← All terms

Offboarding (Leaver Risk)

Offboarding is the controlled removal of a departing employee's access and data. Done late or incompletely, it leaves accounts attackers and insiders can use.

Offboarding is the security process that runs when an employee, contractor, or vendor leaves: revoking accounts and credentials, recovering devices and data, and closing the standing access their role accumulated. Leaver risk is what remains when that process is slow, partial, or informal — and it is one of the most consistently underestimated sources of insider incidents.

How it becomes a security problem

Departure is the highest-risk moment in the employment lifecycle. Insider research repeatedly finds that data exfiltration clusters in the weeks around resignation — source code, customer lists, and pipeline documents copied to personal drives "for reference." After the exit, the risk changes shape: orphaned accounts that nobody disabled keep working, shared passwords the leaver knew stay unchanged, and OAuth grants, API keys, and SaaS logins that never touched the central directory survive indefinitely. An attacker who phishes or buys those credentials months later walks in through a door everyone believes is closed — and monitoring rarely watches an account whose owner is gone. Access sprawled across dozens of SaaS tools, personal devices under BYOD arrangements, and shadow IT accounts registered to work emails all make the checklist longer than the one HR keeps.

How to defend against it

Make offboarding same-day, automated, and complete. Drive deprovisioning from the HR system so termination triggers identity-provider disablement immediately, not at the end of a ticket queue. Maintain a living inventory of each person's entitlements — enforcing least privilege during employment is what keeps the leaver checklist short — and include the long tail: SaaS admin consoles, shared mailboxes, API keys, MFA tokens, and physical badges. Rotate shared secrets the person knew, recover or wipe devices including personal ones holding work containers, and heighten monitoring for bulk downloads during the notice period. Treat sudden or contentious departures as elevated risk with an accelerated checklist. For the program this sits inside, see our guide to insider threat management; the onboarding half of the lifecycle deserves the same rigor.

Related terms

Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.Principle of Least PrivilegeLeast privilege means every user, process and system gets only the access it needs, for only as long as it needs it — limiting what a compromised account can do.Data ExfiltrationData exfiltration is the unauthorized transfer of data out of an organization — by external attackers, malicious insiders, or careless employees.Privileged Access Management (PAM)Privileged access management (PAM) secures and monitors the powerful accounts — admins, service accounts, root — that attackers and insiders prize most.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo