Cairitech IT Support and Services Logo

Leader in IT Support & Cybersecurity Across Ontario

Cairitech IT Support and Services Logo
CairiTech blog cover image

The Summer Student Went Back to School — Their Login Stayed Behind

Powered By CairiTech

Quick answer

Every fall, co-op students and seasonal staff head back to class — but at many firms their email, VPN access, and cloud logins stay active long after they've gone. That's not a harmless loose end: 83% of former employees admit they kept accessing accounts after leaving, and improper offboarding now tops the OWASP Non-Human Identities Top 10 for 2025. An orphaned account is a login that still works after its owner has left the organization — an open door nobody is watching. The fix is a repeatable offboarding checklist that revokes every access point the day someone departs. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses — including AEC firms with rotating co-op and field staff — close these gaps before they're exploited.

3 min read posted on 08/30/26

What is an orphaned account, and why is it dangerous?

An orphaned account is an active login — email, VPN, a cloud app, or an admin account — that belongs to someone who has left the organization. It's dangerous because it's access without an owner: no one is using it legitimately, no one is watching it, and it often keeps its old permissions indefinitely. Improper offboarding ranks first on the OWASP Non-Human Identities Top 10 for 2025, and orphaned identities were involved in roughly 32% of related security incidents. Worse, IBM's 2025 research shows breaches involving stolen or compromised credentials — the category dormant accounts fall into — take the longest to detect, averaging 292 days.

Why does late summer make this worse?

Late summer makes this worse because it's when seasonal staff leave in bulk. Co-op students return to school, summer hires wrap up, and field and project help rolls off all at once — often informally, without the paperwork a permanent departure triggers. AEC firms feel this sharply: they lean on co-op students, temporary drafters, and short-term site staff during the busy build season, and when those people leave, their access to Revit files, project folders, and email frequently lingers. A rushed, verbal "they're done" is exactly how accounts get orphaned.

What access actually needs to be revoked?

Everything the person could log into needs to be revoked — and the list is longer than most firms expect. A complete offboarding covers:

  • Email and Microsoft 365 / Google Workspace — disable sign-in immediately, then reassign the mailbox.

  • VPN and remote access — a top target for attackers using leftover credentials.

  • Cloud and SaaS apps — Procore, Autodesk, accounting, CRM, file sharing, and anything single-purpose.

  • Shared drives and project folders — remove from groups, not just the primary account.

  • Admin and privileged accounts — these carry the most damage potential.

  • Physical access — building badges, alarm codes, and keys.

  • Devices and mobile — recover or wipe company laptops and phones.

  • Software licenses — reclaim them so you stop paying for seats no one uses.

Ad hoc vs. standard offboarding — what's the difference?

The difference is whether anything gets missed. An ad hoc, memory-based process almost always leaves a door open; a standard, checklist-driven one closes them all, on time:

Ad hoc offboarding

Speed

Days or weeks — or never

Coverage

Whatever someone remembers

Licenses reclaimed

Rarely

Audit trail

None

Orphaned-account risk

High

Standard offboarding process

Speed

Same day as departure

Coverage

Every account on a checklist

Licenses reclaimed

Yes — cost recovered

Audit trail

Documented and reviewable

Orphaned-account risk

Low

How do you build an offboarding process that actually works?

You build a reliable process by making it a repeatable, shared routine between HR and IT — not a favour someone does when they have a spare minute:

  • Use a written checklist that lists every system, so nothing depends on memory.

  • Trigger it the moment a departure is known — HR notifies IT the same day, ideally in advance for planned exits.

  • Centralize logins with single sign-on (SSO) so most access can be cut in one action.

  • Disable first, delete later — kill sign-in immediately, then reassign email and files before removing the account.

  • Reclaim licenses and devices as part of the same workflow.

  • Run a quarterly access review to catch anything the routine missed, especially after busy seasonal turnover.

CairiTech helps Greater Toronto Area businesses build and run a proper offboarding process — same-day deprovisioning, license reclaim, and regular access reviews — so a departing co-op student never leaves an open door behind. Book your free discovery call with CairiTech today.

FREE REPORT: IT Buyers Guide

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)

Frequently asked questions

How quickly should we disable a former employee's access?

Access should be disabled the same day the person leaves — ideally at the moment their employment ends. Any delay is a window in which an active, unmonitored account can be misused, and dormant credential misuse is among the slowest breaches to detect.

What's the difference between disabling and deleting an account?

Disabling blocks sign-in immediately while preserving the account's data; deleting removes it entirely. Best practice is to disable first — cutting off access right away — then reassign the person's email and files before deleting, so nothing important is lost.

Do we need to keep a departing employee's email and files?

Usually yes. Convert the mailbox to a shared or archived mailbox and reassign important files to a manager, so client history and project work stay accessible. This can be done immediately after sign-in is disabled.

How do orphaned accounts actually lead to breaches?

Orphaned accounts get breached when their credentials are guessed, phished, reused from another leak, or misused by the former employee. Because no one monitors them, attackers can operate undetected for months — which is why these incidents are among the costliest and slowest to catch.

Can better offboarding save money?

Yes. Reclaiming unused software licenses during offboarding stops you paying for seats nobody uses, and preventing a single credential-based breach avoids costs far larger than the effort of a checklist.

Written by the CairiTech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

Popular Reads You Don’t Want to Miss

Blog Cover Image: Cyber Resilience Is Now a Business Requirement for Ontario Manufacturers & Builders

March 29, 2026

Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

Blog Cover Image: Inside Look: How Hackers Use AI To Attack Your Business

January 17, 2025

If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

LOCATIONS

Canada

1-2 Vata Court, Aurora, ON

United States

39288 Calle Tonala, Indio, CA

Copyright 2026. Cairitech. All rights reserved.