Interested in our Cybersecurity Framework?
Strengthen Your User Lifecycle Management
Need Strategic IT Leadership Without a Full-Time Hire?
By the time an employee resigns, the success or failure of their offboarding has already been determined.
This matters because cybersecurity and data exposure risk is not theoretical. 43% of UK businesses report experiencing a cybersecurity breach or attack in the last 12 months. For medium-sized organisations, that figure increases to 65%, highlighting the elevated exposure for businesses in the 30–400 user range.
In many organisations, onboarding decisions are made quickly; a shared login is introduced, a SaaS tool is set up independently, or a personal device is used temporarily. Over time, these become embedded practices.
When an employee leaves, these decisions resurface as operational and governance issues.
Why Poor Onboarding Increases Offboarding Risk in UK Organisations
In a well-governed environment, offboarding is controlled and predictable.
However, many organisations experience prolonged offboarding because they lack visibility of:
- SaaS tools and subscriptions
- User access and credentials
- Device ownership and security controls
This lack of visibility is reflected in broader UK trends. Nearly 90% of UK IT administrators report concern about unauthorised apps and devices expanding their attack surface.
Additionally, phishing – the most common attack type – accounts for 84% of breaches affecting UK businesses. Many of these attacks exploit poor access control and credential management, both of which originate in onboarding.
Four Onboarding Practices That Create Offboarding Risk
1. Uncontrolled SaaS Sign-Ups
When employees independently create accounts, organisations lose visibility and control.
This is increasingly common. UK SMEs typically operate between 12 and 18 SaaS tools, with around 40% underutilised or unused.
Risk:
- Unknown systems storing company or client data
- Inability to revoke access centrally
- Ongoing financial waste
2. Use of Unmanaged Personal Devices
Personal devices often become permanent without appropriate controls.
This introduces measurable risk. 57% of businesses report that securing devices outside the office is now more difficult, and 46% say personal devices undermine their security strategy.
Risk:
- No control over company data post-departure
- Increased likelihood of data exposure
- Potential non-compliance with UK GDPR
3. Shared Logins and Weak Credential Practices
Shared credentials create systemic access risks.
At a broader level, credential misuse is widespread. Up to 80% of UK users reuse passwords across accounts, increasing the likelihood of credential compromise.
Risk:
- Inability to remove access for individual users
- Lack of accountability in audit trails
- Elevated exposure to phishing and credential-based attacks
4. Client Relationships Managed in Individual Mailboxes
Client communication stored in individual inboxes creates continuity risk.
This is particularly relevant in professional services environments, where operational knowledge is concentrated in individuals.
Risk:
- Loss of critical client context
- Disruption to service delivery
- Reduced organisational resilience
How to Strengthen Your Current Environment
Conduct a SaaS Audit
Most organisations underestimate their software footprint.
Research indicates 30–50% of SaaS licences are unused, representing both cost and security risk.
Create a Device Register
Unmanaged devices significantly increase exposure.
Without visibility and control, organisations cannot effectively enforce data protection standards or respond to incidents.
Move Client Communication to Shared Systems
Ensure client relationships are owned by the organisation.
Structured communication improves resilience and continuity during staff transitions.
The Role of Your IT Provider in Onboarding
IT providers should not only be engaged at the point of offboarding.
A governance-led approach requires involvement at onboarding to:
- Provision identity and access centrally
- Apply single sign-on (SSO)
- Enrol and secure devices
- Establish access and documentation standards
Without this, organisations inherit unnecessary risk across the employee lifecycle.