Departure is a security event
Employee offboarding is often treated as an HR procedure: recover company property, finish paperwork, disable email and close the employee record. From a cybersecurity perspective, it is also an identity, access, data-protection and corporate-representation event.
A forgotten cloud application, active API credential, synchronized personal device, accessible customer list or still-active professional identity can remain an exposure long after the final working day. The process must therefore be systematic rather than dependent on someone remembering every account and identity surface the employee used.
Departing employees are a material data-loss risk
Proofpoint’s 2025 Voice of the CISO research reported that two-thirds of surveyed CISOs experienced material data loss in the previous year. Among those CISOs, 92% said departing employees played at least some role, compared with 73% the year before. Separate Proofpoint cloud analysis associated 87% of anomalous file-exfiltration activity observed over nine months with departing employees.
Not every incident is deliberate theft. People may retain work samples or contacts, misunderstand who owns material they created, or leave data synchronized accidentally. In other cases the former employee simply retains access because an account, folder, token, device or external identity was not deactivated.
Insider risk includes mistakes and misuse
Verizon’s 2025 Data Breach Investigations Report analyzed more than 22,000 security incidents and 12,195 confirmed breaches. Its EMEA findings attributed 29% of breaches to internal actors; 19% involved unintentional mistakes and 8% involved misuse. An offboarding control designed only for a malicious insider therefore misses a large part of the problem.
The inventory should cover email, business and cloud applications, collaboration stores, VPN and remote access, repositories, privileged accounts, service accounts, API tokens, customer information, mobile applications and company-managed devices. It should also cover outward-facing cards, public profiles, QR codes, email signatures and other branded identity assets.
Ask three different security questions
Access asks whether the employee can still authenticate to corporate systems. Data asks whether the employee can still possess, synchronize, export or retrieve sensitive information. External identity asks whether customers, suppliers or partners can still encounter an apparently valid corporate identity belonging to the former employee.
Disabling Microsoft 365 and VPN access may answer the first question without answering the other two. Secure offboarding must address all three layers and document who owns each action.
Protect the critical window before departure
Leakage can occur before an account is disabled. Proofpoint described a 2025 law-firm case in which an employee who had accepted a competitor role emailed large amounts of sensitive information to a personal account on the final day. It also observed that departing employees can increase the volume and frequency of sensitive-data transfers shortly before leaving.
For sensitive or privileged roles, the period between notice and departure may justify proportionate monitoring and an activity review under applicable policy and law. This is risk-aware control, not an assumption that every departing employee is malicious.
Coordinate revocation at termination
HR, IT, cybersecurity, application owners and the business manager should coordinate timing. Authentication, active sessions, VPN access, cloud sessions, application and privileged accounts, MFA registrations where appropriate, tokens, shared-mailbox delegations and third-party access all need an assigned owner and confirmed outcome.
Company devices should be recovered or remotely controlled, and credentials that cannot be attributed to one person—such as shared passwords or embedded integration secrets—should be rotated rather than merely removing the employee’s named account.
Review the corporate-data trail
Where appropriate, review unusual downloads, mass transfers, personal-email forwarding, cloud synchronization, external sharing, removable-media activity, large CRM exports, repository downloads and suspicious changes near departure. Preserve relevant evidence and follow legal, privacy and employee-monitoring requirements.
The objective is to determine whether corporate information remains exposed and to contain it, not simply to record that login access ended at a particular time.
Do not overlook external corporate identity
A former salesperson may still possess a company digital card, an apparently valid QR profile, logo and title, an old email signature, branded meeting materials and established customer relationships. Even after internal access is removed, a customer may have no simple way to know that this person is no longer authorized to represent the organization.
IAM platforms answer whether an identity may access a system. Corporate Digital Identity Control answers whether a professional identity remains authorized to represent the organization externally. These controls complement one another; neither should be mistaken for the other.
Where CardIQ fits
CardIQ addresses the outward-facing professional-identity layer. Organizations can centrally manage supported company-authorized identity touchpoints and deactivate the CardIQ identity when an employee leaves, so live digital cards, public profiles and QR-based verification no longer present current authorization.
CardIQ does not replace Active Directory, Microsoft Entra ID, Okta, HR systems, data-loss-prevention, endpoint management or privileged-access management. It addresses the complementary question of whether a former employee can still appear through CardIQ-controlled surfaces as an active company representative.
Make completion verifiable
A complete record should confirm employment status, internal identity disablement, session revocation, application and privileged-access removal, API credential revocation, device recovery or control, any appropriate data review, external professional-identity deactivation and the final audit. High-risk roles may also warrant post-offboarding validation for unexpected access.
The broader problem is fragmented ownership: HR knows the employee left, IT controls some accounts, application teams control others, security monitors data, sales owns CRM records and marketing manages brand assets. Secure offboarding closes the employee’s complete relationship with corporate access, corporate data and corporate identity—and leaves evidence that it did so.