Someone resigned last month. HR processed the paperwork, collected the laptop, and organised the farewell morning tea. Three weeks later, their email account still works. They can still log into the client database. The shared password for your accounting software? Nobody thought to change it.

This happens in businesses across Australia every single day. Not through malice or negligence, but because offboarding rarely gets the same attention as onboarding. The result is a growing number of "ghost employees," people who no longer work for you but can still access your systems. Building better internal systems around this blind spot is one of the simplest ways to reduce your cyber risk.

Why Ghost Employees Are a Bigger Problem Than You Think

Most business owners assume that when someone leaves, their access disappears with them. The reality is messier.

Consider what a typical departing employee has access to: email, cloud storage, accounting software, CRM, project management tools, social media accounts, and whatever shared logins the team uses for various platforms. Each of these requires a separate action to remove access. Miss one, and you've left a door unlocked.

The risks fall into three categories:

  • Deliberate data theft. A departing employee, especially one leaving on bad terms, might download client lists, financial records, or internal business information in their final days. They still have full access, and nobody is watching more closely than usual.
  • Stolen login details. If a former employee's login remains active and those credentials get compromised (through a phishing attack or a data breach at another service), attackers have a ready-made entry point into your systems.
  • Shared password exposure. When teams share logins for platforms and someone leaves, that password doesn't expire with their employment. Unless you change it immediately, anyone who knows it retains access indefinitely.

Under the Notifiable Data Breaches scheme, Australian businesses covered by the Privacy Act (typically those with an annual turnover of more than $3 million) must report 'eligible data breaches' that are likely to result in serious harm. A ghost employee accessing client data after departure could trigger reporting obligations and reputational damage.

Building Better Internal Systems Around Departures

The fix isn't complicated, but it does require a deliberate process. Good internal systems mean having processes that capture and act on information about your business operations. For offboarding, this translates to a simple checklist that gets followed every time someone leaves.

Your offboarding checklist should include:

  • Disable email account within 24 hours of departure
  • Remove access to cloud storage (Google Drive, Dropbox, OneDrive)
  • Remove from accounting and financial software
  • Update all shared passwords the person knew
  • Remove from project management and communication tools (Slack, Teams, Asana)
  • Remove access to CRM and client databases
  • Remove from social media account access
  • Collect and wipe any personal devices used for work
  • Forward their email to an appropriate team member for 30 days

The checklist itself takes five minutes to create. The discipline to use it consistently is what separates secure businesses from vulnerable ones.

The Shared Password Problem

Shared passwords deserve special attention because they're the hardest to manage and the easiest to forget.

Many small businesses share logins for tools like Canva, social media scheduling platforms, industry-specific software, or even bank accounts. When someone leaves, you need to change every shared password they knew. This is tedious, which is why it often doesn't happen.

A better approach: use a password manager that lets you share access without revealing the actual password. When someone leaves, you remove their access in the password manager. The underlying credentials stay intact, and you don't need to update logins across a dozen platforms.

If a password manager feels like overkill for your business, at minimum keep a list of every shared login. When someone departs, work through that list systematically. It's not glamorous, but it works.

Cyber Security Education for Your Remaining Team

Ghost employees create risk, but so do the staff who remain. When someone leaves, their colleagues often retain information that should disappear with them: shared passwords written on sticky notes, login details shared in old chat messages, or access credentials stored in shared documents.

This is where ongoing cyber security education matters. Your team needs to understand that security hygiene isn't just about protecting against external threats. It's about managing internal changes too.

Regular phishing simulations help here in unexpected ways. Beyond testing whether staff click suspicious links, they keep security awareness present in daily work. A team that's alert to phishing attempts is also more likely to think twice before sharing passwords or leaving access credentials lying around. The onboarding process should include clear guidance on password handling and what happens when colleagues leave.

Compliance Reporting and Documentation

If your business handles client data (and most professional services firms do), you likely have compliance obligations around access management. Accountants, lawyers, and healthcare providers face particular scrutiny.

Good compliance reporting requires documentation. You need to show that access was removed, when it happened, and who was responsible. This doesn't require expensive software. A simple spreadsheet tracking departures, the date access was removed, and sign-off from whoever completed the checklist creates an audit trail.

For businesses with cyber insurance, this documentation matters. Insurers increasingly ask about access management practices. Being able to demonstrate a consistent offboarding process strengthens your position if you ever need to make a claim. The requirements for cyber insurance often include proof of security awareness training and access controls.

Making It Automatic

The businesses that handle this well don't rely on memory or goodwill. They build triggers into their existing processes.

When HR processes a resignation, the offboarding checklist automatically goes to whoever handles IT (even if that's just the office manager). The checklist has deadlines. Someone is accountable for completion. This isn't bureaucracy for its own sake. It's making sure the job gets done when everyone is busy with their regular work.

For phishing awareness, the same principle applies. Manual, one-off training sessions get forgotten or deprioritised. Automated systems that send regular simulations and assign training to those who need it keep security awareness consistent without requiring constant attention from management.

Start With What You Can Control

You can't prevent staff turnover. You can control what happens to system access when people leave.

This week, make a list of every system and platform your business uses that requires a login. Note which ones have shared passwords. Create your offboarding checklist. Assign someone to be responsible for it.

Then look at your current staff. Are they alert to phishing attempts? Would they recognise a suspicious email from a "former colleague" asking for login details? If you're not sure, test them.

Sign up for a free trial and send yourself a test phishing email. See how realistic modern phishing attempts look. Then decide whether your team needs regular practice spotting them. The ghost employees in your system are invisible until something goes wrong. The training gaps in your team are just as hidden, but much easier to fix.