A former employee's account is a potential entry point for unauthorized access to the corporate network. According to the ENISA Threat Landscape 2025, phishing remains the leading initial access vector, making offboarding a critical, managed 24-hour security transaction.
Industry implications
For modern enterprises, failing to secure the offboarding process leads to severe security gaps, including potential data leaks, regulatory non-compliance, and unauthorized access to proprietary systems. As cyber threats evolve, maintaining strict identity management becomes a critical factor in preserving business continuity and client trust.
Key risks of "orphaned" accounts
According to the Cisco Cybersecurity Readiness Index 2025, identity management is the foundation of cyber resilience. Vulnerabilities arise when a central IAM is not integrated with all services. Common points of failure include:
- retained SaaS access via local accounts without SSO;
- active VPN sessions that are not forcibly terminated;
- unrotated passwords for shared service accounts;
- untransferred ownership of critical files and repositories.
What to do
To secure your organization, establish a strict 24-hour offboarding protocol. Integrate all corporate services with a central IAM, automate session revocation, and follow a structured timeline to systematically disable access, rotate secrets, and audit the entire process as detailed below.
Four steps to securely revoke access
1. Central IAM and session revocation
Disabling an account in the IdP or Active Directory is only the first step, as it does not always terminate active sessions. It is essential to forcibly revoke web sessions and OAuth tokens (Session Revocation) within the first few hours of departure.
2. Securing the network perimeter
Access to VPNs, bastion hosts, and PAM systems must be terminated immediately. The response playbook should include the forced termination of active VPN tunnels to eliminate open communication channels.
3. SaaS application inventory
For services that do not support SSO or SCIM, a separate registry must be maintained with designated owners who manually deactivate local accounts according to a strict protocol.
4. Secret rotation and ownership transfer
Before deleting a user, it is critical to transfer ownership of repositories and cloud resources, as well as rotate shared passwords and API keys the employee had access to.
Hour-by-hour offboarding timeline
To minimize risks, we recommend implementing an internal SLA where every action is logged in an audit trail:
- 1-2 hours: account suspension in IdP and forced revocation of active sessions.
- 4 hours: deactivation of VPN and PAM access.
- 8 hours: manual lockout of local SaaS accounts.
- 12-16 hours: rotation of service account secrets and transfer of resource ownership.
- 24 hours: ticket closure and preservation of a complete audit trail.
Prepared by a Software Ukraine member. Original publication.