
Late summer is when a lot of Massachusetts small businesses quietly turn over staff. Seasonal hires wrap up, interns head back to campus, and a few people move on to new jobs before the fall push. Somewhere in that shuffle, a laptop gets returned and everyone assumes the job is done. It usually isn’t.
The access nobody remembers to kill
Recent research from Beyond Identity found that roughly 89 percent of former employees still have access to at least one business application after they leave. A separate study from Oomnitza put a number on the uncertainty behind that: 68 percent of organizations say they cannot confirm with certainty that all of a departing employee’s access has actually been revoked. Wing Security’s research on SaaS sprawl found something similar, 63 percent of businesses have at least one former employee who still has a live login to a corporate app nobody remembered to shut off.
None of this is really about malice. It’s about process, or the lack of one. A departing employee might have accounts in twenty different systems: email, file storage, a CRM, a scheduling tool, a handful of niche apps someone signed up for two years ago and forgot to mention to IT. Killing the domain login doesn’t touch any of that.
What this actually costs
The FinWise Bank breach earlier this year is a useful reminder of what “somebody still had access” looks like in practice: a former employee accessed sensitive files after their employment ended, and roughly 689,000 customers had personal data exposed as a result. Breaches involving the human element, error, misuse, stolen credentials, or social engineering, still account for something like 60 percent of all incidents industry-wide, and insider-related breaches carry some of the highest average costs of any attack type.
You don’t need a former employee to act maliciously for this to hurt you. An old, unmonitored account is just a door somebody forgot to lock, and it takes exactly one person finding it.
Why offboarding falls through the cracks
For most small and mid-sized businesses, offboarding is a checklist stapled to an HR process, not a security control tied to identity management. HR knows the person is leaving. IT finds out when someone remembers to send an email, sometimes days later. There’s rarely one system that shows every app a given employee ever touched, so deprovisioning becomes a memory exercise instead of a process, and memory is exactly the thing that fails first when a team’s stretched thin during a busy season.
Closing the gap
This is fixable, and it doesn’t require an enterprise budget to get right:
- Centralize identity. Route access to core systems through a single identity provider so one action, disabling the account, actually shuts most doors at once.
- Tie IT to HR, not to memory. Offboarding should trigger automatically the moment HR marks someone as terminated, not whenever it occurs to someone to make a call.
- Run access reviews on a schedule. Quarterly reviews catch the accounts that centralization misses, the side tools, the shared logins, the vendor portal someone set up in 2023.
- Document it. A written offboarding checklist that names every system, not just email and the network drive, closes the gap between “we think we got it” and “we know we got it.”
Its worth saying plainly: this isn’t a one time project, its an ongoing discipline, and the businesses that treat it that way are the ones that don’t end up explaining a breach to their customers next year.
Cloud9 Tech Solutions builds identity governance and access management into the operational backbone we run for clients, so offboarding stops being a memory exercise and becomes something that just happens correctly, every time, without anyone having to remember to do it.
Schedule a free security assessment with Cloud9 and we’ll show you exactly which accounts, apps, and former employees still have a door propped open in your environment.
