03333 44 6500 Mon–Fri 8am–6pm
IT Support

IT Onboarding and Offboarding: The Security Gap Most Businesses Overlook

Most security incidents don't come from sophisticated hacking. They come from an ex-employee's account that was never disabled, or a new starter who spent their first week locked out of the systems they needed. Onboarding and offboarding are unglamorous — and that's exactly why they get neglected.

CH
CloudHost Team
16 Jul 2026 · 6 min read

Ask most business owners how their IT team handles a new starter or a leaver, and the answer is usually vague — "we sort it out," or "HR lets IT know." That vagueness is the problem. Onboarding and offboarding sit at the intersection of IT, HR and security, and when nobody owns the process end to end, things get missed. A new employee doesn't have the accounts they need on day one. A former employee's login still works three weeks after they've left.

Neither of those outcomes is dramatic on its own. But taken together across a business with normal staff turnover, they represent one of the most persistent and preventable security gaps we see.

Why Offboarding Is the Bigger Risk

A slow onboarding is a productivity problem. A slow offboarding is a security problem — and it's more common than most business owners realise. When someone leaves a company, their access needs to be removed from every system they touched: email, file shares, VPN, CRM, accounting software, any SaaS tool they had a login for, and any shared passwords they knew.

In practice, that list is rarely written down anywhere, which means offboarding becomes a memory exercise for whoever handles it. Accounts get missed. Shared logins don't get changed. And the risk isn't hypothetical — a disgruntled former employee with lingering access, or simply an old account that gets compromised because nobody's watching it anymore, are both realistic scenarios we've dealt with directly.

The mobile device blind spot: If staff use personal phones for work email via mobile device management (MDM) or simple app-level access, offboarding needs to include revoking that access specifically — it's one of the most commonly forgotten steps, and it's often the one that leaves company email visible on a personal device indefinitely.

What a Proper Offboarding Process Covers

  • Immediate access revocation for email, file storage, VPN and any admin-level accounts — ideally actioned the moment HR confirms the leave date, not days later
  • A full inventory of accounts tied to that person, including SaaS tools that may not run through central IT (marketing platforms, project management tools, industry-specific software)
  • Mailbox handling — converting to a shared mailbox, forwarding to a manager, or archiving, depending on what the business needs to retain
  • Device return and wipe, including confirmation that company data has been removed from personal devices where applicable
  • Password rotation for any shared or service accounts the person had knowledge of
  • Physical access — building access cards, alarm codes, keys — which often falls outside IT's remit entirely but should be part of the same checklist

Why Onboarding Deserves the Same Rigour

The cost of a poor onboarding is different but still real. A new employee who spends their first two or three days without proper system access, correct permissions, or a working laptop isn't just having a bad week — it's a direct hit to productivity during the period when they should be forming their first impression of how the business operates. It also creates a workaround culture: staff start sharing logins or using personal accounts to get things done, which quietly undermines the access controls you've put in place elsewhere.

A defined onboarding process also matters for the reverse of the offboarding problem — least-privilege access. New starters should be given exactly the access their role requires, not a copy of a colleague's permissions "to save time," which is how access sprawl accumulates over years.

Building a Repeatable Checklist

The fix isn't complicated, but it does require someone to own it. A joiner/mover/leaver process, documented once and followed every time, removes the dependency on memory:

  • HR notifies IT of a confirmed start or leave date as soon as it's known — not on the day itself
  • A standard account template exists for each role, so new starters get the right access from day one without ad hoc decisions
  • A single checklist tracks every system a leaver needs removing from, signed off item by item
  • Access reviews happen periodically anyway, to catch anything the process missed

Where This Fits With Managed IT

For businesses without a dedicated internal IT function, this process usually falls through the cracks between HR and whoever handles IT informally. It's one of the most common gaps we find when we take on a new managed IT client — not because anyone was careless, but because nobody had been given clear ownership of it.

Under a managed IT arrangement, onboarding and offboarding become a standard, tracked part of the service — a ticket raised the moment HR confirms a date, a checklist worked through, and a record kept of what was done and when. It's not a complex fix. It just needs to be someone's job.

Questions worth asking your IT provider: Is there a documented checklist for onboarding and offboarding? How quickly is access removed after a leaver's last day? Who owns the process when HR and IT need to coordinate?

Next Step

Want a Proper Onboarding & Offboarding Process in Place?

We handle IT onboarding and offboarding for businesses across Derby, Nottingham and Leicester as a standard part of our managed IT service — new starters ready on day one, leavers fully removed on their last.

Or call: 03333 44 6500 · Mon–Fri 8am–6pm