The post has been translated automatically. Original language: Russian
Offboarding as an information security threat
When they think about information security, they imagine hackers and viruses. But in fact, one of the most frequent sources of leaks is the usual dismissal of an employee, where access was closed "when they got their hands on it."
Why is this happening
- Access rights are revoked not on the day of dismissal, but after a week or two, because HR and IT do not work synchronously.
- They forget not only mail, but also shared folders, CRM, messengers, VPN, access to the company's social networks.
- If the dismissal is in conflict, there is a risk that the employee will "take with him" the customer base while access is still active.
How it should be
- HR notifies IT in writing about the date of dismissal in advance, not after the fact.
- On the last working day, all accesses are closed: mail, CRM, cloud, VPN, messengers — synchronously with the departure of the person, and not "during the week".
- A laptop, flash drives, and a pass are seized; it is checked whether mail forwarding to a personal mailbox is configured.
- An audit is being conducted to determine if the employee has remained an administrator somewhere else (advertising, analytics, domain).
The main thing Onboarding in companies has been perfected to the point of automatism, and offboarding often exists only on paper. This is HR's responsibility no less than IT is HR who finds out the date of dismissal first and should be the initiator of the process, not the observer.
Offboarding как угроза ИБ
Когда думают про инфобезопасность, представляют хакеров и вирусы. А на деле один из самых частых источников утечек обычное увольнение сотрудника, где доступы закрыли «когда руки дошли».
Почему так происходит
- Доступы отзываются не в день увольнения, а через неделю-две — потому что HR и IT работают несинхронно.
- Забывают не только почту, но и общие папки, CRM, мессенджеры, VPN, доступ к соцсетям компании.
- Если увольнение конфликтное — риск, что сотрудник «прихватит с собой» базу клиентов, пока доступ ещё активен.
Как должно быть
- HR письменно уведомляет IT о дате увольнения заранее, а не постфактум.
- В последний рабочий день закрываются все доступы: почта, CRM, облако, VPN, мессенджеры — синхронно с уходом человека, а не «на неделе».
- Изымаются ноутбук, флешки, пропуск; проверяется, не настроена ли пересылка почты на личный ящик.
- Проводится аудит: не остался ли сотрудник администратором где-то ещё (реклама, аналитика, домен).
Главное Onboarding в компаниях отработан до автоматизма, а offboarding часто существует только на бумаге. Это ответственность HR не меньше, чем IT именно HR первым узнаёт дату увольнения и должен быть инициатором процесса, а не наблюдателем.