Data leaks by former employees: how to protect your SaaS
Someone resigned from your company this year. Do you remember cutting that person's access to Drive, the CRM, WhatsApp Business, the payments dashboard? All of them? On the same day? If the answer took more than two seconds, this article is for you. Data leaks by former employees are not just a giant's problem. But the giant of the moment helps show how big the hole is.
What Apple is saying, in plain English
In August 2026, Apple stated in court that more former employees may have taken confidential information to OpenAI. The case started with a hardware engineer who left for OpenAI and, according to Apple, copied files about unreleased products before walking out. Now the company says he wasn't alone.
Notice the detail: Apple has chip badges, monitored networks, a legal department the size of a building and an entire team dedicated to secrecy. Even so, the problem showed up afterwards. They found out by investigating, not by preventing.
If Apple couldn't stop it at the door, your company with 8, 20 or 50 people won't stop it at the door either. The right question is a different one: how much damage can one person do on the way out, and how long does it take you to notice?
Where the real risk lives in a small company
You probably don't have a secret chip to leak. But you do have things worth real money:
- The client list with phone numbers, average ticket and who renews when.
- The price table and the margins on each service.
- The prompts, automations and spreadsheets that keep the operation running.
- The shared passwords in that WhatsApp group from 2022.
I saw a case like this up close. A services company with about 15 employees. The salesperson left on good terms, hugs, cake, all fine. Three months later, clients started getting a proposal from a competitor with a discount calculated on the exact amount they were paying. The guy didn't hack anything. He just exported the CRM to a CSV in his last week, something he did every Monday to build a report. Nobody found it strange because it wasn't strange.
That's the point most people miss. A leak is rarely a hacker in a hoodie. It's the normal routine, done by someone who already has the key, a week before handing the key back.
Security isn't stopping the person from leaving with the file. It's making sure you know they left with it.
Why SaaS made this worse (and better)
Ten years ago, data lived on a server in the back room. Taking it with you took effort. Today your company runs on 12 different SaaS tools, each with its own login, and half of them have an "Export all" button in the corner of the screen.
It got worse because the friction to copy dropped to zero. It got better because almost every decent SaaS records what each user did. Exported something? There's a log. Downloaded 400 files at 11pm? There's a log. Shared a folder with an external email? There's a log.
The problem is nobody looks at the log. And then you become Apple: you find out from the damage, months later.
An offboarding checklist that fits on one page
You don't need to hire a consultancy. You need a boring, repeatable process. Mine, adapted for small businesses:
- Access inventory. A simple spreadsheet: person, tool, access level. If you don't know where the person has a login, you can't cut it. Do this today, before you need it.
- Centralized login whenever possible. Google Workspace or Microsoft 365 as the single door. Deactivate the account and everything hanging off it drops. One action instead of twelve.
- Zero shared passwords. If the company Instagram has a password four people know, it's already leaked. A password manager fixes this and costs less than one lunch a month.
- Minimum access per role. Sales sees their own clients. Finance doesn't need the marketing prompts. The less each person sees, the less each person takes.
- Cutoff on the same day as the notice. It's not distrust, it's procedure. Say this clearly at hiring and nobody gets offended later.
- Review of the last 30 days of logs. Exports, bulk downloads, external shares. It takes 20 minutes and it's where you find the CSV story before the competitor does.
- Confidentiality agreement signed on day one. It doesn't prevent anything. But it's the difference between being able and not being able to do something afterwards, which is exactly where Apple is right now.
"But I trust my team"
Great. I trust mine too. Trust and process don't compete. A seatbelt isn't an insult to the driver.
The most honest objection I hear is a different one: "I don't have time for this". I get it. That's why my favorite part of this topic is that it can be automated. A simple flow: when HR marks someone as offboarded in the spreadsheet, a bot deactivates the Google account, removes them from WhatsApp groups via API, revokes CRM access and sends you a summary of that person's recent activity. Once it's set up, you never forget again, because it doesn't depend on you remembering.
I build this kind of automation in one or two weeks for a small company. It's not a months-long project. It's stitching together tools you already pay for.
The lesson from the Apple case
Apple will spend millions on lawyers and maybe recover part of what it lost. You don't have that budget, so you need to win on cheap prevention. Inventory, single sign-on, minimum access, immediate cutoff, a look at the logs. None of that requires new technology. It requires deciding to do it.
And if you want to turn that checklist page into something that runs on its own while you take care of the business, that's the kind of problem I solve.
LinkedIn summary
Someone resigned from your company this year. Did you cut their access to Drive, the CRM, WhatsApp Business and the payments dashboard on the same day? Apple, with a legal department the size of a building, just found out that former employees took confidential information to OpenAI. Found out by investigating, not by preventing. I've seen the same movie at a 15-person company: a salesperson left with hugs and cake, and three months later clients were getting a competitor's proposal with a discount calculated on the exact amount they were paying. He didn't hack anything. He just exported the CSV he exported every Monday. A leak is rarely a hacker in a hoodie. It's the normal routine, done by someone who already has the key, a week before handing the key back. What works for a small company: an access inventory, single sign-on, minimum access per role, cutoff on the day of notice and 20 minutes looking at the last 30 days of logs. None of that requires new technology. It requires deciding to do it. If you want to turn that checklist into something that runs on its own, reach out. It's the kind of problem I solve. #InformationSecurity #SaaS #Automation #AccessManagement #SmallBusiness