What 170,000 job cuts have done to the credentials nobody was tracking

At 6 am, even before anybody has opened their laptops, there is the dreaded email waiting for them – they’ve been laid off. And the badges have already stopped working by the time the first affected engineer would normally have reached the building.

The months, and in some cases several years, of their work and effort have been reduced to a document and a piece of paper. And the devices have been sent back via couriers, wiped clean and even reissued quickly – the standard offboarding checklist, the process has closed cleanly and on schedule.

It isn’t anything personal – most large enterprises execute that sequence with real precision, and the precision is what obscures the problem, because none of it reaches the automation those engineers left running.

The scheduled job, written four years ago to reconcile two systems that were never designed to communicate, keeps running, as does the service account created for a migration that finished in 2023 and was never decommissioned. These assets appear on no checklist and belong to nobody. The scale of the current reductions has turned them from an untidy backlog into a risk category of their own.

The technology sector announced 123,653 job cuts in the first five months of 2026, according to Challenger, Gray & Christmas, a 66% increase on the same period a year earlier, while trackers including Layoffs.fyi and TrueUp put the running total above 170,000 people.

Recent months brought cuts of 16,000 corporate roles at one online retailer, 3,000 at a financial software firm amounting to 17% of its workforce, and 1,400 at a consumer brand where the majority sat in technology.

Security teams are inside those figures rather than shielded from them, and ISC2’s 2025 Cybersecurity Workforce Study, drawn from 16,029 practitioners, recorded 24% reporting layoffs within their own function and 36% reporting budget cuts, rising to 32% and 46% at the largest organisations.

When asked what those reductions do to their exposure, 72% said that cutting security personnel significantly increases breach risk, and IBM’s 2025 Cost of a Data Breach research found that organisations reporting a high skills shortage paid an average of $5.22 million per breach against $3.65 million for those reporting little or none.

A departure changes the security posture, and enterprises still account for it as a personnel change

The process governing that change was built for a workforce that no longer exists, and it is administered by a function with no visibility into the systems concerned.

“Offboarding has historically been treated as an HR checklist: collect the laptop, cancel the badge, done,” said Saran B. Paramasivam, Regional Director, MEA at Zoho. “When someone leaves, their digital footprint does not automatically leave with them.”

James Maude, Field Chief Technology Officer at BeyondTrust, argues for treating the departure as an exercise rather than an administrative closure, since the information an organisation would need during an incident is the same information it needs at an exit.

“We should think of offboarding as a rehearsal for an identity compromise, because that puts the risk in the right terms and forces you to think about whether you actually know what that employee could access,” Maude said. “What systems, what secrets, what credentials, and what privileges did they have on those systems? You can find out in an afternoon, in a low-risk way, what someone could access and what damage could be inflicted, without having to work it out during an incident response.”

Palo Alto Networks’ 2026 identity security research, which surveyed 2,930 decision-makers and succeeds CyberArk’s annual study following the acquisition, found machine identities outnumbering human identities by 109 to one, up from 82 to one twelve months earlier, and nine in 10 organisations in that dataset had experienced a successful identity-related breach that year. Mena Migally, Regional Vice President for EMEA East at Veeam, was working from the earlier ratio when we spoke, and the arithmetic holds either way, because offboarding one person or a thousand means multiplying by everything attached to them.

“Offboarding needs to be viewed as a cyber resilience and an organisational resilience process, with clear visibility into what identities we have, what privileges are given to them, what dependencies exist between them, and how we recover from any lapse,” Migally said.

The failure becomes acute at volume, according to Biju Unni, Vice President at Cloud Box Technologies, since access removal has to cover email, cloud platforms, APIs, management consoles, VPNs and source code repositories at once, and each revocation depends on somebody knowing that the access existed.

“While many companies still rely on manual processes, these approaches have proven inadequate, especially when large numbers of employees leave at the same time,” Unni said.

Nobody disables an account they cannot explain

Human accounts represent the governed portion of the estate, and everything else operates at the edge of institutional visibility. The 2026 Palo Alto Networks research found 61% of privileged access requests fulfilled with standing privilege rather than granted on demand, CyberArk reported that 88% of organisations apply the definition of a privileged user solely to humans even though 42% of machine identities hold sensitive access, and Gartner found identity teams responsible for only 44% of an organisation’s machine identities.

Cheryl Martin, CISO at C86, reduces the resulting deadlock to the question that determines whether an account survives a restructuring, and the answer sets the size of whatever attack surface remains.

“Most organisations can identify departing employees. Far fewer can confidently identify every service account, API key, cloud token, certificate or automation credential those individuals created,” she said. “The question many struggle to answer is simple: what business service will fail if we disable this account? When nobody knows the answer, access is rarely removed.”

Physical assets are recovered within days, whereas the digital residue accumulates as certificates, SSH keys and service accounts that survive on institutional caution alone, and Unni described a stalemate in which teams decline to close an account they suspect is dormant, because the consequences of being wrong fall on production.

“Managing machine identities can be challenging since they often lack a single owner or clear ownership,” Unni said. “This creates orphaned accounts, and concerns about disrupting production if they are disabled without a full understanding of their dependencies.”

Migally locates the sharpest exposure a level below that stalemate, among identities that were never inventoried at all.

“The greater risk is that there are identities, especially the machine identities, that might not be known in the first place, and that were created and managed by those individuals,” he said. “When you are offboarding hundreds or thousands, these assets can become orphaned. They are overprivileged, they are poorly governed, and they are creating blind spots that an external attacker can use, expanding the attack surface long after that employee has left.”

Maude divides the estate into three tiers, describing human accounts as generally well handled, shared and embedded credentials as patchily handled, and machine identities as barely handled at all, with the organisations BeyondTrust works with typically running between 50 and 100 non-human identities for every human one.

He points to the Midnight Blizzard intrusion at Microsoft, where a compromised test account carried a service principal with privileged access into the corporate environment, and to the Colonial Pipeline breach, where a single dormant VPN account without multi-factor authentication, using a password recovered from an earlier breach, preceded the shutdown of a pipeline supplying close to half the fuel on the US East Coast.

Verizon’s 2026 Data Breach Investigations Report, built from more than 22,000 confirmed breaches across 145 countries, found credential abuse somewhere in the attack chain in 39% of them, the most pervasive technique in the dataset even after vulnerability exploitation overtook it as the leading initial access vector at 31%. Paramasivam described the access that escapes the inventory in the first place.

“When technical staff leave, they often hold access to systems that are not centrally documented: shared credentials, service accounts set up for a specific project, API keys tied to their personal work email instead of a group address,” he said. “Full visibility into who or what has access to which system remains one of the most underinvested areas in enterprise security.”

The most expensive asset lost in a restructuring is the reason things were built the way they were

Documentation survives a departure reliably, while the reasoning behind it rarely does, and the gap determines how an organisation performs during its next incident. IBM recorded a mean of 241 days to identify and contain a breach in 2025, months a reduced team spends reconstructing an environment somebody else designed, since firewall exceptions and integrations built under deadline pressure carry a history that lives with a handful of people.

“Institutional knowledge becomes an invisible layer of resilience for the organisation,” Migally said. “The vulnerability is no longer the absence of technology; it is the absence of operational understanding.”

Martin drew the distinction that decides whether an architecture remains governable once its architects have gone.

“Documentation explains what a system does; institutional knowledge explains why it exists,” she said. “If critical security knowledge exists primarily in the minds of a few individuals, the organisation carries a hidden dependency that may only become apparent after they leave.”

None of the practices involved is novel, since guidance from the NCSC, SANS and NIST converges on identity governance, least privilege and account lifecycle management as foundational controls, and the organisations that come through a reduction without incident run the same sequence before anybody leaves, covering rapid removal of access, asset recovery, credential rotation, monitoring, and a documented handover of identities to named teams. Unni contrasts that with the alternative, where the same questions are asked later and under worse conditions.

“Organisations that fail to document credentials and rely instead on outdated records, forgotten credentials and unnecessary access often face significant issues, which typically surface only during a security incident or an audit,” he said.

The exposure extends past whichever company is cutting, and the sharpest version has surfaced in the crypto sector during 2026, where Crunchbase recorded two blockchain companies ceasing operations entirely within a single reporting period. A dissolved company retains nobody who can answer an ownership question, while its API integrations into partner platforms and its certificates keep authenticating until they expire, and Verizon found third-party involvement in 48% of confirmed breaches in 2026, a 60% increase year on year.

Martin pushes the exercise past the perimeter for that reason, into a supply chain where identical reductions are running unobserved.

“Boards should be asking not only which employees are leaving, but what critical access, dependencies and knowledge are leaving with them,” she said. “If this mass departure is occurring in one of our critical suppliers, how immune are the services, solutions and processes that we depend on?”

Maude points to continuous identity inventory rather than quarterly access reviews, ownership assigned to every non-human identity at the moment it is created so that a departure triggers reassignment automatically, and movement towards zero standing privilege, where access is granted just in time and withdrawn once used.

“If you can offboard one person cleanly today, with basically no notice, and you understand what all the exposure is, then you are in reasonable shape,” he said. “If you could not do that within 24 hours, you know you have a challenge.”

Sequencing is where most offboarding programmes come apart, since the security function is typically consulted after the decisions have been taken.

Access revocation needs to happen in real time, and every system that person touched needs to be accounted for, not just the obvious ones. Security and IT need to be part of that conversation from the start.”

The six o’clock lockout is the straightforward part and the part almost every organisation now performs competently, while the scheduled job written four years ago runs at six o’clock as well, untouched by anything in the morning’s sequence and answerable to nobody still employed.

Sindhu V Kashyap

Global Technology Journalist & Multimedia Storyteller | Covering Founders, Investors & Leaders Reshaping Tech | Writer · Interviewer · Moderator · Editor

Next
Next

Attackers have stopped hunting for vulnerabilities and started hunting for relationships