When Staff Leave: Securing Your Systems During Handover
High turnover in Hong Kong SMEs often leaves critical systems exposed. One clinic's CTO left with payment processing credentials on a personal phone — the whole business nearly collapsed.
High employee turnover is a reality for Hong Kong SMEs — 10–15% annual churn is commonplace. But most companies overlook a critical vulnerability: when staff leave, how do you ensure systems, data, and automation workflows don't walk out the door with them?
During a recent security audit at a Central private clinic, we discovered a nightmare scenario: their entire appointment system, payment processing, and staff scheduling ran on one CTO. When he handed in his notice, the new team discovered his personal phone held the payment processor credentials. His WhatsApp Business account was under his name. The only person who understood the auto-reconciliation script was gone. The result: three days of downtime, one month of lost revenue ($120,000).
When One Person Leaves, Everything Stops
This isn't unique. Hong Kong SMEs typically operate this way: small teams, tight budgets, one smart person managing everything. Then that person walks out, and the business becomes hostage to their knowledge. The three most common vulnerabilities:
- Missing credentials.AWS, Stripe, bank API keys — all registered under one person's account or stored on their personal laptop. Without them, access is locked.
- Undocumented automation.Scripts that auto-invoice, reconcile accounts, send emails — written by one person, understood by no one else. Modifying or replacing them is impossible.
- Customer channels locked in personal accounts.WhatsApp Business, Google Business, email workflows — all tied to the departing employee's device. One person leaves, communication stops.
The fallout extends beyond downtime. We've seen companies with years of customer data locked in a former employee's personal cloud storage, supplier passwords unknown, and automation errors running undetected for a year before audit caught them.
How to Hand Over Systems Properly: Five Steps
Most companies treat staff departures as two steps: sign the resignation letter, send a farewell email. The system layer is afterthought. But follow these five steps, and 99% of risk is eliminated:
Step 1: Inventory all systems.Do this on day one of hiring; refresh it two weeks before departure. Which systems does this person own? Which credentials are under their name? Which processes depend on their custom code? Build a checklist:
- External services: AWS, Stripe, banking, email, CMS
- Internal systems: ERP, CRM, accounting software, automation tools
- Credentials: API keys, passwords, 2FA setup
- Documentation: source code repo, procedures manual, runbooks
Step 2: Migrate credentials and 2FA.Change every password. Move all accounts to company-controlled credentials (or use a password manager like 1Password or Vault). Critical accounts with sole 2FA control — AWS root, banking apps, critical email — must transfer ownership to a company device. As long as one person controls a critical code path, the vulnerability persists.
Step 3: Document automation workflows.Every custom script, scheduled job, or webhook needs a code walkthrough with documentation. The replacement might not grasp all of it, but someone must understand: how does this start, what happens if it fails, how do you modify it? If this step is skipped, budget $3,000–5,000 per script for external remediation later.
Step 4: Conduct a handover dry run.One week before departure, sit down together and run through a full handover simulation. Let the new person change a password, restart a system, execute a maintenance task. Problems will surface immediately. If they surface after the person leaves, it's too late.
Step 5: Post-departure audit.One month after the person leaves, do an internal (or third-party) IT audit: Are old accounts revoked? Are new ones active? Have processes depending on personal accounts been migrated? Catching oversights months later is far more costly than catching them immediately.
One logistics company followed this framework for an ops handover. Total time: three days (versus the CTO handover which took a month). Cost: $8,000 for external remediation on one critical script. Benefit: avoided $150,000 in monthly losses.
Design Systems for Handover From Day One
Foresighted companies bake handover into system design from the start. Every script, automation, and tool is built with the question: "How will this transfer to someone else?" Best practices:
- No personal accounts.AWS, Stripe, banking APIs — always register under the company. Individuals merely borrow access.
- Every automation gets a README.Scripts, scheduled jobs, webhooks — each needs simple documentation: how to run it, how to troubleshoot, who's on-call if it breaks.
- Regular handover drills.Don't wait for someone to resign. Run fake handovers every six months with new team members. This usually reveals 3–5 gaps.
- Redundancy for critical systems.Never let one person control money or customer data. Build in backup coverage from day one.
One e-commerce startup invested two weeks building a "handover-ready architecture." Later, with 30% staff turnover, each handover took 3–5 days and cost $2,000–3,000. Without that architecture, losses would have exceeded hundreds of thousands.
No IT Staff? Hire an Audit
Running a five-person startup with no full-time IT? Don't assume "small team means low risk." The worst cases we've seen were small companies. Here's what to do:
- Hire an external cybersecurity consultant for a $5,000 "departure risk audit."They'll identify risky accounts, assess handover readiness, flag automation gaps.
- Create a one-page offboarding checklist. Store it in shared drive.Next time someone leaves: straight through — password changes, file transfers, stakeholder notifications.
- Run a monthly "fake handover" with someone on staff.Can they manage someone else's systems? If yes, you have redundancy. If no, you found your vulnerability.
FAQs
Does everyone need to understand the entire system?
No. But every critical component — payment processing, customer databases, auto-reconciliation — must be known by at least two people. There's a difference between specialization and single-point-of-failure. Good teams are T-shaped: everyone has deep expertise, but all understand the system architecture.
Small budgets. Can't afford 1Password or a password vault. What's the minimum?
Buy it. $10–30 per month is insurance against a departure crisis. But if you absolutely can't: shared encrypted spreadsheet (password-protected Google Sheets) with critical credentials. Not ideal, but infinitely better than one person holding everything.
A departing employee refuses to hand over credentials. What now?
Legally, company system credentials are company assets. On departure, handover is mandatory. If they refuse, you can escalate to the service provider (AWS, Stripe) using company identity recovery. It's costlier and messier, but possible. Best practice: include a handover checklist in employment contracts from day one, eliminating ambiguity.
Next Step: Run a System Inventory
If you're a founder or tech lead, spend a morning auditing your systems. Ask yourself five questions:
- Which systems do only one person understand?
- Under whose name are critical accounts (banking, payment) registered?
- Are there undocumented custom scripts only one person can modify?
- How long did the last staff handover take?
- Does your offboarding process include IT?
If you answer "we don't know," "just them," or "we found out months later," you've identified serious risk. A small investment — $5,000 audit plus $2,000 in tools — can prevent $100,000+ losses down the road.
Ready to build a handover-proof system or conduct a security audit? Our quote wizard takes just a few minutes to estimate cost.