
Powered By CairiTech
Quick answer
Every fall, co-op students and seasonal staff head back to class — but at many firms their email, VPN access, and cloud logins stay active long after they've gone. That's not a harmless loose end: 83% of former employees admit they kept accessing accounts after leaving, and improper offboarding now tops the OWASP Non-Human Identities Top 10 for 2025. An orphaned account is a login that still works after its owner has left the organization — an open door nobody is watching. The fix is a repeatable offboarding checklist that revokes every access point the day someone departs. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses — including AEC firms with rotating co-op and field staff — close these gaps before they're exploited.
3 min read posted on 08/30/26
An orphaned account is an active login — email, VPN, a cloud app, or an admin account — that belongs to someone who has left the organization. It's dangerous because it's access without an owner: no one is using it legitimately, no one is watching it, and it often keeps its old permissions indefinitely. Improper offboarding ranks first on the OWASP Non-Human Identities Top 10 for 2025, and orphaned identities were involved in roughly 32% of related security incidents. Worse, IBM's 2025 research shows breaches involving stolen or compromised credentials — the category dormant accounts fall into — take the longest to detect, averaging 292 days.
Late summer makes this worse because it's when seasonal staff leave in bulk. Co-op students return to school, summer hires wrap up, and field and project help rolls off all at once — often informally, without the paperwork a permanent departure triggers. AEC firms feel this sharply: they lean on co-op students, temporary drafters, and short-term site staff during the busy build season, and when those people leave, their access to Revit files, project folders, and email frequently lingers. A rushed, verbal "they're done" is exactly how accounts get orphaned.
Everything the person could log into needs to be revoked — and the list is longer than most firms expect. A complete offboarding covers:
Email and Microsoft 365 / Google Workspace — disable sign-in immediately, then reassign the mailbox.
VPN and remote access — a top target for attackers using leftover credentials.
Cloud and SaaS apps — Procore, Autodesk, accounting, CRM, file sharing, and anything single-purpose.
Shared drives and project folders — remove from groups, not just the primary account.
Admin and privileged accounts — these carry the most damage potential.
Physical access — building badges, alarm codes, and keys.
Devices and mobile — recover or wipe company laptops and phones.
Software licenses — reclaim them so you stop paying for seats no one uses.
The difference is whether anything gets missed. An ad hoc, memory-based process almost always leaves a door open; a standard, checklist-driven one closes them all, on time:
Ad hoc offboarding
Speed
Days or weeks — or never
Coverage
Whatever someone remembers
Licenses reclaimed
Rarely
Audit trail
None
Orphaned-account risk
High
Standard offboarding process
Speed
Same day as departure
Coverage
Every account on a checklist
Licenses reclaimed
Yes — cost recovered
Audit trail
Documented and reviewable
Orphaned-account risk
Low
You build a reliable process by making it a repeatable, shared routine between HR and IT — not a favour someone does when they have a spare minute:
Use a written checklist that lists every system, so nothing depends on memory.
Trigger it the moment a departure is known — HR notifies IT the same day, ideally in advance for planned exits.
Centralize logins with single sign-on (SSO) so most access can be cut in one action.
Disable first, delete later — kill sign-in immediately, then reassign email and files before removing the account.
Reclaim licenses and devices as part of the same workflow.
Run a quarterly access review to catch anything the routine missed, especially after busy seasonal turnover.
For related reading, see our posts on securing remote and field staff and stopping credential-driven fraud, plus our cybersecurity services.
CairiTech helps Greater Toronto Area businesses build and run a proper offboarding process — same-day deprovisioning, license reclaim, and regular access reviews — so a departing co-op student never leaves an open door behind. Book your free discovery call with CairiTech today.

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)
Access should be disabled the same day the person leaves — ideally at the moment their employment ends. Any delay is a window in which an active, unmonitored account can be misused, and dormant credential misuse is among the slowest breaches to detect.
Disabling blocks sign-in immediately while preserving the account's data; deleting removes it entirely. Best practice is to disable first — cutting off access right away — then reassign the person's email and files before deleting, so nothing important is lost.
Usually yes. Convert the mailbox to a shared or archived mailbox and reassign important files to a manager, so client history and project work stay accessible. This can be done immediately after sign-in is disabled.
Orphaned accounts get breached when their credentials are guessed, phished, reused from another leak, or misused by the former employee. Because no one monitors them, attackers can operate undetected for months — which is why these incidents are among the costliest and slowest to catch.
Yes. Reclaiming unused software licenses during offboarding stops you paying for seats nobody uses, and preventing a single credential-based breach avoids costs far larger than the effort of a checklist.
Written by the CairiTech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

March 29, 2026
Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

January 17, 2025
If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

Canada
1-2 Vata Court, Aurora, ON
United States
39288 Calle Tonala, Indio, CA
Copyright 2026. Cairitech. All rights reserved.