Access debt compounds
Most organisations we assess have more active accounts than employees. Every unclosed account is a credential waiting to be phished or brute-forced, and it will not show up in a payroll reconciliation.
The fix is procedural: onboarding and offboarding are mirror images, and both are checklists with named owners and evidence.
Teach three things well
Skip the annual hour-long module. New starters need to reliably do three things: verify payment and banking changes by phone, report a suspicious message in one click, and never reuse a work password.
The checklist
Day 1 provisioning
- Account created from a role template, not by copying an existing user
- MFA registered in person or via verified enrolment
- Device enrolled in management with disk encryption confirmed
- Password manager provisioned and demonstrated
Week 1 education
- Payment and banking change verification procedure walked through
- One-click phishing report button demonstrated
- Acceptable use and data handling policy acknowledged
- Incident reporting contact saved to phone
Ongoing
- Access reviewed at 90 days and on every role change
- Simulated phishing included from month 2
- Privileged access requested separately and time-bound
Offboarding mirror
- All sessions and tokens revoked, not just password reset
- MFA methods removed and device wiped or returned
- Mailbox delegated or converted to shared per retention policy
- SaaS applications outside SSO manually deprovisioned