Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What is post-employment access?

Post-employment access is use of organisational data or systems after the authorised relationship ends. A later login does not automatically identify the former employee, and later possession may not require a new login.

Align offboarding with technical lifecycle

Preserve the employment end time, required revocation, accounts, tokens, applications, devices and sessions that actually remained active. Then identify authentication source, device and resulting activity.

Offboarding failure establishes opportunity, not personal use. Shared identities, automation and other users may explain activity, while the former employee may knowingly exploit access left open.

Consider earlier copies and synchronisation

Organisational data may remain on personal devices or cloud accounts through earlier downloads or sync. Examine pre-departure removable media, uploads, sharing and client configuration.

Later availability can reflect earlier authorised setup, earlier unauthorised copying or a continuing token. Distinguish those routes before concluding post-departure system access.

Key takeaway

Compare the relationship end with actual account, token, device and data-copy lifecycles, then prove who used any surviving access.

Reference: CIM-241Cyber Incidents & Offender Methods