Practical guideEN056

The Small Business Offboarding Security Checklist

Use this step-by-step checklist to revoke access, recover devices, transfer data, and protect client relationships when an employee leaves.

When an employee leaves, the biggest risk is not the goodbye but the forgotten access that can linger for months. The direct answer: to offboard securely, you must revoke all digital and physical access, collect and wipe devices, transfer or archive critical data, update client-facing accounts, and document every step. Acting before the last day and following a repeatable checklist reduces your exposure to data breaches and client confusion. This guide provides the essential steps, based on resources from CISA and NIST.

Why Offboarding Deserves a Security Checklist

A departure can leave behind digital doors that should have been closed. Former employees might still reach email, cloud files, customer databases, or third-party tools with their old credentials. If not revoked, these accounts become a vulnerability that cybercriminals can exploit. CISA’s small business resources advise reviewing access controls regularly, and that includes removing former staff. For a small company, one overlooked login for a CRM or file share can be the point of compromise.

Beyond immediate security, a structured offboarding process helps you show due diligence if a client asks how you protect their data. It also prevents operational hiccups, such as lost client history or delayed handovers. A checklist becomes a record you can audit, which is useful for any future review of security practices.

  • Forgotten access can lead to data theft or unauthorized changes.
  • An outdated account can be used as a foothold for an attack.
  • A documented process supports compliance conversations with clients.
  • A clear handover keeps business moving after the employee departs.
Sources and verification date: [1][2]

Build Your Offboarding Checklist Before the Employee Leaves

Assemble a list of everything the employee can access with a login or a key. Think beyond the obvious: email, cloud storage, accounting, CRM, project trackers, social media, and any partner portals. Ask the employee to name their accounts, and cross-check with your own admin records or with the IT person who set up their accounts. If you don’t keep that list, now is the time to start one.

For each item, decide who will be responsible for revoking access and when. In a small team, the owner or a manager usually handles it, but you might need an outside IT service for certain systems. Write down these owners in the checklist so nothing is assumed. Store the checklist securely, and review it whenever you add a new service or change who handles certain tasks.

  • List every internal and external system with a login.
  • Confirm the list with the employee and your IT team.
  • Assign an owner for each revocation step.
  • Keep a secure copy of the completed checklist for audit.
  • Update the checklist as you add or remove services.
Sources and verification date: [2]

Step-by-Step Security Actions on the Last Day

Act first on the day of departure, or earlier if there is any concern. Revoke access to all accounts you listed. For systems where the employee had admin rights, change the password. Remove or reset any multi-factor authentication tokens that are tied to their device, and disable email forwarding. You can keep the account active for a short handover period, but only under your control, otherwise deactivate it.

Collect all company-owned hardware: laptops, phones, tablets, keys, and security devices. Back up what you need and wipe the device safely. If the employee used a personal device with company data, follow your bring-your-own-device policy to remove only company data, without touching personal files. Document every item you recover and every wipe you perform, so there is a clear trail.

  • Revoke access to email, cloud services, and apps.
  • Reset passwords and remove MFA tokens that were assigned to the leaver.
  • Collect hardware, back up files, then wipe the storage.
  • For BYOD, remove only company data, not personal content.
  • Log all actions in the checklist.
Sources and verification date: [1][2]

Protect Data and Client Accounts During Transitions

Before access is cut, transfer ownership or archive critical business files. Move important documents to another owner in the cloud drive, export emails that relate to ongoing projects or clients, and save a copy of any files that are needed later. Then, confirm that only the right people can see confidential information. Restrict access to customer data while you sort out the handover.

Also pay attention to accounts that are outward-facing, such as social media profiles, client portals, or partner systems. Change passwords and update the contact person so the former employee cannot speak for your company. If a new employee will manage a client account, treat that as you would any new working relationship. The U.S. International Trade Administration’s guidance on due diligence for partners is a useful model: check who you are dealing with before granting access.

  • Transfer file ownership and archive critical emails.
  • Change passwords for social media and client portals.
  • Update internal records to reflect the new owner.
  • If you bring in an external party, do a basic suitability check first.
  • Decide, with legal input, whether to inform clients about the change.
Sources and verification date: [1][2][3]

Make Offboarding a Habit and Review Regularly

Security is not a one-time task. Schedule a quarterly review of user lists in every system you use, and check for accounts of former employees that still work. Remove them, or disable them if they are not needed. Use a password manager so you can generate unique passwords, and enforce multi-factor authentication on any service that supports it. These are core recommendations in the NIST Small Business Quick-Start Guide.

Train your team on this offboarding process and do a trial run with a pretend departure to find any missing steps. When you bring in a new tool, add it to your checklist right away. By repeating these checks, you make security a normal part of business, reducing the chance of a costly oversight.

  • Review user access lists quarterly.
  • Remove or disable accounts of former employees that are no longer needed.
  • Use a password manager and enforce MFA.
  • Practice with a mock offboarding scenario.
  • Add every new service to your checklist at signup.
Sources and verification date: [1][2]

What to verify

  • Laws about data retention and employee privacy differ by location; consult a lawyer for your jurisdiction.
  • This guide is a starting point, not a full security program; consider a deeper risk assessment.
  • CISA and NIST resources are U.S.-focused; adapt for other countries or check local guidance.
  • Specific legal duties for your industry are not covered; get tailored counsel if needed.

Questions and answers

What is the first step to secure an employee’s departure?

The first step is to list all accounts and hardware the employee can access, including email, cloud documents, software, and physical devices. Then, revoke that access on the last day or earlier if you are concerned. The CISA small business resources provide a baseline for these actions. [1]

Should I delete an ex-employee’s email account?

Do not delete it until you have saved essential business emails and set forwarding or an auto-reply if needed. After that, deactivate the account, but keep a backup for a period that fits your policy and any legal duties. After 30-90 days, you can permanently delete it. The NIST guide stresses the need for a defined access control process, which includes email accounts. [2]

How do I handle a departing employee who used a personal device for work?

Follow your BYOD policy if you have one. Use an MDM tool or guide the employee to remove company email and apps from the personal device. Ensure you only delete company data, not personal information. Document that the removal occurred. If you lack a BYOD policy, consider creating one to make future offboarding easier. [1][2]

Sources and verification date

  1. Official source: cisa.govcisa.gov · Checked
  2. Official source: csrc.nist.govcsrc.nist.gov · Checked
  3. Official source: trade.govtrade.gov · Checked

Related reading