HR one of biggest culprits in allowing ex-employees access to network

-

shutterstock_86123638

Organisations in the UK and the US are neglecting to deploy vigilant post termination processes, allowing ex-employees continued access to systems and data after they have left their position, research from security software provider IS Decisions has revealed. Over a third (36%) of desk-based workers in the UK and the US are aware of having had access to a former employer’s systems or data after having left the organisation.

This finding, explored in IS Decisions new report ‘From Brutus to Snowden: a study of insider threat personas’, potentially highlights an even bigger problem, as an even greater number of ex-employees may still have access to data without even realising it.

Age groups

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

It also differs wildly across age groups, with a much larger 58% of 16 to 24 year olds and 48% of 25 to 34 year olds stating awareness of having had continued access to a former employer’s systems or data. This continues to decrease for older age groups, averaging just 21% for those aged over 55, which could be attributed to younger age groups moving jobs more frequently, but does suggest that the issue is a growing one.

Acting on access

Of the 36% that were aware of their continued access, 9% actually chose to use it, meaning nearly one in 10 ex-employees access systems or data from their former employers. Once again, this tended to be higher for younger age groups, averaging 13% for all those aged 16 up to 34.

Industry sectors

The worst industry sectors for allowing their ex-employees to continue to access systems are surprising, with HR and recruitment and IT being the joint top, along with arts and culture at 46%. This suggests that those industries that should know better, are in fact worse than the rest.

Job roles

The most likely job role for an ex-employee with continued systems or data access to have is marketing, with a huge 68% of this sample stating this was the case. The next highest is potentially even more worrying, with 56% of those handling sensitive company data working in legal roles continuing to have access after leaving an employer.

François Amigorena, CEO of IS Decisions, said, “As the number of disparate systems and networks we use in our every day working lives increases, it’s natural that access management is becoming a more difficult problem to address for organisations. Marketing departments apparently suffer from this worst of all; between email, social media, CRM systems and everything else there is a lot to cover.

“The fact is though, that an ex-employee is more likely to have incentive than anyone to put this access to malicious use. Former employees are probably the greatest insider threat, yet they are the easiest to address; just make changing passwords and deactivating accounts a part of the termination process. Yet businesses are failing to do this, and worse still businesses in the industries you would most expect this to be standard procedure, IT and HR, are failing even more than the rest.”

Download From Brutus to Snowden: a study of insider threat personas.

Latest news

Curtis Holmes: Payroll is the driver for employee engagement

Payroll has long been treated as a back-office necessity: essential, but not something that shapes culture or drives engagement. This no longer stands.

Labour market yet to show major AI impact on jobs, govt adviser says

A government economic adviser has challenged predictions of widespread AI-driven unemployment, arguing labour market data has yet to show disruption.

Young workers ‘pressured into signing NDAs after workplace injuries’

Workers say injuries are being hidden behind confidentiality agreements while financial pressures leave many afraid to challenge unsafe conditions.

CIPD recognises 30 HR leaders driving change across UK workplaces

The CIPD has unveiled its HR30 list for 2026, recognising senior people leaders whose work has delivered measurable impact across organisations and workforces.
- Advertisement -

Brits dream of being their own boss, but still cling to the monthly pay cheque, survey reveals

Britons say they like the idea of self-employment, but most still value the security and stability of traditional jobs.

AI Coaching Won’t Replace Managers. It Will Expose Coaching Debt.

As AI coaching expands, employers may gain a clearer view of where manager support is falling short.

Must read

David Freedman: Improving sales performance – tools that really work

There is no substitute for training, and managed behaviour...

David Hilton: Will AI remove the human from recognition?

Employee recognition is one of the last purely human experiences at work. However, some fear that AI is taking over the realm of employee appreciation...
- Advertisement -

You might also likeRELATED
Recommended to you