S
Stitex
Data protection

How to Detect Data Theft Before an Employee Resigns

Short answer: a leak before resignation isn’t given away by one download — it’s a spike in activity on top of otherwise normal work: bulk exports, access outside someone’s usual scope, forwarding to a personal inbox. Anomaly monitoring catches that pattern; blanket restrictions don’t. Here’s what to watch for and what to do about it.

July 21, 20269 min readStitex Technologies

Why the Resignation Period Is the Riskiest Window

Most client-database leaks don’t start with a hack — they happen in an employee’s last few weeks on the job. At that point they still have full, legitimate access, but now they’re motivated to take what they built with them, to a competitor or into a business of their own. Which means the flight-risk group is known well in advance: anyone who’s handed in notice, or whose contract is about to end.

Warning Signs Someone Is Taking Data With Them

  • A spike in exports and downloads — where the usual volume is a handful of records, suddenly it’s hundreds,
  • Access outside their usual scope — opening client or department data they don’t normally touch,
  • Forwarding to a personal inbox — databases, price lists, contracts attached and sent to an outside address,
  • Removable media — a USB drive plugged in, files copied off,
  • Off-hours activity — bulk operations at 2 a.m. or on a Sunday.
One Signal Isn’t a Leak
Any one of these, on its own, can be perfectly innocent. What matters is several signals stacking up on someone already in the flight-risk group. That’s why the useful unit isn’t a single log line — it’s the behavior pattern a monitoring system assembles from all of them.

How to Monitor This in Practice

StepWhat it involves
1. Log accessrecord who opens, exports, and copies what
2. Set a baselineknow the normal volume of work by role, so you can spot the outliers
3. Detect anomaliesAI flags spikes and unusual activity, alerts a manager
4. Watch flight risks harderdeparting employees get separate, more sensitive monitoring
5. Revoke accessthe moment someone leaves, cut every system at once, not one at a time

What’s Legal to Monitor

Monitoring what employees do on company devices and in company systems is legal under two conditions: employees are notified, and the company has a documented trade-secret regime in place. Meet both, and access logs establish what actually happened, giving the company grounds to act on it. Skip either one, and there’s nothing to point to later, which is why the legal groundwork goes in before the fact, not after. In Russia that framework rests on the trade-secret provisions of Federal Law 98-FZ, with any personal data collected governed by Russia’s data-protection law (152-FZ), broadly comparable to GDPR-style consent and notice requirements elsewhere. Outside Russia the specific statutes differ, but the same two-part logic tends to hold. We walked through how to set this up properly in how to protect a customer database from copying. Whether a specific incident holds up is a question for your own counsel, not something this article can answer.

How CorpShield Helps

Stitex CorpShield monitors access continuously. AI flags the anomalies — bulk exports, downloads that spike right before someone resigns, USB drives being plugged in — and sends alerts that are actually readable, not a wall of raw logs. It also helps you flag the flight-risk group and revoke access in one pass. Built for mid-sized companies without an in-house security team, deployed turnkey.

FAQ

How can you tell an employee is about to leave and taking data with them?

Behavioral tells: a sudden jump in exports and downloads, access to data outside their usual scope, bulk forwarding to a personal email account, USB drives plugged in, activity outside working hours. One signal on its own is nothing. Several in a row, on someone already in the flight-risk group, is worth a closer look.

Can this be used as evidence?

Access logs collected under a documented trade-secret regime, with employees notified in advance, establish what actually happened. Whether that holds up in a specific case is a question for a lawyer — but without the logs and the regime in place, there's nothing to argue from to begin with.

What should you do the moment someone hands in their notice?

Restrict the departing employee's access to sensitive data early, not on their last day. Step up monitoring on their activity for the rest of the notice period. The moment they actually leave, revoke every access right at once, across every system. CorpShield handles both the flight-risk monitoring and the one-pass revocation.

Catch the leak before it happens

We set up anomaly monitoring and flight-risk tracking, and help you restrict access and revoke it cleanly when someone leaves. Turnkey, no in-house security team required.