Employee Exit is Also a Cybersecurity Problem

Indian employee exits leave live access behind. See how HR-IT handoff gaps, notice-period risk, and T+30 audits reshape offboarding security.
Employee Exit is Also a Cybersecurity Problem
Kumari Shreya
Monday October 05, 2026
9 min Read

Share

On October 11, 2025, a senior research scientist at Amadeus Software Labs India transferred the company’s source code to his personal email account. His employment was formally terminated on December 3. Bengaluru police registered an FIR in late January 2026 under sections of the IT Act, 2000, estimating the stolen code’s value at roughly ₹87 crore.

The case is unusual in scale, not in kind. Every day, in Indian companies large and small, employees leave the building with something more valuable than a laptop and a swag bag in their hands: access.

That access is what makes an employee exit a cybersecurity event, not only an HR one. The paperwork side (final settlement, gratuity, experience letters, exit interview notes) sits with HR. The access side (SSO tokens, VPN sessions, SaaS logins, admin privileges, endpoint devices, shared drives) sits with IT. The handoff between the two is where things fall apart, and the failure has a rising price tag attached to it.

The HR-IT Handoff Gap Costs Real Money

Every offboarded employee leaves behind a trail of live entitlements: mailbox forwards, shared folder permissions, API tokens, third-party app connections. If HR closes the file and IT never gets a clean trigger, that trail stays open. Attackers do not need to break a wall when a door has been left ajar.

The average total organisational cost of a data breach in India hit ₹25.5 crore in 2026, a 15.9% jump over the prior year, according to IBM’s 2026 Cost of a Data Breach Report. Identity and access management now sits third on the post-breach investment priority list for Indian organisations, cited by 49% of respondents. India’s national numbers reinforce the direction of travel: CERT-In handled 29.44 lakh cyber incidents in 2025, up from 20.41 lakh in 2024.

None of that math treats offboarding as a niche concern. It treats identity, and the sloppy handling of it around departures, as the new perimeter.

What Actually Walks Out the Door With an Employee

Most exit checklists still read like they were built in 2012, when the biggest concern was returning a laptop and a proximity card. The modern departing employee sits inside a much larger attack surface, and each layer needs its own revocation path.

The categories worth mapping to a real offboarding process:

Asset CategoryWho Holds the TriggerCommon Failure at Exit
Endpoint devices (laptop, phone, tokens)IT asset managementDevice recovered, disk not wiped, cached credentials remain
SSO / Active Directory accountIT identity teamDisabled but not deleted, backdoor via legacy apps
SaaS accounts outside SSO (Notion, Figma, marketing tools)Function heads + ITOrphaned accounts, licences still billed, ex-employee still logged in
Email + calendar delegationsIT + ManagerForwarding rules and shared inbox access left intact
Cloud storage (Drive, OneDrive, S3)IT + ManagerPersonal-account copies, external share links never revoked
VPN, jump-hosts, developer keysIT securitySSH keys and API tokens not rotated after the person’s departure
Customer / CRM dataSales ops + ITBulk export in final week, no download audit review
Source code and IPEngineering + ITRepo access retained through personal GitHub, code cloned pre-exit

The Amadeus case is a textbook illustration of the last two rows. Source code moved from a corporate account to a personal Gmail. The company’s internal review caught it after the fact, not during the exfiltration itself. HR and IT working from a shared offboarding trigger, with data-loss monitoring wired into the notice period, would have shortened the detection window from weeks to hours. Breach-proofing employee records is the same problem in miniature: it depends on knowing exactly who can touch what, right now.

The Notice Period is a Risk Window, Not a Buffer

Indian notice periods are among the world’s longest. Two to three months is standard in IT services, professional services, and many BFSI roles. That’s a design feature for backfill and handover. It’s also a long window in which a departing employee has full access, unsupervised, to systems they no longer have any long-term stake in protecting.

Data-loss monitoring during notice periods is where most Indian companies leave the biggest gap. A three-month notice is roughly 60 working days of active credentials, of shared drive access, of downloadable customer lists, of code repository check-ins.

During this window, HR is running knowledge-transfer sessions, and IT is often still treating the employee as a fully trusted internal user. That mismatch is the entire risk. Companies revisiting how notice periods shape attrition and backfill planning in India also need to revisit what those same 60 days look like from an IT security dashboard.

Access needs to shrink on a schedule during the notice period, not fall off a cliff on the last working day. A tiered model works better: high-sensitivity systems (production databases, financial systems, source repositories) come off within the first week of resignation acceptance. Client-facing systems reduce in the middle third. Only email and internal collaboration tools stay live until the last day. The intent isn’t punitive. It’s a mirror of what’s already happening in the employee’s head.

A Coordinated HR-IT Exit Playbook

A workable offboarding playbook needs three things to hold together: a single trigger event, a defined split of responsibilities, and a closure sign-off that lives outside a spreadsheet. Every exit, resignation or termination should move through the same track with the same audit trail.

  1. Trigger (Day 0): HR logs the resignation or termination decision in the HRMS. That entry auto-notifies IT security, the reporting manager, and the SaaS-admin owners for every tool the employee has access to.
  2. Risk classification: IT tags the exit by risk band based on role, access level, and reason for exit. A privileged administrator leaving for a competitor is not the same file as a rotational trainee moving to higher studies.
  3. Access reduction schedule: IT publishes a per-system revocation calendar tied to the last working day. Manager confirms which systems the employee still genuinely needs for handover.
  4. Monitoring uplift: DLP alerts on unusual data movement (bulk downloads, personal-email transfers, USB writes, external share creation) are dialled up for the duration of the notice period.
  5. Knowledge handover, without artefact hoarding: The handover documents, credentials transfer, and system walkthroughs are logged. This is where reducing knowledge loss after a resignation and closing the security loop meet in one workflow.
  6. Last-working-day closeout: All SSO and non-SSO accounts disabled by end of shift. Devices collected and quarantined. Physical access revoked. SaaS licences released.
  7. T+30 audit: IT confirms zero active sessions, zero shared-drive orphan permissions, zero API keys still tied to the ex-employee’s identity. HR closes the file only after this confirmation.

The point of writing it this way is that no single team owns the whole thing, but every step has a name against it. Exits break when accountability is diffuse.

Where Indian Companies Are Getting This Wrong

Patterns from breach reviews and access audits across Indian mid-market and enterprise environments repeat with unsettling consistency. The problems are rarely exotic. They’re operational hygiene issues that have simply never made it onto anyone’s KRA.

  • Orphaned SaaS accounts: Tools bought by function heads outside IT (design software, analytics platforms, freemium collaboration tools) rarely feature in the master offboarding checklist. Licences keep billing, accounts stay live, ex-employees stay logged in for months.
  • Shared credentials that no one changes: Team-level logins for legacy dashboards, shared vendor portals, or internal wikis. When an employee leaves, the password does not.
  • Personal devices with corporate data: BYOD without a mobile-device-management wrapper means corporate email, chat history, and cached documents leave with the phone.
  • VPN and jump-host access that outlives the employment contract: Especially common in remote-heavy engineering teams where the offboarding process assumes a Delhi or Bangalore office return.
  • No offboarding calendar visible to IT: HR knows an exit is coming three months out. IT often finds out three days out, or later.

Each of these is fixable. None is fixed by memo. They are fixed by a single owned process, a shared calendar, and a habit of treating the last day as a security milestone.

In the End…

An employee exit is the moment the trust model breaks. It’s also the moment most Indian companies discover which of their systems were never designed to track who was inside them. Fixing that starts before the resignation letter arrives, with a joint HR-IT offboarding operating model that assumes shared ownership and shared visibility.

The companies getting this right in 2026 have three things in common. Their offboarding trigger is a single system event, not a Slack ping. Their access-revocation calendars are managed alongside the notice-period handover plan, not after it. Their T+30 audit is treated as the file-closure gate, not a nice-to-have.

HR teams that hand IT a genuine partnership on exits, and IT teams that treat HR as the source of truth on who is walking out the door, will spend less time explaining a breach to the Data Protection Board and more time on the work that actually retains talent.


FAQs


Why is employee offboarding a cybersecurity concern in India?

Departing employees leave live access across SSO, SaaS, email, cloud storage, and developer systems. If HR closes the file without a clean IT trigger, those entitlements stay open. India’s average breach cost hit ₹25.5 crore in 2026, and identity and access management is now a top-three post-breach investment priority.

What should an HR-IT employee offboarding checklist cover in India?

Endpoint devices, SSO and Active Directory accounts, SaaS tools outside SSO, email and calendar delegations, cloud storage shares, VPN and jump-host access, developer keys and API tokens, CRM data, and source code repositories. Each category needs a named owner and a revocation point tied to the last working day.

How should companies manage data access during the notice period?

Access should shrink on a schedule, not fall off a cliff on the last day. High-sensitivity systems come off within the first week of resignation acceptance, client-facing systems in the middle third, and only email stays live until the final day. DLP monitoring runs across the full window.

What is a T+30 offboarding audit?

A thirty-day post-exit review by IT security confirming zero active sessions, zero orphan drive permissions, and zero API keys still tied to the ex-employee’s identity. HR closes the employee file only after this audit returns clean, making it the file-closure gate rather than a nice-to-have.

Where do most Indian companies get offboarding security wrong?

Orphaned SaaS accounts bought outside IT, shared team credentials no one rotates on exit, BYOD devices without MDM, VPN access that outlives the contract in remote engineering teams, and IT learning about resignations three days before the last day instead of three months out.

Author
//
Kumari Shreya
Content Specialist Shreya delights in conveying her ideas and thoughts through her words. She enjoys exploring the different sides of the HR world and how the industry’s impact on the Indian population is increasing by the day. When not immersed in writing or researching for her writing, you can find her passionately discussing her favorite stories and learning more about the history of the world.
Show More
latest news

trending

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.

Tagged:

More of this topic

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.