Ask your IT person a simple question: how many login accounts are active right now for people who don't work here anymore?

Watch the pause. I've asked it a dozen times in mid-market companies, and the pause is always the same. Because nobody knows the answer off the top of their head, and almost nobody has ever checked.

Departed employees are the security hole nobody pictures. When you hear "breach," you think of a hacker in a hoodie. But in my experience, the far more common version is an old account that never got turned off. A sales rep who left in 2024 still has the CRM on his phone. A bookkeeper who was let go can still open the shared drive. Nothing malicious so far. But the door is open.

Offboarding Is a One-Time Event That Nobody Owns

Here's how it usually goes. HR walks someone out on Friday. The manager asks IT to "cut off their access." IT disables the email. Maybe. Then everyone moves on to the next thing, and the six other accounts nobody remembers just sit there.

The shared file system. The accounting software. The CRM. The building alarm code. The vendor portal where they had an admin login because someone needed a favor three years ago. The VPN token nobody collected.

Each one is a small gap. Added up, they're a wide-open back door.

It's Not Just Full-Time Employees

Contractors are worse. The IT consultant who helped with the server migration in March still has the VPN profile. The temp from the busy season still has the shared inbox. Vendor accounts are the worst of all, because they were created by people who don't work there anymore, for companies you might not even use anymore.

And nobody reviews this list because there's no list. That's the real problem. There's no single inventory of who can access what.

The Fix Costs an Afternoon

This is one of those problems that sounds scary and turns out to be cheap. Sit down with a spreadsheet. Every system your company uses, and every account on it. Then match accounts to current employees. Everything left over gets disabled, starting with the email-forwarding ones (those are the sneaky ones, still routing mail to a departed employee's inbox).

Then make it a habit. Two things, done quarterly: HR sends IT the departure list every time someone leaves, not just at termination but at the exit interview, and IT runs the account inventory against it. Offboarding becomes a checklist with one owner, not a verbal request that fades after lunch.

It takes an afternoon to do the first sweep. I've never done one at a company and found zero surprises. The record is eleven active accounts for people who'd been gone over a year.

The Threat Isn't Always Malicious

Most departed employees aren't coming back to steal anything. The risk is duller than that. An old phone that gets lost or sold with the company email still on it. A weak reused password on a CRM account that someone else cracks. An ex-employee who answers a phishing email thinking it's still their workplace, because in a way, the door is still open for them.

You don't need to be paranoid. You just need to close doors when people leave the building for the last time. That used to be a physical key. Now it's twenty digital keys, and most companies never ask for them back.


Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.


About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.