An Employee Just Left. Who Still Has the Keys to Your Business?

Someone gives notice. You collect the door key, the laptop, and the company credit card, sign off on their last timesheet, and wish them well. Two months later a customer emails to say they got a strange message from that person's old company address. Or you notice invoices still being approved from a login nobody remembers using. Or you go to change a vendor portal password and realize the only person who ever knew it left in the spring.

None of that is a hacker. It's just an ordinary departure that was never fully closed out — and it's one of the most common security gaps we see in small businesses across Southwest Ohio.

This is more common than anyone admits

In a survey of U.S. workers, 83% said they continued accessing accounts from a previous employer after leaving, and 74% of employers said they'd been negatively affected by a former employee breaching their digital security (Beyond Identity, "Former Employees Admit to Using Continued Account Access to Harm Previous Employers," 2022). Those are self-reported numbers from one survey, so take the exact figures loosely. The direction is the point: when nobody owns the shutdown, access lingers.

And most of the time it's not malice. It's an ex-employee who still has the email app on their phone, a shared "office" password nobody rotated, or a cloud account that was never on anyone's list to begin with. The consequences are the same either way.

Why small businesses are especially exposed

Big companies have an HR system that flips a switch and forty things happen automatically. A 12-person business in Xenia or Lebanon usually has a manager who knows most of the logins, an office admin who knows the rest, and a handful of accounts that were set up on somebody's personal email years ago and forgotten.

Three things make it worse:

  1. Shared passwords. One "front desk" login for the scheduling software, one shared inbox password, one Wi-Fi password taped under the router. Whoever leaves takes those with them, and they don't change unless someone makes it happen.

  2. Accounts that aren't in "IT." The social media page, the online banking view-only login, the shipping account, the QuickBooks user, the Google Business Profile manager. None of these live on a server. All of them can be used from a phone in a parking lot.

  3. The phone system. VoIP made phones flexible, which means an extension can ring a personal cell, voicemail can be forwarded to a personal email, and a mobile app can answer your main line from anywhere. Very few offboarding checklists mention any of that.

The offboarding checklist

Here's the list we work through with clients. Print it, keep it with your HR paperwork, and run it on the last day — not "sometime that week."


Same day (before they walk out):

1. Disable the email account — disable, don't delete. You'll want the mailbox for customer history, and deleting it can release the address for reuse. Set an auto-reply and forward incoming mail to whoever is taking over their customers.

2. Sign them out everywhere. Most business email platforms (Microsoft 365, Google Workspace) have a "sign out of all sessions" button and a way to remove a phone or laptop from the account. Use both. Changing a password does not always kick out a device that's already logged in.

3. Remove their multi-factor authentication method. If their personal phone is the MFA device on any shared account, that account is now half-controlled by someone who doesn't work for you.

4. Reassign their phone extension. Turn off call forwarding to their cell, remove the softphone app from their user, change the voicemail greeting, and route their direct line to a live person. Check that they aren't still listed in any ring group or on-call schedule.

5. Collect and reset devices. Laptop, desktop, tablet, company phone, any USB drives. Sign the device out of the user's accounts before you reassign it. If they used a personal phone for work email, remove the work account from it (mobile device management makes this a one-click job; without it, you're relying on them to do it).

Within 48 hours:

6. Rotate every shared password they knew. Wi-Fi, the office Windows login, shared inboxes, the scheduling system, the printer admin page, the alarm code, the router. Yes, the router. If you don't know which shared passwords they knew, assume all of them.

7. Remove them from cloud and vendor accounts — file sharing, accounting, CRM, payroll, social media pages, website admin, domain registrar, online banking (view-only counts), shipping and supplier portals, and your internet and phone carrier portals. This is also the moment to check who is listed as the account contact with your carriers. If it's the person who just left, service notices, contract renewals, and outage alerts are now going to someone who doesn't care.

8. Transfer ownership of anything they created. Shared documents, recurring calendar events, automations, the Facebook page admin role. Deleting a user account without transferring ownership can quietly break things weeks later.

9. Check for personal-email accounts holding business assets. The domain name, the Google Business Profile, a software license, or the toner subscription registered to their personal email is a problem you want to find now, not during a dispute.

Within a week:

10. Confirm nothing still routes to them. Send a test email to their old address, call their old extension, and check any mail or ticket rules that forwarded to them.

11. Write down what you did. A dated one-page record of what was disabled and when is worth having if there's ever a question — and it becomes your template for next time.


What good offboarding actually needs

Most of the items above take five minutes each. The reason they don't get done is that nobody has the full list in one place. That's the fix: a single, current inventory of every system your business uses, who has access, and how to shut it off.

If you have a managed IT provider, ask them for it. If you are the IT provider for your own business, a spreadsheet is enough to start — and a password manager with a company vault is the single biggest upgrade, because it turns "who knows the printer password?" into "revoke this person's vault access."

The same inventory pays off at onboarding, too. New hires get the right access on day one instead of borrowing someone else's login, which is how the shared-password problem starts in the first place.

One point of contact makes this easier

When a client's employee leaves, we don't need to be told which systems to check — we already know, because we set most of them up and we're the account contact for the rest. That's the practical advantage of having one independent advisor across your internet, business phones, managed IT, and computers: nothing falls between two vendors.

CreaTech Innovations is a business-only, carrier-neutral technology advisor serving Wilmington, Dayton, Cincinnati, Beavercreek, Centerville, Xenia, Lebanon, Blanchester, Sabina, and Washington Court House. We work with many providers rather than any single one, and we act as your single point of contact — for the phone extension that needs rerouting, the laptop that needs wiping, and the carrier portal login that needs a new owner.

Not sure who still has access to what? We'll help you build the inventory and close the gaps: Contact Us or call (937) 556-4123.

Next
Next

Why Your Business Internet Bill Keeps Creeping Up — and How to Audit It in 20 Minute