Two moments decide whether an employee can walk out with your data: the day they join and the day they leave.
Day one
Own login for every system (no shared passwords); rights limited to the job; 2FA set up before the first login; the IT & social-media policy read and signed; company devices only for company data; shown how to report a suspicious message.
During
Quarterly access review (does this person still need this?); shared passwords in a manager, not in WhatsApp; no personal cloud drives for company files.
Exit day
Access removed the same day (e-mail, ERP, UPI / banking, social pages, cloud drives, CCTV app); every shared password rotated; company devices returned and wiped; 2FA moved to a new owner; a check of exports and posts from the last thirty days.
Checklist
- ☐Own login + least privilege + 2FA on day one
- ☐Policy signed
- ☐Quarterly access review dated
- ☐Exit: access removed same day
- ☐Exit: shared passwords rotated
- ☐Exit: devices returned and wiped
- ☐Exit: last-30-day activity reviewed