Jessica Entwistle
September 3 2026
The Register reports that a terminated employee caused significant financial damage to their former employer because nobody revoked their system access after they left. The individual had elevated privileges beyond a standard user account, and IT teams failed to track or disable what needed to be cut off. The employee continued to access company systems after termination, leading to losses estimated in the hundreds of thousands of dollars. The incident highlights a fundamental failure in offboarding processes and access lifecycle management that many organisations will recognise as a persistent operational risk.
Leaver processes are often inconsistent, poorly documented or reliant on manual steps that can be missed under pressure or during periods of organisational change. When someone leaves, particularly if they held elevated access to financial systems, customer data, cloud platforms or administrative tools, the risk window is immediate. Many organisations lack a single source of truth for what access an individual holds, especially when permissions span on-premises systems, SaaS applications, shared accounts, third-party integrations and privileged access management tools. The operational impact of failing to revoke access promptly can range from data exfiltration and sabotage to regulatory breach, financial loss and reputational damage. The challenge is compounded when elevated accounts are not tracked separately, when access is granted informally or when there is no clear ownership of the offboarding process across IT, HR and line management.
Review whether offboarding processes are documented, automated where possible, and consistently enforced across on-premises systems, cloud services and third-party applications. Consider whether IT, HR and line managers have clear ownership of access revocation, whether elevated or administrative accounts are tracked separately in a central register, and whether there is a defined process for disabling access to cloud services, VPNs, email, collaboration tools and shared drives immediately upon termination. Organisations should also review whether access reviews are conducted regularly to identify dormant accounts or permissions that were not removed during offboarding. Where automation is not feasible, ensure there are checklists, ticketing workflows and accountability mechanisms to confirm that access revocation has been completed. Consider whether there is a process for recovering company devices, credentials and access tokens, and whether there is monitoring in place to detect post-termination access attempts.
Source: The Register