Ex-employee still has access to your systems? Here is why that fails Cyber Essentials
Removing access immediately when staff leave is a Cyber Essentials requirement, and forgotten logins are one of the most common gaps assessors find.
Here's a scenario that plays out often enough to be a pattern, not a one-off: a business discovers, eight months after a member of staff left, that their old login to the booking system was never removed. Nobody used it maliciously. It simply sat there, active, because offboarding meant collecting the laptop and changing the till code, not auditing every system that person ever had a login for. When the business eventually checks properly, three more former staff still have live access to systems they left months or years earlier.
Cyber Essentials asks this directly: do you remove access immediately when staff leave? It's a CE3 User Access Control question, and it's one of the easiest to fail, not because removing access is hard, but because nobody has a single list of everywhere access needs removing from.
Why this is a real and ongoing risk, not a formality
Every account a former employee still has access to is a door that's no longer being watched by anyone with a reason to keep it secure. They're not checking for suspicious activity on it. They're not updating its password. If that account is compromised after they've left, whether through a breach at an unrelated service where they reused the same password, or simply because the credentials are old and weak, nobody notices, because nobody's looking.
There's also a more direct risk: a departure that ends badly. Most leavers are not a threat, but the businesses that get burned by this are the ones where a difficult exit met an account nobody remembered to remove, and the two combined into actual damage, whether that's data taken, customers contacted, or systems altered out of spite.
Why "immediately" is the actual requirement
Cyber Essentials doesn't ask whether you eventually remove access. It asks whether you remove it immediately. The distinction matters because the gap between someone leaving and their access being revoked is exactly the window where risk is highest, both from the departing person and from anyone who might exploit lingering credentials before IT gets round to a cleanup that wasn't scheduled with any urgency.
This connects directly to having admin accounts properly separated in the first place, since a clear account structure makes a leaver's access far easier to identify and remove completely, rather than discovering months later that they also had standing access to something nobody thought to check.
Building a process that actually works
The fix isn't a one-off cleanup, it's a checklist used every time someone leaves, covering every system they might have had access to: email, cloud storage, accounting software, the CRM, any shared logins, building access systems, and anything tied to a personal device they used for work. Maintaining a central list of who has access to what, even a simple spreadsheet, makes this checklist possible to run quickly rather than relying on memory.
Where a platform supports it, set offboarding to happen on the employee's last working day, not whenever HR gets round to filing the paperwork. For shared or generic logins that can't be tied to one individual and disabled cleanly, this is also the moment to ask whether that shared login should exist at all, since it's exactly the kind of access that's hardest to audit when someone leaves.
Frequently asked questions
What counts as "immediately" for Cyber Essentials purposes? There's no exact hour-by-hour definition, but the expectation is access is removed on or very close to the employee's last working day, not weeks later as part of a routine cleanup.
Does this apply to contractors and freelancers too, not just employees? Yes, anyone with access to your systems, whether employed directly or working as a contractor, should have that access removed when their engagement ends.
What if someone used a personal device for work and we can't remotely wipe it? Focus on revoking their account-level access to company systems and data, which prevents continued access regardless of which device they're using.
How do we keep track of every system someone has access to, especially in a small business with lots of separate tools? A simple shared document listing each system and who has access works for most small businesses; the goal is having one place to check, not a complex piece of software.
Will an assessor ask for proof of a specific offboarding process? Assessors may ask how you handle this in practice and could request evidence of a recent example, so having even a basic documented process helps.
Run a free scan of your domain and your CE Readiness checklist will cover this alongside the rest of CE3 User Access Control, ready before your assessor asks: olimpio.io/free-scan