TL;DR:

  • Insider threats cause a significant share of UK small business data breaches — often accidental, sometimes deliberate, frequently discovered months late
  • The riskiest moment is when someone leaves: accounts often stay active long after their last day
  • Access reviews, offboarding checklists, and the principle of least privilege are the three controls that matter most

When small business owners think about cybersecurity threats, they picture hackers — external attackers trying to break in. But some of the most significant data breaches affecting UK small businesses involve people who were already inside: an employee who took a client list when they resigned, a contractor whose access wasn’t removed after the project ended, or a former partner whose email login still worked eighteen months after the relationship ended.

Insider threats aren’t always malicious. Many are accidental — an employee emails a spreadsheet to their personal account to work from home and forgets about it, or clicks the wrong share button in Google Drive. But whether deliberate or careless, the result can be a serious data breach, regulatory exposure under UK GDPR, and potential competitive harm.

Why Small Businesses Are Particularly Exposed

Large organisations have dedicated IT and HR teams whose processes catch access removal and data loss. Small businesses typically don’t. Offboarding is informal. Account removal is reactive. Access reviews don’t happen. The owner has admin on everything and no visibility into what others are doing with their access.

The ICO’s breach data consistently shows that small organisations account for a disproportionate share of incidents traced back to internal actors — not because their employees are more dishonest, but because the controls that would catch problems early don’t exist.

The Highest-Risk Moment: When Someone Leaves

Departing employees represent a concentrated risk window. Research consistently shows that data exfiltration by employees who are about to leave — or who have just been told they’re leaving — spikes in the period around termination. Common patterns include downloading client lists, copying project files, forwarding emails to personal accounts, and sharing sensitive documents with a personal cloud storage account.

The other risk is simpler: accounts that aren’t deactivated promptly after someone leaves remain live attack vectors. A disgruntled ex-employee can walk back in through their old login. A credential phished from them six months ago can be used against your systems. Former contractors’ VPN or software access, if never revoked, is a door that stays open indefinitely.

The fix is a proper offboarding checklist. This doesn’t need to be complicated — it needs to be done. Every departure should trigger a checklist that covers:

  • Deactivate Microsoft 365 / Google Workspace account and sign out all active sessions
  • Revoke access to shared accounts (social media, booking systems, supplier portals)
  • Remove from any shared password manager vaults
  • Revoke VPN credentials
  • Remove from project management tools (Trello, Asana, Monday.com, etc.)
  • Recover any company devices
  • Change passwords for any shared accounts they had access to

Run this checklist on the last day, not a week later.

The Principle of Least Privilege

The best preventive control against insider threats is ensuring people only have access to what they actually need for their role. This sounds obvious; in practice, most small businesses have accumulated access creep over time — people who were given admin access for a one-off task and kept it, or accounts that started with full permissions because it was easier to set up that way.

An access review doesn’t need to be an annual audit process. It can be a simple question asked quarterly: does everyone who currently has access to our systems actually need that level of access?

For cloud services like Microsoft 365, Google Workspace, and Xero, this means:

  • Don’t give admin roles to people who don’t need them for their day-to-day work
  • Use shared mailboxes and team drives rather than giving individuals direct access to sensitive data they only occasionally need
  • Set access to sensitive folders and documents explicitly, rather than sharing everything by default

Monitoring for Warning Signs

You don’t need enterprise security tools to notice unusual access patterns. Most cloud platforms include basic activity logs that can alert you to:

  • Large file downloads outside working hours
  • Bulk email forwarding rules set up in an account
  • New connections from unexpected locations or devices
  • Large shares to external email addresses

In Google Workspace: Reports > Audit & investigation > Drive log events will show file download and share activity. In Microsoft 365: the Security & Compliance Center shows bulk download activity under Activity Explorer.

You don’t need to watch these daily — but reviewing them when someone is about to leave, or when an employment relationship is becoming difficult, is worthwhile.

Contractors and Third Parties

Contractors and third-party suppliers often get access to systems for a project and never have it removed. A freelance web developer who had admin access to your WordPress site two years ago may still have it. A bookkeeper who helped you set up Xero may still be listed as an admin user.

Audit your third-party access at least once a year. Most cloud tools have a way to see all users with access — do a review and remove anyone who isn’t actively working with you.

For ongoing contractor relationships, consider creating time-limited accounts or access tokens rather than permanent credentials. Some tools support this natively; for others, setting a calendar reminder to review access quarterly achieves a similar result.

A Simple Starting Point

If you take away one action from this article, make it this: open up your Microsoft 365 or Google Workspace admin panel right now and look at the list of active user accounts. Are there any names of people who no longer work for you? Any accounts for former contractors? Any accounts for email addresses you don’t recognise?

That list is your immediate priority. Deactivate those accounts today.

The rest — access reviews, offboarding checklists, least privilege — can be built from there. But removing access that shouldn’t exist is the single highest-impact action most small businesses can take to reduce their insider risk, and it costs nothing except twenty minutes.