TL;DR: Almost every business we look at has at least one live account belonging to somebody who no longer works there. It is rarely deliberate. Somebody left, the laptop came back, everyone moved on, and nobody closed the door behind them. It is the cheapest security gap in existence to fix and one of the most common reasons a Cyber Essentials renewal falls over. Here is the list, and how to stop it depending on anybody's memory.
The account nobody closed
When somebody leaves, the visible things get done. The laptop comes back. The keys come back. Payroll is told. Somebody makes a card.
What usually does not happen is anyone sitting down and working through everything that person could sign into. Partly because it is dull, partly because it happens at the busiest possible moment, and partly because nobody owns it. HR assumes IT did it. IT was never told they had left.
So the account sits there. Still licensed, still able to receive email, still able to sign in from anywhere in the world, still holding whatever it held on the day they walked out.
Why it is worse than it sounds
An open account is not just an unused account. It is a way in that nobody is watching.
Nobody notices the sign-ins. If a current member of staff has their password stolen, there is a decent chance something looks odd to them: a prompt they did not ask for, a folder that moved, a reply to a message they never sent. A leaver's mailbox has nobody looking at it. An intruder can sit in it quietly for months.
The password is probably out there. People reuse passwords. A leaver's work password is quite possibly also their password on some website that has since been breached. Once they have gone, nobody is going to change it, and nobody is going to be prompted to.
It is often the account with the widest access. Long-serving people accumulate permissions. The person who was there fifteen years has access to things nobody else does, and no line manager can tell you what those things are.
The mailbox is full of useful material. Invoice history, supplier contacts, bank detail conversations, the tone the person wrote in. That is exactly what somebody needs to write a convincing fake, which is how payment fraud usually starts.
We wrote up a real example of what happens when the wrong mailbox is reachable in our breach case study. The mechanics are dull and the consequences are not.
The bit that catches certification
If you hold or want Cyber Essentials, user access control is one of the five technical controls, and removing access when it is no longer needed is part of it. An assessor asking "how do you know every leaver has been removed?" is not asking a philosophical question. They want to see that you can answer it.
Since the April 2026 update this matters more, because that update also made missing multi-factor authentication on a cloud service an automatic fail. Every stray account on every service is now a potential fail rather than a note. We covered the rest of that in what the Danzell update changed.
The two lists you actually need
Everything below depends on having these, and most businesses have neither written down.
One: what your business signs into. Not just Microsoft 365. The accounting package, the CRM, the payroll system, the online banking, the supplier portals, the courier account, the design tool one person pays for on a card, the social media logins, the domain registrar, the website. If nobody has ever listed these, that is the first job, and it is a job for an afternoon rather than a project.
Two: who has access to what. Roughly is fine. You are not building a matrix. You just need to know, for each service, who to remove.
Once those exist, offboarding stops being an act of recall and becomes a list you work through.
The leaver checklist
Before the last day
- Agree what happens to their email. Usually a redirect to a colleague for a period, then closure. Decide it in advance rather than in a hurry.
- Find out what only they know. Which supplier they always deal with, which spreadsheet drives what, which login is in their head. This is a business continuity question, not a security one, and it is much easier asked while they are still there and still friendly.
- Ask them, plainly, what they sign into for work. People are usually happy to tell you, and they will name three things you did not know existed.
On the last day
- Disable the account rather than deleting it. Deleting can take data with it and can break things that referenced it. Disabling stops sign-in immediately and buys you time to sort the rest out properly.
- Sign them out everywhere and revoke active sessions. This is the step people miss. Changing a password does not always kick out a session that is already signed in on a phone. On Microsoft 365 the sessions have to be revoked explicitly.
- Remove access from their phone. If work email was on a personal device, the company data needs pulling off it. This is straightforward when devices are managed properly through something like Intune and awkward when they are not.
- Collect the hardware, and write down what came back. Including the laptop, the dongle, the second monitor and the phone.
In the following week
- Work down the services list. Every one of them. This is where the ones nobody knew about surface.
- Reclaim the licence. A Microsoft 365 licence sat on a disabled account is money leaving your bank every month for nothing. This is the part of the job that pays for the rest of it.
- Check for forwarding rules and delegated access. A rule quietly copying mail elsewhere is both a security problem and an easy thing to miss.
- Change any shared passwords they knew. Which brings us to the real problem.
The shared login problem
Almost every business has a few logins that are not attached to a person. The generic info@ mailbox. The bank card portal. The account with the electricity supplier. The one for the machine that needs an account and does not care whose.
These are the ones that never get changed when somebody leaves, because changing them affects everybody and no one person owns it. So the leaver keeps working access to them indefinitely.
Two things help, and neither is dramatic. Put shared credentials in a password manager the business controls, so changing one is a two minute job rather than a ring-round. And reduce the number of genuinely shared logins by giving people their own accounts wherever the software allows it, which most now do.
The awkward one
Not every departure is amicable. If somebody is leaving badly, or is being let go, the order changes: access is removed as the conversation happens, not afterwards.
That feels harsh and people resist it, which is understandable. But it is standard practice for a reason, and it protects the leaver as much as the business. If nothing is deleted and nothing goes missing, nobody is having an argument about it later.
Stop it depending on memory
The reason leavers get missed is never that people do not care. It is that the process lives in somebody's head and that person is busy on the day it matters.
Three things make it stick:
- One trigger. Whoever knows first, HR or the line manager, tells one named person or one shared mailbox. Not "mentions it".
- One written list. The checklist above, adapted to your business, on one page, with your actual services named on it.
- A periodic sweep. Twice a year, list every account that can sign in and check each one against the payroll. It takes an hour and it is how you find the ones that slipped through. If your IT is managed properly this should be a report somebody sends you rather than a job you do.
The NCSC's small business guide covers access control alongside the other basics if you want the official version, and the ICO's guidance for organisations is the place to start on the data protection side, because a leaver still holding access to personal data is a data protection question as well as a security one.
Where to start
Do the sweep first. Before you write any process, find out how many open accounts you currently have belonging to people who have gone. That number is usually what convinces everybody the rest is worth doing.
If you would like us to run that check across your systems and tell you what is still open, get in touch or call us on 01584 517234. It is a quick job, we do it as part of managed support anyway, and it is one of the few security exercises that usually saves money in licence costs while it is at it.

