Index / Investigation and response

The Departing Employee

kind
Checklist
domain
People
stage
Investigation and response
read
3 min
assumes
No prior programme in place

The single highest-yield focus in insider risk, and the one with the clearest window for action.

If a programme can only concentrate on one scenario, it should be this one. Departures produce a disproportionate share of real incidents, and unlike most insider risk they come with advance notice and a defined window.

Why departures concentrate risk

Motive is present. A new employer, a grievance, or a belief that the work is personally owned.

Opportunity is unchanged. Access usually continues through the notice period.

Belief in entitlement. This is the important one. Many people taking material do not consider it theft. A salesperson believes the relationships are theirs. An engineer believes the code they wrote is theirs. A consultant believes the deck they built is theirs.

That belief is sincere and generally wrong contractually, and the gap is where most cases originate. Which means a substantial share are preventable by telling people clearly, before they act.

The window

Risk rises from the moment the person decides to leave, which is before you know.

Before resignation. Sometimes visible in retrospect — access broadening, unusual collection, downloads outside normal patterns. Rarely actionable in advance.

Resignation to last day. The critical period. You now know, and access typically continues.

After departure. Residual access that was not revoked, personal devices with corporate data, cloud files still shared.

What to do at resignation

Trigger a review, automatically. Resignation should generate a signal to the risk programme as a matter of process. In many organisations it does not, and the team learns about departures incidentally.

Look backwards, not just forwards. Review the preceding thirty to ninety days of activity. If something was taken, it was probably taken before the resignation, not after.

Narrow access to what the handover requires. Not full revocation on day one — that is punitive and disrupts handover — but removal of access to anything outside the immediate role.

Watch specific signals during notice: bulk download or clone volume, removable media use, external sharing from corporate storage, unusual printing, access to systems outside normal role, forwarding rules.

Preserve, quietly. Mailbox, home directory, endpoint state. Preservation is cheap and unrecoverable if skipped, and it is not an accusation.

The conversation that prevents most of it

An explicit exit discussion about what belongs to the organisation.

Not a warning. A clear statement: here is what is company property, including work you personally created; here is what you may keep; please confirm you have not retained copies, and if you have, tell us now and it is not a problem.

This is uncomfortable to conduct and it works. A meaningful share of people who would have taken something do not, once someone tells them plainly, and some return material they had already copied.

Pair it with a signed acknowledgement. The signature matters less than the conversation.

Involuntary departures

Different profile: no notice period, higher emotion, and the person may become aware before the meeting.

Plan access revocation to coincide with the conversation, not after. This requires coordination arranged in advance with whoever holds the access, which is awkward to organise before it is needed and considerably worse to improvise.

Preserve before the meeting.

Do not revoke early. Someone who discovers their access has gone before being told is a situation nobody wants to manage.

After departure

Confirm equipment returned. Confirm cloud files reassigned and external sharing revoked. Confirm all accounts closed, including the third-party services nobody tracks. Rotate any shared credentials the person knew.

Most organisations do the first and not the rest, and the rest are where the residual exposure lives.