Why the Resignation Period Is the Riskiest Window
Most client-database leaks don’t start with a hack — they happen in an employee’s last few weeks on the job. At that point they still have full, legitimate access, but now they’re motivated to take what they built with them, to a competitor or into a business of their own. Which means the flight-risk group is known well in advance: anyone who’s handed in notice, or whose contract is about to end.
Warning Signs Someone Is Taking Data With Them
- •A spike in exports and downloads — where the usual volume is a handful of records, suddenly it’s hundreds,
- •Access outside their usual scope — opening client or department data they don’t normally touch,
- •Forwarding to a personal inbox — databases, price lists, contracts attached and sent to an outside address,
- •Removable media — a USB drive plugged in, files copied off,
- •Off-hours activity — bulk operations at 2 a.m. or on a Sunday.
How to Monitor This in Practice
| Step | What it involves |
|---|---|
| 1. Log access | record who opens, exports, and copies what |
| 2. Set a baseline | know the normal volume of work by role, so you can spot the outliers |
| 3. Detect anomalies | AI flags spikes and unusual activity, alerts a manager |
| 4. Watch flight risks harder | departing employees get separate, more sensitive monitoring |
| 5. Revoke access | the moment someone leaves, cut every system at once, not one at a time |
What’s Legal to Monitor
Monitoring what employees do on company devices and in company systems is legal under two conditions: employees are notified, and the company has a documented trade-secret regime in place. Meet both, and access logs establish what actually happened, giving the company grounds to act on it. Skip either one, and there’s nothing to point to later, which is why the legal groundwork goes in before the fact, not after. In Russia that framework rests on the trade-secret provisions of Federal Law 98-FZ, with any personal data collected governed by Russia’s data-protection law (152-FZ), broadly comparable to GDPR-style consent and notice requirements elsewhere. Outside Russia the specific statutes differ, but the same two-part logic tends to hold. We walked through how to set this up properly in how to protect a customer database from copying. Whether a specific incident holds up is a question for your own counsel, not something this article can answer.
How CorpShield Helps
Stitex CorpShield monitors access continuously. AI flags the anomalies — bulk exports, downloads that spike right before someone resigns, USB drives being plugged in — and sends alerts that are actually readable, not a wall of raw logs. It also helps you flag the flight-risk group and revoke access in one pass. Built for mid-sized companies without an in-house security team, deployed turnkey.
FAQ
How can you tell an employee is about to leave and taking data with them?
Behavioral tells: a sudden jump in exports and downloads, access to data outside their usual scope, bulk forwarding to a personal email account, USB drives plugged in, activity outside working hours. One signal on its own is nothing. Several in a row, on someone already in the flight-risk group, is worth a closer look.
Can this be used as evidence?
Access logs collected under a documented trade-secret regime, with employees notified in advance, establish what actually happened. Whether that holds up in a specific case is a question for a lawyer — but without the logs and the regime in place, there's nothing to argue from to begin with.
What should you do the moment someone hands in their notice?
Restrict the departing employee's access to sensitive data early, not on their last day. Step up monitoring on their activity for the rest of the notice period. The moment they actually leave, revoke every access right at once, across every system. CorpShield handles both the flight-risk monitoring and the one-pass revocation.