The Biggest Access Risk Isn’t Employee Terminations. It’s Internal Transfers

    August 2, 20264 min read
    The Biggest Access Risk Isn’t Employee Terminations. It’s Internal Transfers

    Every security team I’ve worked with has a tight, well-rehearsed process for offboarding. Someone resigns, gets terminated, or retires, HR files a ticket, IT disables the account, access reviews confirm it’s gone. It’s a clean, well-understood event with a clear trigger.

    Internal transfers don’t get that treatment. And that’s exactly why they’re more dangerous.

    Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.

    The Access That Never Gets Removed

    When someone moves from Finance to Sales, or from a regional team to corporate, the standard workflow adds the new access they need for their new role. What almost never happens automatically is removing the access they had in their old role.

    Nobody owns that removal. HR’s job was to process the transfer. IT’s job was to provision the new system access. The old manager has moved on to backfilling the role. The new manager doesn’t know, and doesn’t care, what the employee used to have access to. The result is an account that accumulates permissions the way a hallway closet accumulates junk: nobody put it there maliciously, but nobody’s ever going to clean it out either.

    I’ve seen this play out the same way across dozens of environments. An employee who spent three years in accounts payable moves into IT. Eighteen months later, they still have standing access to the AP system, the vendor master file, and the ability to approve payment batches, because nobody ever asked whether they should.

    That’s not a hypothetical. That’s a segregation of duties violation sitting quietly in your access logs, waiting for an auditor, or worse, an incident, to surface it.

    Why This Is Worse Than Termination Risk

    Terminated employees are, from a risk standpoint, a known quantity. There’s a date. There’s a trigger. There’s urgency, because everyone understands that a departed employee with active credentials is an obvious problem.

    Internal transfers create entitlement creep, access that accumulates slowly, silently, and legitimately. No single grant looks wrong in isolation. Each one made sense at the time. But stack five years of transfers, promotions, and “just give them access while we figure out the new process” and you end up with employees who are, on paper, more privileged than your system administrators.

    This matters more than termination risk for a few reasons:

    • It’s invisible in normal monitoring. Nothing alerts on “employee still has old access” the way something alerts on “terminated employee logged in.”
    • It’s a much larger population. In any given year, far more people change roles internally than leave the company.
    • It defeats least privilege quietly. The org chart says one thing. The access map says something else entirely. And most companies are governing off the org chart.

    What Actually Fixes This

    Terminations get fixed with a checklist. Internal transfers need something closer to a re-provisioning event, not an add-on event.

    A few things that actually move the needle:

    1. Treat every transfer like a mini-offboarding. The old role’s access should be reviewed for removal with the same rigor as a termination, not as an afterthought six months later.
    2. Time-box exceptions. If someone genuinely needs overlap access during a transition, put an expiration date on it. Standing access with no expiry is how “temporary” becomes permanent.
    3. Make access reviews role-based, not tenure-based. A quarterly access review that just asks “does this person still work here?” will miss entitlement creep entirely. It needs to ask “does this person’s current role justify this access?”
    4. Give someone explicit ownership. If offboarding works because someone owns it, transfers will only get fixed the same way: assign the review to a specific role, not a vague shared responsibility.

    My Take

    If I had to bet on where an insider risk or an audit finding was going to come from in a mature organization, I wouldn’t bet on a disgruntled departing employee. I’d bet on a well-meaning employee who’s been promoted twice and still has admin rights to a system they haven’t touched in two years.

    Termination risk gets all the attention because it’s dramatic and easy to explain to a board. Internal transfer risk doesn’t get attention because it’s boring, slow, and doesn’t have a clean before-and-after. But boring and slow is exactly what makes it dangerous, it’s had years to compound before anyone notices.

    If you want to know where your real access risk lives, don’t start with your termination list. Start by pulling everyone who’s had two or more role changes in the last three years, and go look at what they can still touch. I’d be surprised if you like what you find.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify