Onboarding and Offboarding: The IT Security Risks

Posted on Oct 2, 2026 in Security

Laptop displaying 'Cyber Security' text on screen in a modern office setting

Image: cottonbro studio via Pexels

Every organisation thinks carefully about cybersecurity threats from the outside — phishing emails, ransomware, dodgy links. But two of the most significant security risk points sit much closer to home: the day someone joins your team, and the day they leave it.

Getting onboarding and offboarding right isn’t just good HR practice. It’s a fundamental part of keeping your systems, your data, and your clients safe.

The Risks When Someone Arrives

When a new staff member starts, there’s understandable pressure to get them productive quickly. Accounts get created, access gets granted, and sometimes the proper checks get skipped or delayed. This creates a few common problems:

  • Over-provisioning: New starters are given broader access than their role actually requires, often because it’s easier than scoping permissions carefully.
  • Inadequate vetting: Background checks and reference verification are sometimes rushed or skipped entirely, particularly for contractors or short-term staff.
  • Weak credential setup: Temporary passwords aren’t changed, multi-factor authentication isn’t enforced from day one, or accounts are shared to “get them started.”

A case that illustrated this vividly came to light in May 2026, when a US federal jury convicted former IT contractor Sohaib Akhter for conspiring to delete approximately 96 government databases. The case exposed serious vetting failures — both Akhter and his brother had prior federal convictions for hacking, yet were rehired into privileged IT roles across more than 45 federal agencies. The damage they were ultimately able to cause was a direct consequence of failures at both ends of the employment lifecycle.

While that’s an extreme example from a large government context, the underlying vulnerabilities are just as relevant to a Wellington law firm, a health provider, or a not-for-profit managing sensitive client data.

The Risks When Someone Leaves

Offboarding is arguably where things go wrong most often. In the busyness of someone’s last day, access revocation can fall through the cracks — sometimes for weeks or months. That means a former employee or contractor may still be able to log in to your systems, access client files, or read confidential communications long after their last day.

This isn’t always malicious. Sometimes it’s simply an oversight. But the exposure is real either way. Disgruntled departures, of course, carry a higher risk — and in the Akhter case, the database deletions happened within hours of termination, because access had not been fully revoked at the moment of separation.

Building a Safer Process

The good news is that sound onboarding and offboarding procedures aren’t complicated — they just need to be consistent. A few practical steps make a significant difference:

  • Apply the principle of least privilege — grant only the access each person genuinely needs for their role, and review it regularly.
  • Make access revocation immediate on the day someone leaves, not something that happens when IT gets around to it.
  • Conduct proper background checks before granting privileged access, including for contractors.
  • Enforce multi-factor authentication from the very first login.
  • Maintain a clear register of accounts and access levels so nothing gets forgotten.

The NCSC’s guidance for New Zealand organisations is a helpful starting point for thinking about access controls and security baselines across your workforce.

If you’d like a hand reviewing your onboarding and offboarding processes — or just want to make sure nothing is slipping through the cracks — our team is always happy to help.

Simon Falconer
Director, Resolve Technology

When he’s not finding a reason to buy the latest gadget, Simon is probably setting it up, breaking it, and fixing it again — all before breakfast.

Need help with this?

Resolve Technology can help. Learn more about our Cyber Security Services services, or get in touch to discuss your needs.

Leave a Reply