10-Step Employee Offboarding Security Checklist

A departing employee can create a security gap in less time than it takes to send a company-wide farewell email. Their laptop may still hold client files, their phone may receive multifactor authentication prompts, and their inbox may contain years of sensitive conversations. A clear employee offboarding security checklist helps your business close those gaps quickly, respectfully, and without disrupting the work that still needs to get done.

For small and mid-sized businesses, offboarding is often handled by a busy office manager, HR lead, or owner who is balancing several priorities at once. That is understandable, but access removal cannot wait until the end of the week. A consistent process protects your data, supports compliance, preserves business continuity, and gives every departing employee a professional experience.

Why Offboarding Is a Security Priority

Most cybersecurity discussions focus on outside attackers. Yet former employees can become an unintentional risk when accounts are left active, devices are not returned, or business data remains in personal storage locations. In more serious situations, a disgruntled employee may attempt to delete files, forward customer records, or retain access after their employment ends.

The goal is not to treat every employee as a threat. It is to recognize that access granted for a job should end when that job ends. A well-run process protects the business while treating the individual fairly and respectfully.

The right timing depends on the departure. For a planned resignation, you can prepare account ownership changes and knowledge transfer in advance. For an involuntary termination, access removal should happen at the time of notification, coordinated closely between leadership, HR, and IT. In either case, your process should be documented rather than dependent on someone remembering what to do.

The Employee Offboarding Security Checklist

1. Notify the right people early and discreetly

HR, the employee’s manager, IT, and any relevant department leaders should know the departure date and the expected timing for access changes. Share only the information necessary to complete the offboarding process. This is especially important when the employee has access to financial systems, medical information, legal files, customer databases, or confidential project materials.

Assign one person to own the checklist. When responsibility is unclear, tasks are easily duplicated or missed. The owner should confirm completion with IT rather than assuming an account was disabled.

2. Identify every account and access point

Start with a current inventory of the employee’s systems. Email and computer logins are only part of the picture. Review cloud applications, shared drives, accounting platforms, CRM tools, VoIP systems, remote access tools, password managers, file-sharing services, project management platforms, and industry-specific software.

Pay close attention to accounts that are not connected to your central identity system. If an employee signed up for a software tool using a company email address but managed it independently, that access may not be removed when their Microsoft 365 or Google Workspace account is disabled.

A managed IT provider can help maintain an accurate user and application inventory throughout the year. That makes offboarding faster and far less dependent on last-minute detective work.

3. Disable sign-in access at the right time

On the employee’s final working day, or immediately during a termination meeting when appropriate, disable their primary network, email, and single sign-on accounts. This action should also revoke active sessions, not simply prevent future logins. Otherwise, an already-signed-in browser or mobile app may remain connected.

Remove access to virtual private networks, remote desktop tools, shared folders, internal portals, and cloud applications. Reset shared passwords the employee knew, including passwords for departmental logins, vendor portals, Wi-Fi administration, alarm systems, and social media accounts.

Do not automatically delete the user account. Disabling it first preserves business records and provides time to confirm that email, files, and licensing have been handled correctly. Retention requirements vary by industry, so legal counsel or compliance leadership may need to guide how long records are kept.

4. Remove multifactor authentication methods

Multifactor authentication is one of the strongest protections for active employees, but it can create a lingering access risk after departure. Remove the employee’s registered phone numbers, authenticator apps, hardware tokens, recovery codes, and security keys from company accounts.

This step is easy to overlook when access is removed through a central directory but individual applications maintain their own MFA settings. Confirm that the former employee cannot approve sign-in requests or use a saved recovery method to regain access.

5. Transfer ownership of email, files, and business records

A departing employee’s inbox and cloud storage may contain active customer conversations, contracts, estimates, project documents, and operational knowledge. Before access is removed, determine what needs to be transferred to a manager or successor.

Set up appropriate email forwarding or an auto-reply when it serves the business and fits your privacy requirements. An auto-reply can direct clients to a shared mailbox or a designated contact without exposing unnecessary details about the employee’s departure. Avoid forwarding all mail indefinitely. It can create privacy concerns and bury important messages in another person’s inbox.

Review file ownership as well. Shared drives are preferable to storing essential business files solely in an individual’s personal cloud folder. If key records are located there, transfer ownership and confirm the team can still access them after the account is disabled.

6. Recover and inspect company devices

Collect laptops, desktop computers, mobile phones, tablets, monitors, keys, access badges, USB drives, and any company-issued hardware. Record the serial number, condition, returned accessories, and date of return.

Before reissuing a device, IT should verify that it is managed, fully encrypted, updated, and cleared of the former employee’s personal profile and stored credentials. If a device cannot be recovered promptly, use mobile device management or endpoint security tools to lock it, locate it where permitted, or remotely wipe company data.

Personal devices require a different approach. If your bring-your-own-device policy allows business email or files on personal phones, remove company apps and business data through the approved management platform. Do not wipe an employee’s personal photos, contacts, or private information unless your policy and consent process clearly allow it.

7. Review privileged and financial access separately

Not all accounts carry the same level of risk. Administrative accounts, banking portals, payroll systems, accounting software, domain registrar access, cybersecurity dashboards, and backup platforms deserve an additional review.

Remove the former employee as an administrator, signer, billing contact, or recovery contact. Rotate credentials for shared administrative accounts and review whether any personal email address or phone number remains attached to a critical service. A former employee should not be able to reset the password for your website domain, approve a bank transfer, or access a backup containing sensitive records.

For regulated businesses, document who completed these changes and when. That record can support audits and provide assurance that sensitive access was handled properly.

8. Preserve continuity for customers and coworkers

Security should not leave your team unable to answer customer questions or finish active work. The employee’s manager should identify open tasks, key contacts, calendar commitments, voicemail messages, and shared responsibilities before the departure date whenever possible.

Update phone system call routing, shared mailbox permissions, support queues, and team calendars. If the employee was the only person with access to a vendor account or client portal, transfer responsibility before disabling their account. This is one reason offboarding should involve both operational leadership and IT.

9. Check for unusual activity after access is removed

A short post-offboarding review can catch issues that were not apparent during the transition. Look for failed sign-in attempts, unusual file downloads, unexpected forwarding rules, or new external sharing permissions created shortly before departure.

The appropriate level of monitoring depends on the employee’s role and the sensitivity of your data. A staff member with basic email access presents a different risk profile than an IT administrator, finance leader, or employee with patient, client, or financial records. Your incident response plan should define who is notified if suspicious activity is discovered.

10. Document completion and improve the process

Keep the completed checklist with the employee’s HR or security records. Document accounts disabled, hardware returned, data transferred, access exceptions, and any follow-up items. Documentation is valuable for compliance, but it also prevents recurring confusion when someone asks months later who owns an account or where a former employee’s files went.

After each offboarding, take a few minutes to identify gaps. Was there a software account nobody knew about? Did device recovery take too long? Were shared passwords being used where individual access should have been required? Small improvements after each departure create a stronger process over time.

Common Mistakes That Leave Businesses Exposed

The most common mistake is waiting until after the employee has left to contact IT. By then, the person may still have access to email, cloud files, and remote systems. Another frequent issue is deleting an account immediately, which can erase information the business still needs or complicate legal retention obligations.

Businesses also overlook third-party tools, especially free applications adopted by departments without formal IT involvement. A reliable software approval process and routine access reviews reduce that risk long before an employee gives notice.

Finally, do not rely on verbal confirmation. A manager saying, “I think we shut everything off,” is not a security control. A documented process with assigned owners is.

Make Offboarding Part of Your Security Culture

The best offboarding process begins before anyone leaves. Maintain an updated asset list, use individual accounts instead of shared credentials, require multifactor authentication, centralize access where practical, and keep critical business files in shared company locations. Those habits make an employee transition more orderly and reduce the chance that a single departure creates unnecessary downtime or exposure.

People move on for many reasons. Your business should be ready to wish them well while protecting the customers, information, and operations that remain in your care.