When someone leaves with information.
WHAT TYPICALLY OCCURS
Files copied before departure Data forwarded to personal accounts Customer lists taken Access retained after leaving
WHAT TO ESTABLISH
What they had access to What they accessed in the period before leaving Whether anything was copied or transferred
WHAT TO EXAMINE
Unusual volumes of access or download Transfers to personal accounts or external services Connection of storage devices Printing volumes Email to personal addresses
WHY THE PERIOD BEFORE
Activity changes in the weeks before a planned departure.
WHAT TO ESTABLISH IN ADVANCE
Logging that would show this.
WHY
It cannot be reconstructed afterwards.
WHAT TO DO ON RESIGNATION IN SENSITIVE ROLES
Consider reviewing activity, proportionately and per your policies.
WHAT TO ESTABLISH
That any review is authorised and proportionate.
WHAT TO PRESERVE
Their device and account, before reassignment.
WHY
Reassigning a device destroys the evidence.
WHAT TO ESTABLISH
That devices of departing staff in sensitive roles are preserved for a period.
WHAT TO DO ABOUT ACCOUNTS
Disable rather than delete, initially.
WHY
Deletion removes the contents.
WHAT TO ESTABLISH ABOUT OBLIGATIONS
What their contract requires of them.
WHAT TO ADDRESS
Return of data and devices Confirmation that copies were destroyed Reminder of continuing obligations
WHAT TO DO IF DATA WAS TAKEN
Establish what, and take advice.
WHY ADVICE
Remedies exist but they are time-sensitive.