FREE forever · no login for checks and guides

Employee Onboarding & Exit Security Checklist

Accounts created with least privilege, 2FA on day one, the policy signed, shared passwords rotated on exit, access removed the same day — the two moments most data walks out.

Two moments decide whether an employee can walk out with your data: the day they join and the day they leave.

Day one

Own login for every system (no shared passwords); rights limited to the job; 2FA set up before the first login; the IT & social-media policy read and signed; company devices only for company data; shown how to report a suspicious message.

During

Quarterly access review (does this person still need this?); shared passwords in a manager, not in WhatsApp; no personal cloud drives for company files.

Exit day

Access removed the same day (e-mail, ERP, UPI / banking, social pages, cloud drives, CCTV app); every shared password rotated; company devices returned and wiped; 2FA moved to a new owner; a check of exports and posts from the last thirty days.

Checklist

  • ☐Own login + least privilege + 2FA on day one
  • ☐Policy signed
  • ☐Quarterly access review dated
  • ☐Exit: access removed same day
  • ☐Exit: shared passwords rotated
  • ☐Exit: devices returned and wiped
  • ☐Exit: last-30-day activity reviewed

Questions people ask

An employee left with the UPI / social logins.

Rotate every shared password today, remove their device from accounts, transfer 2FA, and check the transaction and post history since their last day.

Been hit and need a human?

Our team helps you draft, file and follow up with the bank and the cyber cell — leave your number for a free callback.

The Cyber Desk provides educational tools, checklists and self-help drafts — not legal advice. For serious or high-value fraud, also consult the police and a qualified lawyer.