Insight Articles: Identity Security Risks Series – They Left. Their Access Didn’t

For Business Owners, CIOs & CISOs [8-minute read]
They Left. Their Access Didn’t
Nearly 4 in 10 former employees can still access their ex-employer’s systems. The account your IT team forgot is the door attackers are counting on.
The resignation letter arrived on a Friday afternoon. The employee, a senior member of your operations team, was leaving for a competitor. HR processed the paperwork. Their badge was deactivated. Their laptop was returned. Their manager sent a farewell email.
Everyone assumed they were gone.
Fourteen months later, their Salesforce account still has full access to customer data. Their Active Directory account was disabled, but their GitHub access was never revoked. Their cloud storage account, where legal contracts are stored, still works because it authenticates outside your identity platform.
Your organization doesn’t know any of this. The cyber attacker might.
The Numbers Are Alarming
38%
Of former employees have successfully accessed their ex-employer’s systems after leaving – according to a survey of former workers
46%
Of security breaches involve formant, orphans, or former employee accounts as an attack vector
300%
Higher orphaned account risk at organizations relying on manual offboarding processes vs. automated lifecycle management
67%
Reduction in security incidents at organizations that automate their joiner-mover-leaver (JML) processes
These statistics highlight two distinct risks:
- Malicious insiders who retain access after leaving
- Orphaned accounts that remain dormant until an attacker discovers them
Both stem from the same problem: incomplete identity lifecycle management.
Why Offboarding Fails at Scale
Ten years ago, offboarding was relatively straightforward. Disable an employee’s Active Directory account, collect their laptop, revoke VPN access, and most of their system access disappeared with it. That world no longer exists.
The average mid-sized organization now relies on hundreds of SaaS applications. Many authenticate independently of Active Directory or the organization’s primary identity provider. Some were adopted by business units without IT involvement. Others support both single sign-on (SSO) and local accounts, allowing employees to retain separate usernames and passwords that standard offboarding processes never disable.
Disabling an employee’s network account no longer guarantees they’ve lost access to your business.
The Offboarding Reality
When an employee leaves, IT deprovisions the accounts it knows about. The ones it doesn’t know about remain active, invisible, and available to whoever discovers them first.
This is not a theoretical problem. It is the norm. Walk through what happens when an employee exits a typical organization:
| DAY 1 | HR submits a termination ticket. IT disables Active Directory account. Badge access revoked. VPN access removed. |
| WEEK 1 | Manager is supposed to submit a list of applications for IT to deprovision. This often doesn’t happen, managers don’t know all the tools the employee used, and they’re busy covering the departing employee’s workload. |
| MONTH 1 | The employee’s GitHub, Slack, Jira, Salesforce, HubSpot, AWS console, and 12 other SaaS accounts remain active. Some have been reassigned to colleagues. Most have simply been forgotten. |
| MONTH 6 | An attacker purchases a credential dump on the dark web. The former employee’s email and password, reused from another breach, is in the file. The attacker tries it against your Salesforce instance. It works. |
| MONTH 8 | Your security team detects unusual Salesforce activity. Investigation begins. Eight months of potential unauthorized access has occurred through a door that should have been closed on day one. |
Case Studies
The Contractor Problem Is Even Harder
If former employee access is an underestimated risk, contractor and vendor access is often an invisible one. Temporary users frequently fall outside the identity governance processes designed for permanent employees.
First, contractor offboarding is inconsistent. Employee departures usually trigger HR workflows, IT tickets, and account reviews. Contractors often leave when a project ends, with no formal deprovisioning process. If no one submits the request, their access remains.
Second, contractors work across multiple organizations. Their credentials may be used from personal or third-party managed devices that also connect to other client environments. Your security team has little visibility into those devices or how they are protected.
Third, contractors often receive elevated privileges. To complete specialized work quickly, they may be granted administrator-level access to business systems, cloud environments, or production infrastructure. Those privileges are frequently broader than those assigned to permanent employees and may remain long after the engagement has ended.
The result is a privileged account with no active owner, no business purpose, and no one verifying that it should still exist.
“The most dangerous account in most organizations isn’t a current employee’s; it’s a contractor who finished their engagement six months ago and no one thought to revoke.”
What Auditors Are Starting to Ask
Access governance is no longer just a cybersecurity issue. It is an audit issue.
During SOX, SOC 2, ISO 27001, and other compliance assessments, auditors increasingly examine how organizations manage user access throughout its lifecycle. They look for evidence that departing employees and contractors are deprovisioned promptly, privileged access is reviewed regularly, and access decisions are documented.
Organizations that cannot demonstrate consistent, repeatable offboarding processes often receive audit findings or recommendations for improvement. For public companies, significant deficiencies in access controls can contribute to broader concerns about internal controls and financial reporting.
What Automated Lifecycle Management Does
The solution is not a better checklist. Manual processes do not scale. They rely on people remembering to remove access during a departure, when time is limited and priorities are shifting.
Automated joiner-mover-leaver (JML) lifecycle management eliminates that dependency. When an employee or contractor leaves, access is provisioned, updated, or revoked automatically across integrated systems based on predefined policies. No forgotten tickets. No missed applications. No reliance on memory.
Organizations that automate identity lifecycle management report significantly fewer access governance failures because the process is consistent, repeatable, and verifiable. Instead of relying on people to catch mistakes, the process is designed to prevent them.
The Question to Ask Right Now
If your largest sales executive resigned today, how many applications would retain active access by end of day? Do you know? Could your IT team tell you within an hour?
Find Out If Your Offboarding Process Leaves Doors Open
Our Identity Security Gap Analysis includes dedicated sections on identity governance and third-party access. Answer targeted questions and see exactly where your lifecycle management has gaps.
