Serving Plant City, Tampa & Central Florida 📞 (508) 243-7410 ✉ brendan@beardedbytes.com

The IT Offboarding Checklist Every Florida Small Business Needs

When an employee leaves, how fast you cut their access determines whether it's a clean exit or a security incident. Here's the IT offboarding checklist to use.

Illustration of a departing employee silhouette walking through a doorway while a padlock secures a laptop and keycard behind them, representing IT offboarding

Here’s the uncomfortable truth: most small businesses have a great process for setting up a new employee’s accounts, and no process at all for tearing them down. Someone gives their two weeks, HR shakes their hand on the last day, and their email, VPN login, and shared Dropbox folder just… keep working. Sometimes for months.

I’ve seen this exact issue at three clients in the last year — and every single time, nobody noticed until I asked.

If you run a small business in Tampa, Lakeland, or anywhere in Central Florida, you’ve probably got some version of this problem right now. Not because you don’t care about security, but because offboarding isn’t a fun task, it’s not urgent the day someone leaves, and it’s easy to assume IT “just handles it.” Let me walk you through what I’d actually do — and the checklist I use with clients so nothing gets missed.

Why this matters more than people think

An ex-employee with lingering access isn’t usually a Hollywood villain plotting revenge. Most of the time it’s much more mundane and still costly:

None of these require malice to become a problem. They require access that should have been revoked on day one, but wasn’t. And if you ever have to file a cyber insurance claim or explain a breach under Florida’s data breach notification law, “we forgot to disable a former employee’s login” is not a sentence you want to say out loud.

The same-day offboarding checklist

This is the list I run through with clients the moment someone gives notice — not the day they walk out, but the day you know they’re leaving. Treat departure day as the deadline, not the starting point.

1. Cut identity and email access first

Disable (don’t delete yet) the Microsoft 365 or Google Workspace account. Disabling first preserves the mailbox in case you need to search it later, while immediately blocking login. Set up an auto-forward or delegate access so someone on your team can catch anything time-sensitive landing in that inbox.

2. Revoke MFA and password manager access

If they’re enrolled in multi-factor authentication, remove their device from the account. If your business uses a shared password manager (and it should — see our Microsoft 365 security settings guide for why), revoke their vault access and rotate any shared credentials they had visibility into.

3. Kill VPN and remote access

If they had remote access to your network — a VPN client, RDP, or remote desktop tool — disable that credential the same day. Remote access left open after departure is one of the most common ways former employees (or someone who guesses their old password) can get back in without anyone noticing.

4. Remove them from every shared system

Walk through the full list: shared drives, QuickBooks or accounting software, your CRM, scheduling tools, your POS system, any industry-specific software. It helps enormously to keep a running document of “who has access to what” — most of my clients don’t have this until after their first offboarding scare, and then they never go without one again.

5. Physical access matters too

Collect keys, badges, and fobs. Change any shared door codes or alarm codes they knew. If you use smart locks or a camera system with app access — like the setups we install for security camera projects — remove their login from that app specifically. This one gets missed constantly because it doesn’t feel like “IT.”

6. Retrieve and wipe devices

Get back any company laptop, phone, or tablet. Before reissuing it, wipe it properly rather than just deleting a few folders — a factory reset takes ten minutes and closes the door on any lingering saved passwords or cached email.

7. Update your documentation

Note the offboarding date, what was revoked, and by whom. This isn’t busywork — if you’re ever audited for cyber insurance or need to demonstrate compliance after an incident, a documented offboarding trail is exactly what an insurer or auditor wants to see.

8. Don’t forget contractors, vendors, and part-timers

Offboarding checklists tend to focus on full-time employees, but the same rules apply to the bookkeeper who comes in once a month, the seasonal warehouse help you brought on for the holiday rush, or the contractor who built your website and still has admin access “just in case.” I’ve walked into more than one client account and found five or six logins for people who haven’t done work for the business in over a year. None of those were malicious — they were just never cleaned up. Set a calendar reminder every quarter to review who has standing access and ask yourself honestly whether they still need it.

The exception: give yourself a plan for messy exits

Most departures are calm. Some aren’t. If someone is terminated for cause, or you suspect they’re leaving on bad terms, flip the order: cut access first, have the conversation second. It feels harsh, but a same-day revocation before the termination conversation protects both the business and, frankly, the departing employee from being blamed for something that happens after they’re already gone.

Why this keeps getting skipped

I get it — offboarding isn’t glamorous, and when you’re running a 10-person company, HR paperwork and the actual goodbye conversation eat up all the emotional bandwidth for the day. IT access cleanup falls to whoever remembers, which means it often falls to nobody.

This is exactly the kind of process that a managed IT relationship is built to catch. When we bring a client onto managed IT services, one of the first things we set up is a shared offboarding checklist tied to your HR calendar, so access gets revoked the same day someone’s status changes — not whenever someone remembers to send an email. It’s a small thing to set up once, and it quietly prevents the kind of slow-motion mistake that only becomes obvious after it’s already caused a problem.

A simple fix: build the list before you need it

You don’t need fancy software to fix this. Grab a spreadsheet right now and list every system your business uses — email, VPN, POS, shared drives, physical access, industry software — and who currently has admin rights to revoke access on each one. That single document is the difference between a five-minute offboarding and a two-week gap where an ex-employee still has the keys, literally and digitally, to your business.

If you want a second set of eyes on your current access setup — or you’ve realized while reading this that you honestly don’t know who still has access to what — reach out for a free consultation. It’s a quick conversation, and for most small businesses in Plant City, Tampa, and the surrounding area, it’s the first time anyone’s actually mapped this out.

Tags: #offboarding#cybersecurity#access control#small business#florida#it-support

Need help with this in your business?

Bearded Bytes provides on-site IT support, cybersecurity, and managed services across Plant City and the Tampa Bay area. Book a free consultation.

Talk to Brendan →