In February 2009, as redundancy programmes ran across almost every sector, the Ponemon Institute published a survey of people who had recently left their jobs. Fifty-nine percent admitted taking company data with them. Ninety-two percent said they had taken CDs or DVDs; seventy-three percent, USB memory sticks. A later study of 600 financial services workers in New York and London who had lost or left jobs found forty-one percent had taken confidential company data with them. Those numbers are not evidence of an unusually dishonest workforce. They are evidence that most organizations had no controls at the one moment when controls matter most, and the numbers have not improved as much as the intervening seventeen years of security investment would suggest.
The Mechanics of a Layoff Week
A restructuring compresses every weakness in access management into a few days. The notification is scheduled for Tuesday morning. HR needs the list confidential until then, so IT is not told in advance. On Tuesday afternoon, IT receives fifty names and is asked to disable accounts — usually by email, often with inconsistent name spellings, sometimes without employee IDs. Meanwhile the actual exposure has already occurred. People in scope frequently know, or suspect, before the announcement. The copying happens during the notice period, not after the account is disabled. Then the backlog begins. The primary directory account is disabled quickly. What survives is everything else:
- Applications outside single sign-on. Every SaaS tool procured by a department, every legacy system with local credentials, every vendor portal. These are not in the offboarding checklist because nobody maintains a complete list of them.
- Personal devices with corporate data. Phones with mail and file sync, home computers with documents copied for weekend work, personal cloud accounts holding project folders.
- Third-party and OAuth grants. Tokens issued to connected apps continue functioning after the primary account is disabled, in more environments than administrators expect.
- Shared and service credentials. The departing engineer knew the shared admin password, the service account password, the wifi key for the server room. None of these rotate on a termination.
- Privileged access nobody inventoried. Break-glass accounts, cloud console roles, database credentials in scripts, SSH keys on jump hosts.
- Contractors and consultants. Often outside the HR system entirely, so no termination event exists to trigger anything. Every incident review I have seen after a large restructuring finds at least three of these. Most find all of them.
What the Departing Employee Usually Takes
The stereotype is a disgruntled saboteur. The reality is more mundane and more damaging to compete against: people take the work they consider theirs. Sales staff take contact lists and pipeline. Engineers take code and design documents. Finance staff take models they built. Marketing staff take campaign material and creative files. In the surveys of this period, a large share of respondents said obtaining future employment was a motivating factor — which tells you the destination of the data is usually a competitor, not a criminal market. This is why the problem is not solved by malware detection. It is solved by access control, monitoring of bulk movement, clear ownership rules stated at hire, and an exit process that makes the expectation explicit.
Controls That Actually Work During Restructuring
- Trigger revocation from the HR system, not from an email. Termination in the HR record should automatically disable identity, mail, VPN, SaaS and device access. Manual lists are where names get missed.
- Plan offboarding before the announcement, under confidentiality. Security leadership can be briefed as part of the restructuring team without the names leaking. Being surprised by a layoff is an organizational choice, not a necessity.
- Complete an access inventory first. Every application, every credential type, every third-party grant, every device. If you cannot produce this list in an hour, that gap is your real finding.
- Monitor bulk data movement during notice periods. Large downloads from CRM, code repository cloning, mass mailbox exports, unusual file share access, high-volume printing. Detection at this stage is the only control that catches data that has already left the building.
- Collect devices and verify. Recover hardware, wipe corporate profiles on personal devices, confirm rather than assume.
- Rotate shared and service credentials. Anything the departing person knew, especially in infrastructure and privileged roles. This is the step most commonly skipped because it requires change coordination.
- Revoke tokens and third-party grants explicitly. Disabling the account is not always sufficient.
- Make ownership explicit at exit. A short, specific acknowledgement of what is company property, what must be returned or deleted, and what obligations continue. Signed on the last day, referencing the original employment terms.
- Handle privileged departures differently. System administrators, DBAs and cloud engineers warrant a tailored process: immediate revocation, credential rotation, and review of their recent activity logs. Two caveats worth taking seriously. Employee monitoring intersects with privacy and employment law, which differs sharply across jurisdictions — in the GCC as in Europe, monitoring should be proportionate, documented in policy, disclosed, and run with HR and legal involvement. And treating departing colleagues as suspects damages the people who remain. The objective is systematic control, not visible suspicion.
Prepare privately
Coordinate HR and security before notification; inventory applications, grants, devices and privileged access.
Revoke and rotate
Use the approved termination event; close access and explicitly revoke tokens and shared credentials.
Return and preserve
Recover equipment and corporate profiles while retaining required business records.
Verify closure
Test remaining access paths and document the result rather than assuming revocation succeeded.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
The Modern Version Is Harder
In 2009 the exfiltration channels were CDs, USB sticks and webmail. Today they are personal cloud sync clients, code hosting accounts, browser profile synchronisation, messaging apps with file transfer, and AI assistants where an employee can paste a customer list into a personal account and retrieve a formatted version elsewhere. Meanwhile the average employee's application footprint has multiplied, and much of it was bought with a departmental card and never registered with IT. The offboarding problem has not been solved; it has been distributed across more systems, most of which are not in your identity provider. The practical test is simple, and worth running this quarter rather than during the next restructuring: pick someone who left three months ago and try to prove every access path they had is closed. Most organizations cannot, and the discovery is significantly cheaper now than it will be in the middle of a redundancy programme.
Common Questions
How common is data theft by departing employees?
Studies conducted during the 2008-09 downturn found that a majority of departing employees admitted taking company data, with around four in ten financial services leavers reporting the same. The behaviour is widespread rather than exceptional.
When should access be revoked during a layoff?
The same day, triggered automatically by the HR termination record, covering identity, mail, remote access, SaaS applications, devices and third-party tokens — not only the primary directory account.
What is the most commonly missed offboarding step?
Rotating shared and service credentials the departing person knew, and revoking access to applications that sit outside single sign-on. Both require an accurate inventory that most organizations do not maintain.
Can we monitor employees during their notice period?
Generally yes, within limits set by local employment and privacy law, provided monitoring is proportionate, disclosed in policy, and coordinated with HR and legal. Focus on bulk data movement rather than individual surveillance.
Offboarding Controls Review — Outpace tests whether your leaver process actually closes every access path, builds the automated revocation chain from your HR system outward, and prepares the controls you will need before the next restructuring is announced.
