the Ponemon Institute’s 2025 insider threat research, 55% of insider security incidents stem from negligence—not malice. Nobody is trying to steal anything. The process just does not exist, or nobody owns it. For small businesses without a dedicated IT department, this is the norm, not the exception.
Why This Matters More in 2026
Two things have changed the math on offboarding risk:
- SaaS sprawl is real. The average small business now uses 40–80 cloud applications. Ten years ago, offboarding meant disabling an Active Directory account and collecting a laptop. Today, it means tracking down access across Microsoft 365, QuickBooks Online, Dropbox, Slack, HubSpot, your phone system, your security cameras, your project management tool, and a dozen other apps that individual employees signed up for without telling anyone.
- Cyber insurance underwriters are asking about it. If you have applied for or renewed a cyber insurance policy in 2026, you have probably noticed questions about access management and employee termination procedures. Carriers are increasingly denying claims when the breach traces back to a former employee whose access was never revoked. The logic is simple: that is a preventable loss.
Wing Security’s 2024 research found that 43% of businesses still have ex-employees with access to code repositories like GitHub or GitLab. And Kaspersky reports that nearly half of small and mid-sized businesses are not 100% sure that dismissed employees cannot still access corporate data through cloud services. These are not edge cases. This is the baseline.
The 10-Question IT Offboarding Audit
Print this out. Tape it to the wall in your office. Use it the next time someone gives notice—or the next time you have to let someone go. If you cannot answer “yes” to every question, you have a gap.
1. Do you have a single, written offboarding checklist that HR and IT both follow?
If the process lives in someone’s head, it is not a process. It does not need to be fancy—a shared Google Doc or a checklist in your project management tool works. What matters is that it exists, it is written down, and it gets used every single time.
2. Is IT notified before the employee’s last day?
This is the number one failure point we see. HR schedules the exit for Friday afternoon. IT finds out Monday morning. That gives a departing employee an entire weekend with full access to everything. Best practice: IT should know at least 24–48 hours in advance for a voluntary departure, and simultaneously for an involuntary termination.
3. Can you produce a complete list of every application and system the employee has access to?
Not “the ones you remember.” A complete list. This includes SaaS apps they signed up for with their work email, VPN credentials, remote desktop access, shared drives, security camera apps, door access codes, and Wi-Fi passwords. If you do not have a way to generate this list, you cannot fully offboard anyone. Period.
This is also where network segmentation and zero trust policies pay off—if a former employee’s credentials are compromised, the blast radius is contained.
4. Are all accounts disabled within one hour of the termination conversation?
Not one day. One hour. For involuntary terminations, account disabling should happen during the conversation. This means your IT provider or internal IT person needs to be standing by. Research shows that only 44% of companies revoke all access within 24 hours. One hour should be the target.
5. Do you have a process for shared credentials?
This is the one that catches small businesses off guard. That social media login everyone shares. The vendor portal with one password for the whole office. The alarm code. The shipping account. If a departing employee knew any shared passwords, every one of those passwords needs to change on their last day. A password manager makes this manageable. Without one, it is a nightmare.
6. Do you collect all company-owned devices and wipe personal devices used for work?
Laptops and phones are obvious. But what about the employee who checked email on their personal iPad? Or the sales rep who had your CRM app on their personal phone? If you have a mobile device management (MDM) policy, you can remotely wipe company data from personal devices. If you do not have MDM, you are relying on trust—and trust is not a security control.
7. Are email forwarding rules and auto-replies reviewed before disabling the account?
A common trick—sometimes malicious, sometimes just careless—is setting up an email forwarding rule to a personal address before leaving. Check the departing employee’s mailbox for forwarding rules, delegates, and any auto-replies that might direct clients to a personal email or competing business.
8. Do you have a plan for the employee’s data and email after they leave?
Deleting the account immediately can mean losing client correspondence, project files, and institutional knowledge. Best practice: convert the mailbox to a shared mailbox (free in Microsoft 365), assign a manager as the owner, and keep it active for 90–180 days. Back up their OneDrive or Google Drive to a company-owned location. Then delete.
9. Are physical access controls updated?
Key fobs, door codes, alarm PINs, server room access, parking garage remotes. If your office in Cape Coral uses a four-digit door code and it has been the same code for three years, every former employee from the last three years still has physical access to your building. Change it.
10. Do you review and document the offboarding within one week?
After the dust settles, someone should verify: every account is confirmed disabled, all devices are accounted for, shared passwords are changed, and the whole thing is documented. This is your proof—for your cyber insurance carrier, for compliance audits, and for your own peace of mind.
The Cost of Getting This Wrong
The Ponemon Institute pegs the average cost of an insider threat incident at $17.4 million annually per organization in 2025—but that number is skewed by enterprise-scale breaches. For a 20-person firm in Southwest Florida, the real cost looks more like this:
- A former employee downloads your client list and takes it to a competitor. You lose three accounts worth $150,000 in annual revenue.
- A disgruntled ex-employee logs into your aging server and deletes files. Recovery takes a week and costs $10,000–$25,000 in lost productivity and emergency IT support.
- Your cyber insurance claim is denied because the breach came through credentials you failed to revoke. Now you are paying the full cost of breach notification, legal fees, and client remediation out of pocket.
Mean time to identify and contain an insider breach is 292 days, according to industry benchmarks. That means the damage from a botched offboarding in March might not surface until December. By then, the trail is cold and the damage is done.
How to Start Fixing This Today
You do not need to overhaul everything at once. Here are three things you can do this week:
- Audit your last three departures. Go back to the last three employees who left your company. Can you confirm, right now, that every one of their accounts is disabled? If you cannot, you have active risk sitting in your environment today.
- Build the checklist. Take the 10 questions above and turn them into a step-by-step checklist with names and deadlines. Assign an owner—someone who is responsible for making sure it happens every time.
- Get a SaaS access audit. Ask your IT provider (or do it yourself if you are technical enough) to run a report of every user account across your cloud applications. Look for accounts belonging to people who no longer work for you. You will almost certainly find some.
If you are a small business in Fort Myers, Naples, or anywhere in Southwest Florida and you do not have a formal offboarding process, you are not alone. But you are exposed. And with cyber insurance carriers tightening requirements and insider threats on the rise, “we will figure it out when it happens” is no longer a viable strategy.
Want help building an offboarding process that actually works? SWFIT offers a free IT security consultation for SWFL businesses. We will review your current offboarding procedures, identify gaps, and help you build a repeatable process that protects your business every time someone walks out the door. Schedule your free consultation here or give us a call.