As cited
Copy frozen at (site build).
breaches incidents
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
A terminated employee at a company with over 1,000 staff caused hundreds of thousands of dollars in damage by deleting files, locking out accounts, and corrupting databases after nobody revoked system access following separation. The incident resulted from unclear responsibility between HR and IT departments, lack of a formal offboarding process, and excessive system knowledge concentrated in a single person. The organization's recovery was prolonged because the departing employee was among the few who understood the affected systems.
Why it matters: Security and IT leaders must establish clear offboarding procedures with assigned owners and same-day access revocation to prevent terminated or departing employees from exploiting retained credentials, particularly those with elevated or shared administrative privileges.
- Source published
- First seen by Cybersecurity Tracker