The tolerated pain
Access is often created across SaaS tools, cloud platforms, shared mailboxes, VPNs, devices and vendor portals over months or years. A single HR departure event does not automatically revoke all of it.
Operational consequence
The organisation loses confidence in who can reach sensitive systems and data. Investigations, audits and incident response become slower because account ownership is uncertain.
How it becomes money
The immediate cost may be licence waste, but the larger exposure is conditional: an orphaned account can create investigation, containment, recovery, legal or customer-service costs if it is misused or compromised. Do not invent a generic breach value; measure the systems, privileges and data actually exposed.
Resolution
- Maintain a current inventory of identity-bearing systems.
- Trigger offboarding from an authoritative employment event.
- Revoke identity, sessions, tokens and shared-secret access.
- Recover or secure business devices.
- Transfer ownership of files, workflows and service accounts.
- Verify completion and preserve evidence.
Bottom line
Offboarding should end access as deliberately as onboarding creates it. Anything less leaves a control gap that becomes more expensive to reconstruct later.