Blue curved vector shape
25 Aug 2026

Five People Who May Still Have Access to Your Business

Former employees, contractors and suppliers can retain access to company email, files, applications and sensitive information long after they have left.

Why Should a Business Owner Care?

Unnecessary access creates a genuine business risk.

Someone with an old account may still be able to:

  • Read confidential emails and documents
  • Download customer or employee information
  • Access financial records or supplier details
  • Delete or alter important files
  • Use your systems to impersonate the business
  • Retain commercially sensitive information
  • Provide criminals with an unnoticed route into your network

Even when nobody acts maliciously, cybercriminals can target dormant accounts. Because the account belongs to somebody who has left, suspicious activity may go unnoticed.

There may also be consequences for data protection, cyber insurance, and customer contracts. If you cannot show who has access to sensitive information, it becomes difficult to demonstrate that it is properly controlled.

Who Might Still Have Access?

1. Former Employees

Disabling somebody’s email account may not remove access from personal phones, home computers, cloud applications or shared passwords.

2. Contractors and Freelancers

Temporary access often becomes permanent because nobody records when a project ends or schedules the account for removal.

3. Previous IT Providers

Old administrator accounts, remote-access tools and shared credentials can remain active after a business changes IT provider.

4. Former Suppliers and Advisers

Accountants, marketing agencies, software consultants, and other suppliers may still have access to Teams, SharePoint or business applications.

5. Current Employees With Old Permissions

People change roles, but their access is rarely reduced. An employee may still be able to view payroll, HR, finance, or management information that is no longer relevant to their job.

Put a Robust Leavers Process in Place

Every business should have a documented process covering more than the return of equipment.

Before someone leaves, confirm:

  • Their final working date and time
  • Every system and application they use
  • Which devices must be returned
  • Whether company information is held on a personal device
  • Who will take ownership of their email and files
  • Whether shared passwords need changing
  • Whether they have administrator access

HR, management and your IT provider should be involved, with one person responsible for confirming that every action has been completed.

Review Access Regularly

A leavers policy deals with future departures. It will not necessarily uncover access left behind from previous years.

At least every six months, review:

  • Microsoft 365 users
  • Administrator accounts
  • Email forwarding and shared mailboxes
  • Teams and SharePoint guests
  • Contractors and external suppliers
  • Remote-access systems
  • Business and cloud applications

Managers should confirm whether each person still requires access and whether their permissions remain appropriate.

Temporary access should also have an expiry or review date. If nobody can explain why an account exists, it should be investigated.

How Helps

At FOS.net , regular proactive audits are built into our support cover.

We identify dormant accounts, former users, unnecessary administrator privileges, and external access that could otherwise remain unnoticed.

We then report the findings clearly, shine a light on potential risks, and help you decide what should be retained, restricted or removed.

Your workforce, suppliers and systems are constantly changing. Regular reviews ensure access changes with them.

Are you confident that only the right people can access your business today?

Ask FOS.net to review your users, permissions and external access, and uncover what may have been left behind.

FOS.net logo dark