Brian Sims
Editor
Brian Sims
Editor
IT’S NOT a new phenomenon, writes Fabian Winkels. Someone hands in their notice, works their last few weeks, clears their desk and walks out of the building for the final time. Everyone wishes them well. Then, quietly, nothing happens to their access. The e-mail account still works. The shared drive still opens. The app they used to check their rota still lets them in.
Weeks later, sometimes even months later, that account is still live, still trusted and still capable of pulling confidential information out of the business. It’s a security risk no-one notices.
Most of the time it’s not malicious. People keep an old login simply because it’s convenient or they never thought to mention it. “Everyone does it” is the mantra, but intent isn’t really the point. Whether someone walks off with a customer list deliberately or simply forgets they can still see it, the exposure is the same and the consequences land on the employer.
Those consequences are not trivial in terms of security risk. Under the Computer Misuse Act, using systems you’re no longer authorised to access is a criminal offence. The more serious variants of doing so carry years in prison.
For the organisation, there’s the prospect of regulatory fines, breach notification costs and the operational mess of not knowing who touched what and when. IBM’s most recent ‘Cost of a Data Breach’ report puts the average malicious insider breach at £3.69 million. It’s the most expensive attack vector it tracks. That’s the price of a door left open and not shut tight.
Plenty of enterprises have already worked this out. In a well-run corporate environment, the moment an employee’s contract ends, automated triggers fire.
Access is revoked, accounts are disabled and an audit trail is written showing exactly when the lights went out. Joiners, movers and leavers are handled as a process, not a favour.
It’s not perfect, but it’s a system. Systems scale, particularly for desk workers. However, it keeps going wrong for front line workers. Why?
Flawed assumption
Traditional Identity and Access Management was built on a quiet assumption that almost nobody says out loud: every employee has a company laptop and a personal corporate e-mail address.
Provisioning hangs off that e-mail. Single sign-on hangs off it. Deprovisioning hangs off it as well. Kill the mailbox and, in theory anyway, you kill the access.
For a deskless workforce, that assumption simply doesn’t hold true. The person stacking shelves, driving the van, working the ward or standing on the production line usually has no corporate e-mail address and no company laptop.
The tidy identity lifecycle that protects office staff was never built for them in the first place. Their access lives somewhere else entirely: on a personal phone, a WhatsApp group where shifts are swapped, a shared tablet in the back office or a password written on a laminated card by the till.
When identity is scattered across personal apps and informal channels, there’s no clean switch to throw when someone leaves. You cannot deprovision a WhatsApp group. You cannot revoke someone’s place in a chat where the rota lives. The information keeps flowing to a smart phone that now belongs to a former employee and nobody can see that it’s happening.
Retail: the uncomfortable truth
Retail is where this becomes uncomfortable on the fastest timescale. Walk into most shops and you will find Point-of-Sale terminals logged in with a shared account that the whole shift uses.
It’s understandable. Nobody wants a queue building while each colleague types a password. That convenience runs straight into PCI DSS, which requires a unique ID for every individual who touches the cardholder environment precisely so that actions can be traced to an individual. A shared till login makes that impossible.
The situation worsens. As the login’s shared, nobody wants to change the password. Changing it means retraining everyone on the shift. Credentials sit unrotated for weeks, known to every person who has passed through, including the ones who’ve since left.
Add a seasonal peak, where a store might churn through dozens of temporary staff in a matter of weeks, and the list of people who know that password quietly becomes impossible to count. When something goes wrong, there’s no way to pinpoint who did it. The audit trail is a shrug.
Manual deprovisioning trap
The instinct in a lot of front line organisations is to treat all of this as a minor operational nuisance rather than a security problem. A manager makes a mental note to remove someone’s access ‘at some point’.
That gap between someone’s last shift and someone remembering to close their account is the single most dangerous window in the whole employee lifecycle, and it’s almost always managed by hand.
Manual deprovisioning fails for the most human reasons. The manager is busy. The leaver was a contractor nobody formally owned. The account was created in a hurry and never documented.
Multiply that scenario across hundreds of sites and thousands of seasonal workers and the maths stops working. You’re relying on a person to remember to do a security-critical task, on time, every time, with no reminder and no consequence if they forget. That’s not control. It’s hope.
Closing the gap
The good news is that none of this is exotic to fix. The same discipline that protects office workers can be extended to the front line, while a surprising amount of it isn’t even technical.
On the technical side, the goals are simple:
*bring front line identity into the same managed system as everyone else so that a leaver is a leaver everywhere at once
*deprovisioning should be automatic and tied to the moment employment ends, not to a manager’s memory
*access should be centralised in a mobile employee app (also accessible via desktop) rather than sprinkled across personal apps
*shared and privileged accounts – where they genuinely cannot be avoided – need enforced rotation rules so that a departure forces a change of credentials instead of leaving old ones live
The non-technical safeguards matter just as much, and they cost far less:
*run structured exit interviews that explicitly cover what someone can still access and what they need to hand back
*have people sign non-disclosure agreements at hiring when they’re motivated to join, rather than chasing a signature on the way out when the relationship is already over
*build a culture of data ownership across the whole time someone is employed so that protecting company information is a normal habit rather than a box ticked on the final day
First moment and the last
We pour enormous effort into the first moment of work: onboarding people, ‘badging’ them and making sure they’re productive. We spend far less on the last moment of work.
The day someone leaves is a security event, not an HR formality, and on the front line it’s the event we are the worst at handling. The organisations that take this seriously are not doing anything heroic. They have simply decided that the leaver deserves the same rigour in terms of attention to detail as the joiner. What’s more, they’ve built the plumbing to make it automatic.
Your leavers have gone. The question every organisation should be able to answer, quickly and with evidence, is whether their access went with them.
Most cannot. That’s the gap worth closing.
Dr Fabian Winkels is Senior Vice-President of Strategy and Growth at Flip (www.getflip.com)