The most dangerous employee in your organization is not the one who failed the background check. It is the one who has already handed in a resignation letter.
In 2016, a senior engineer left Google's self-driving car project to start his own company. His name was Anthony Levandowski. In the months before he left, he downloaded around 14,000 technical files from the company's servers. The rest is well known: a massive lawsuit between Waymo and Uber, a settlement worth hundreds of millions of dollars, and a criminal conviction for trade secret theft. All of this happened at a company with one of the most sophisticated security operations in the world.
Most organizations treat a resignation as an HR event: a letter, a conversation, a handover, cake on the last day.
In practice, from the moment an employee gives notice, and sometimes earlier, while the decision is still taking shape in their head, the equation has changed: their access to systems remains full, but their commitment is already at their next job.
This window, between the notice and the last day, is the highest-risk period in the entire employment cycle. And it is not only about dramatic theft. It also looks like this: copying a client list for personal use. Sending pricing documents to a private email address to keep work samples. Photographing methodologies the employee wrote themselves and therefore assumes are theirs. And sometimes with no bad intent at all: a cloud account left open for months after the departure, because nobody knew it existed.
The organizational problem is easy to state: HR knows first, the security manager hears last, and IT cuts off access on the last day. Nobody owns the window itself.
Here is how to close it. Six steps:
1. The day of notice is the day of reporting. A resignation letter reaches the security officer and IT the same day. Not at the end of the week, not once a date has been set.
2. Immediate access mapping. Which systems, databases and folders the employee can reach, and which of them are especially sensitive given where they are going.
3. Gradual reduction. Anything not required for the handover is closed now, not on the last day.
4. Monitoring the window. Unusually large downloads, transfers to a private email address, connection of portable devices. During the window this is not suspicion, it is the best-known point of exposure.
5. Tasks for the last day. A closed list of accounts to shut down, including cloud systems and external vendors that are not connected to central user management. Those are the ones always forgotten.
6. A proper exit conversation. A reminder of confidentiality and intellectual property obligations, and an open discussion about where the person is heading next. Not out of suspicion, out of risk management.
The other side matters too: most leavers are not a threat. An employee who leaves well is an asset, an ambassador, sometimes a future client. Managing the window properly is not about turning every leaver into a suspect. It is the opposite: letting the good ones leave on good terms, and catching in time the rare case that costs the organization a fortune.
Recruitment knows exactly when an employee joins the organization. The question is who owns the moment they leave.