Back
CASE #3
Case file
Cyber security
July 11, 2026

A UAE Company's IT Manager Resigned. His System Access Did Not.

WHAT IS IT ABOUT

Unrevoked system access occurs when an employee's credentials remain active after their departure because the offboarding process covers visible accounts — email, laptop return — but does not systematically audit internal systems, VPN, ERP, CRM, accounting software, and supplier portals. In UAE organisations we have audited, the average time between an employee leaving and full access revocation is 47 days. In some cases credentials remained active for over a year. This is not a hacking problem. It is a process problem. An attacker does not need to break into a system when a former employee's credentials still open the door.

THE INCIDENT

A UAE company's IT manager resigned last month.

His email was deactivated on his last day.

His system access was not.

He did not do anything with it. But he could have. And for six weeks, nobody knew.

When audit was ran, auditors found three former employees who still had active credentials to internal systems. One had left eight months ago. Another had been gone for over a year. All three could still log in — to the ERP, to supplier portals, to the shared drives where contracts and pricing data lived.

None of them had done anything malicious.

That is not the point.

The point is that the company had no way of knowing. There was no alert. No log review. No system that flagged a departure and triggered an access review. The offboarding checklist said: collect laptop, return access card, deactivate email.

Nobody had written down everything else.

In a separate case the same month, a former operations manager at a different UAE company logged into the procurement system fourteen weeks after resigning. Not to steal anything. To check a supplier contact he had forgotten to save.

He could get in because nobody had removed him.

He had done nothing wrong. But if someone else had found those credentials — through a phishing email, through a data leak, through a simple password guess — they would have walked straight into an active procurement system with zero resistance.

The email is not where the data lives. The ERP is. The CRM is. The shared drive is. And in most UAE businesses, those systems have no automatic offboarding trigger.

WHAT THIS REVEALS

The offboarding process in most UAE organisations is an HR process, not a security process. Laptop and access card. Final paycheck. Exit interview. The IT layer — which systems the person was on, what they could see, what they could do — is treated as a footnote.

A disgruntled former employee with active ERP access has everything they need. Supplier relationships. Pricing history. Client data. Procurement schedules. The damage from that access being misused is months of remediation and potential regulatory exposure under UAE PDPL if personal data was involved.

The risk is not limited to malicious intent. A former employee whose credentials are used by a third party — through phishing, credential stuffing, or a data breach — gives that third party the same access. The former employee is no longer in the building. The login still works.

PREVENTION FRAMEWORK

Build a role-specific offboarding checklist covering every system before anyone actually leaves

Set a 24-hour revocation target for all departures covering email, VPN, ERP, CRM, shared drives, and supplier portals

Run a quarterly access audit even when nobody has left — cross-reference all active credentials against current employees

Enable login alerts for accounts that have been inactive for more than 30 days

Require two-person sign-off on all departures — IT confirms access revocation before the departure is marked complete

IF THIS HAS ALREADY HAPPENED

If you have reason to believe a former employee still has active access — or recently used access after their departure — do not change the passwords immediately.

Changing credentials alerts the person and destroys the audit trail of what they accessed and when.

First: pull the access logs. Most enterprise systems record login history. That log tells you when access was used, from which device, from which location. That is the evidence.

Then revoke access and change all affected credentials.

File a report if the access was used after the departure date. Under UAE law, unauthorised system access after employment ends is a criminal matter regardless of whether data was taken.

We can help you read the access logs, understand the exposure, and decide what steps remain available.

Contact us →

Contact us nowView on Linkedin
NORDSTAR NOTE

In every access audit we conduct, the finding is the same: the organisation does not know how many active credentials exist for former employees because nobody ever compiled that list. The offboarding process was designed by HR, not IT. The systems most at risk — ERP, CRM, procurement platforms — are rarely on the checklist because they were added after the checklist was written. Ninety days after any departure is a reasonable assumption for how long stale access persists in a UAE business without a formal audit process.

UAE Employee Offboarding — IT Access Revocation Checklist

A role-by-role checklist of every system to revoke on departure — covering ERP, CRM, VPN, shared drives, supplier portals, admin panels, and cloud storage. 24-hour revocation target. Built for UAE businesses with no dedicated IT security team.
Thank you! Your submission has been received.
Oops! Something went wrong while submitting the form.