ClearSecurity VISION
EN / RO
← All articles

Operations · 27 August 2026 · 7 min read

Digital mishaps #4: The employee who left with the keys

Your best salesperson joins a competitor — and soon your clients start getting counter-offers that are suspiciously well aimed. Episode 4, where the decisions are yours to make.

ClearSecurity Vision

Episode 4 of “Digital mishaps” — short stories about the bad days of companies where security is “something we’ll do next year”. This one works differently: at three key moments, the decision is yours — pick an option and see what follows.

A story composed from real situations seen in practice. The company in the text does not exist.

The story

Monday, 9:20. At a distribution company with 45 employees, Andrei — the salesperson who brings in a third of the revenue — walks into the director’s office with a folder under his arm: “I’ve signed with someone else. My notice period starts today.” Someone else, meaning the main competitor.

The director takes the hit, they shake hands, they part on good terms. Andrei has 20 working days left. He has a laptop, a company phone, email, access to the system holding clients and offers — everything that made him the best.

You are the director. What do you do about Andrei's access during the 20-day notice period?

A. Nothing. He still has work to do and we're parting on good terms — we'll cut everything on his last day.

That's what the director in the story did. The "last day" came, the laptop was handed in — but nobody ever wrote down what Andrei actually had: which accounts, which shared passwords he knew, which devices received his email. You can't cut what you don't know exists.

B. Cut all his access today. Better upset than robbed.

Safe from a technical point of view, but 20 days in which your best salesperson can't work costs real money — and turns a civilised parting into a conflict. There is a middle path, and it starts with a list.

C. Today I make the inventory: which accounts he has, which shared passwords he knows, which devices get his email. Then I decide what gets cut now and what at departure.

That's the right move — and it takes an hour. That list is the difference between "we took his laptop back" and "we closed every door". In the story, the list never existed. Note two details for later: shared passwords and personal devices.

The notice period passes quietly. On the last Friday, Andrei hands in the laptop and phone, signs the HR paperwork, hugs, cake. IT disables his email account on Monday morning. Everyone is under the impression that everything that needed doing was done.

Except the sales team had been using a shared password for the clients-and-offers system for years — the same one for everybody, “because it’s simpler”. Andrei knows it by heart. Nobody thought to change it: after all, it wasn’t his password.

The shared password for the client system. What do you do with it on departure day?

A. Leave it. It's the team's password, not Andrei's — and everyone depends on it.

Exactly what happened in the story. A shared password belongs, in practice, to everyone who has ever known it — including people who no longer work for you. From the moment he walks out, "the team's password" is also the competitor's password.

B. Change it on departure day — and ask: where else do we have shared passwords?

Yes. And the second half of the question is the valuable one: where there is one shared password, there are usually five. The day someone leaves is the day you change every one they knew — from a list, not from memory.

C. He signed a confidentiality agreement on the way out. We're covered.

Paper helps after the damage, in court. It doesn't stop a single login. And to win in court you need to prove who logged in and when — which, with a password used by seven people, is close to impossible.

Three weeks later, the first signs: two long-standing clients announce they are “reorienting”. The competitor’s offer had arrived at exactly the right moment — priced just under the quotes that hadn’t even been published yet, sent to clients for signature a week earlier. Coincidence once, coincidence twice. When the third client is lost the same way, the director calls a meeting.

Your unpublished offers are somehow reaching the competition. What's the first step?

A. Call the lawyer. Andrei is clearly stealing our clients.

Understandable, but premature: the lawyer's first question will be "what evidence do we have?" — and you have none yet. Worse, the leak stays open while you build the case.

B. Check the logs first: who accessed the offers system, when, from where. Close what I find, preserve the evidence, then call the lawyer.

The right order: stop the leak, preserve the evidence, then escalate. In the story, the logs showed evening logins with the shared password from an address that belonged to nobody in the company — plus one more surprise, coming right up.

C. Quietly change all the passwords and move on. A scandal costs more than the lost clients.

You stop the leak — good. But without looking at the logs you don't know what leaked or since when, so you can neither prevent the next departure from ending the same way nor defend yourself if things escalate. And if personal client data leaked too, you may have legal notification duties that "quietly" doesn't cover.

The check took one afternoon and found two open doors. The first: the shared password, used from an unknown address, in the evenings, after hours. The second — the one that hurt: a forwarding rule in Andrei’s email account, set up two weeks before his departure, silently sending a copy of every message to a personal address. The account was disabled on Monday, as we said. But the rule had worked through the entire notice period — including the week the offers went out.

What went wrong

The departure was treated as a day, not a process. “Hand in the laptop and we’re done” covers the objects, not the access. Without the inventory from day one — accounts, shared passwords, devices, forwarding rules — the company closed one door out of five.

The shared password outlived the person. Personal accounts are closed with one click; shared passwords have to be changed, and that requires knowing they exist and who knew them. “It’s the team’s password” meant, in practice, “it’s the password of anyone who ever passed through the team”.

Nobody looked at the logs until the damage appeared. The email forwarding rule had been visible in the settings since the day it was created. One person checking “what rules does this account have?” at every departure would have found it in two minutes.

3 things to do tomorrow morning

  1. A departure checklist — one page, not a project. Accounts to close, shared passwords to change, forwarding rules to check, personal devices with company email. Filled in on the day notice is given, ticked off on the last day, signed by two people. Under NIS2, controlling access at departure isn’t optional — it’s among the minimum measures.
  2. Hunt down shared passwords. Ask the team today: “which systems have one password for several people?” Every answer is a door that stays open after every departure. Where possible, individual accounts for everyone; where not yet possible, the password changes at every departure.
  3. Two minutes in the email settings at every departure. Forwarding rules, delegations, access from personal devices. They are the quietest ways data keeps flowing after the person has walked out the door.

The short moral

Andrei didn’t “hack” anything: he walked through doors the company left open after he’d gone. A departure process isn’t about distrusting the person leaving — it’s about knowing, at any moment, who can enter your house. And that takes a one-page list, not a whole department.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.