In one sentence: don’t wait until an employee leaves before you determine your policies and procedures to keep your company data safe.

Your employees most likely have access to your data – and a lot more than you might think – even if they’re not in your office. The access that you give up front will determine what you can do when an employee leaves, either voluntarily or after being terminated.

First, there’s email. If your employees sync their work email to their phones or tablets or home computers, they may continue to be able to access that information even AFTER you have disabled their account or changed their password.  How to handle this can be different depending on whether they’ve been using a smartphone, tablet, or a laptop or desktop computer.

However, little thought is often given to NEW email being received. Should it simply be returned as undeliverable?  Should the sender get a notice to contact someone else?  Should someone automatically receive copies of all incoming messages?  Should someone else be given access to all EXISTING messages?

A lot of law firms like to use software such as Dropbox or OneDrive to replicate files across multiple devices. Unfortunately, most of these provide no way of limiting access or preventing someone from making copies of the files.  Using a file syncing program that DOES allow restricting access can prevent the possibility of a former employee still having access after separation.

One way to help limit access by a former employee is to prevent employees from accessing data from their own devices in the first place. By issuing company-owned phones, tablets, and laptops, these can be retrieved upon separation, thus preventing future access.

Many firms mistakenly trust former employees, and it may be true that certain former employees would never misuse any data they are able to access. However, are you SURE that they will take the same precautions with that data as a current employee?  What happens if their cell phone or laptop gets stolen or hacked?  While the former employee might not misuse the data, a hacker might and if the firm has no control over the data, they have no control over whether it can be hacked.

Remote access is another common method of allowing employees to access company data while out of the office, but remote control programs such as TeamViewer and LogMeIn are often forgotten about upon employee separation. It is critical that any passwords be changed or accounts cancelled, and it is critical to avoid having shared access across multiple employees because it is difficult to stop access by one employee.

Naturally, it is pretty common to disable a network account for a former employee. But are there any specific policies in place for how that it done and when?  Ideally, it should be done immediately upon separation, but there has to be a procedure in place so that the IT department is notified and can perform the proper actions.

What about other software, such as billing programs, docketing programs, accounting software, time entry software, and so on? Often those critical programs have user credentials that are different than the basic network/computer credentials.  Is there a policy and a procedure in place to disable ALL of those accounts as well?

What about cloud services, especially as more and more data and programs are run from the cloud? Are there policies and procedures in place to disable accounts for former employees?

In summary, there can be a lot of data that a former employee may be able to access, and without having the proper policies and procedures in place, and planning done in advance, it may be difficult or impossible to restrict access to that data.