The Friday afternoon that cost Halcyon Freight Brokers $340,000
Derek Voss was fired on a Friday at 4:15 p.m.
He'd been regional sales operations manager at Halcyon Freight Brokers, a 180-person logistics brokerage outside Charlotte, for six years. HR had spent three weeks building a case: falsified customer rebate records that had quietly diverted roughly $60,000 in credits to accounts he controlled through a relative. When the CFO finally confronted him, Derek didn't deny it. He was walked out with a box of desk items and a stern reminder that his signed confidentiality agreement — buried somewhere in his onboarding paperwork from 2020 — was "still in effect." Nobody could tell him exactly what that meant, and frankly, nobody in the room had read it recently either.
HR sent the standard termination notice to IT that afternoon. It sat in a shared inbox that nobody checks after 3 p.m. on Fridays. The offboarding ticket wasn't opened until Monday morning at 9:40 a.m.
In the gap between Friday afternoon and Monday morning, Derek logged into Halcyon's CRM twice from his home laptop and once from a personal iPad that had been enrolled in the company's mail system eighteen months earlier under a "just this once" exception for a business trip — an exception nobody ever revoked, formalized, or reviewed. He exported the full regional customer contract list: 11,400 records, including negotiated pricing terms for Halcyon's twenty largest accounts. He synced the export to a personal Dropbox folder and, investigators later determined, forwarded a subset of it to a competing brokerage where he'd already accepted an offer.
By the time IT disabled his account Monday morning, the data was gone and the account was already logged in from an IP address nowhere near his home.
I was brought in six weeks later, after the second of Halcyon's anchor accounts — worth $1.2 million in annual freight volume between them — quietly moved to the competitor, which had somehow priced a bid within two dollars of Halcyon's actual margin. Between forensic investigation, outside counsel, breach notification to affected customers, and the lost accounts themselves, Halcyon's board put the total cost of that weekend at just north of $340,000, not counting the reputational damage that doesn't show up on an invoice.
Here's the part that made this a genuinely painful engagement rather than a merely expensive one: every individual person at Halcyon had, in isolation, done something defensible. HR followed a termination process. IT eventually disabled the account. Derek had, in fact, signed an NDA. What Halcyon didn't have was the connective tissue between those actions — a disciplinary process that triggered a security response, a defined offboarding timeline with teeth, a confidentiality obligation anyone had actually reinforced, and any governance at all over the personal devices Derek used to do his job remotely. Four separate gaps, each one a distinct ISO 27001 control, each one small enough to seem forgivable on its own and catastrophic in combination.
Controls 6.4 through 6.7 exist precisely for this seam — the point where an employment decision becomes a security event. This article walks through all four: a formal disciplinary process (6.4), the responsibilities that survive termination or a change of role (6.5), confidentiality and non-disclosure agreements (6.6), and the security measures that protect information when people work outside your walls (6.7).
Who this is for
This is written for HR leaders, information security managers, and the ISO 27001 implementers who have to get HR and IT to agree on a joint procedure — usually for the first time. If you're building or auditing your ISMS and your organization has ever fired someone, changed someone's role, had someone sign an NDA, or let anyone work from home, these four controls apply to you; there's no scoping them out. By the end, you'll have a disciplinary procedure tied directly to security policy violations, an offboarding and role-change checklist with named owners, an NDA framework covering who signs what and when it gets refreshed, and a remote and hybrid working security standard built to survive an external audit.
The four controls at a glance
Controls 6.4 through 6.7 sit inside Annex A's People controls theme (6.1–6.8), and they're the back half of the employee lifecycle — the part that runs from "something went wrong" through "this person no longer works here or no longer has this role" through "this person is now working from a kitchen table in another city." I've found organizations that nail 6.1–6.3 (screening, terms of employment, and awareness training — see the People Controls Overview) frequently stumble here, because these four controls require HR, Legal, IT, and line managers to move in lockstep, and most organizations have never built that muscle.
Control | Name | Core question it answers | Primary owners |
|---|---|---|---|
6.4 | Disciplinary process | What happens, fairly and consistently, when someone violates security policy? | HR, Legal, Information Security |
6.5 | Responsibilities after termination or change of employment | What obligations survive when someone leaves or changes roles, and who enforces them? | HR, IT Security, Line Manager |
6.6 | Confidentiality or non-disclosure agreements | What confidentiality commitments are documented, current, and enforceable? | Legal, HR |
6.7 | Remote working | What protects information when it's accessed, processed, or stored off-premises? | IT Security, Line Manager |
Each of these controls has natural touchpoints elsewhere in Annex A. 6.5 leans directly on access rights removal under control 5.18 and on return of assets under control 5.11. 6.7 leans on user endpoint device management, control 8.1, and on the terms established at onboarding under control 6.2, terms and conditions of employment. Keep that web of cross-references in mind as we go — auditors will follow it, and so should you. If you're still building out the terminology behind these cross-references, our ISO 27001 Glossary of Terms is a fast way to get every stakeholder speaking the same language before the disagreements start.
Control 6.4: Disciplinary process, done fairly and consistently
ISO 27002:2022's guidance on control 6.4 is blunt about the goal: personnel and other relevant interested parties who commit an information security policy violation need to face formal, communicated, consistently applied consequences. Not because ISO 27001 wants organizations to be punitive — the standard is explicit that the process should account for factors like the nature and gravity of the violation, its impact, whether it was a first offense or a pattern, whether the person was adequately trained, and applicable legal, statutory, and contractual obligations — but because the absence of a process is what actually creates risk.
I've sat through more employment tribunals and internal investigations than I'd like as an expert witness, and the pattern is depressingly consistent: it's almost never the disciplinary action itself that gets an organization in legal trouble. It's the inconsistency. Two employees commit functionally the same violation — say, both email a spreadsheet of customer data to a personal account — and one gets fired while the other gets a verbal warning, with the difference explained by nothing more defensible than "the manager liked one of them better." That's not a security failure anymore; it's a discrimination claim waiting to happen, and I'll walk through exactly this scenario in the case studies below.
"The auditors don't actually care whether you fired someone or gave them a warning. They care whether you can show me the same violation got the same response six months apart, across two different departments, with two different managers. That consistency is the entire control." — Priya Natarajan, CISO, Bellwether Health Systems
Building a defensible process
A defensible disciplinary process under 6.4 has five components, and I insist on documenting all five as a single procedure rather than scattering them across an HR handbook and a security policy that never reference each other.
Step | Owner | Timeframe | Output |
|---|---|---|---|
1. Detection and reporting | Any employee, security team, monitoring tooling | Immediate | Incident or violation report logged |
2. Triage and severity classification | Information Security + HR jointly | Within 1 business day | Severity tier assigned, investigation scope defined |
3. Investigation | HR, Legal, IT Security (evidence collection) | Proportionate to severity, typically 3–15 business days | Documented findings, evidence preserved |
4. Decision and action | HR with Legal sign-off; Information Security consulted | Within 5 business days of investigation close | Documented decision with rationale, linked to policy clause violated |
5. Communication and record-keeping | HR | At time of decision | Written notice to individual, confidential case file retained |
Notice that step 1 deliberately overlaps with your incident management process under controls 5.24–5.28 — a policy violation discovered through log monitoring or a colleague's report often is a security incident before it's a disciplinary matter, and the two processes need a defined handoff point rather than running in parallel and duplicating (or contradicting) each other's findings.
Severity tiers keep the process consistent
The single highest-leverage document I build with clients for 6.4 is a severity matrix. It doesn't replace judgment — genuine edge cases will always need Legal and HR discretion — but it gives everyone a shared reference point before a real case forces the conversation under time pressure.
Tier | Example violations | Typical first response | Typical repeat response | Documentation required |
|---|---|---|---|---|
Tier 1 — Minor, unintentional | Leaving a workstation unlocked; misplacing a printed document internally | Verbal coaching, reference to awareness training | Written warning | Manager note in HR file |
Tier 2 — Moderate, negligent | Sharing a password with a colleague; ignoring a mandatory patch/update prompt repeatedly | Formal written warning, mandatory retraining | Suspension or final warning | HR case file, security team notified |
Tier 3 — Serious, willful | Disabling security controls (e.g., antivirus, MFA) to bypass friction; unauthorized data export | Suspension pending investigation, final written warning | Termination | Full investigation file, Legal review, evidence preserved |
Tier 4 — Severe, malicious or criminal | Data theft, fraud, sabotage, unauthorized access for personal gain | Immediate suspension, termination likely, law enforcement referral considered | Termination, referral to authorities | Full forensic evidence package, Legal and possibly regulator involvement |
I map every documented information security policy against this matrix during implementation, so that when someone violates the acceptable use provisions in the information security policy, there's no ambiguity about which tier applies before anyone's emotions are running high.
What auditors actually check
Certification auditors sampling control 6.4 rarely ask to see a specific termination case (though they may, with appropriate anonymization). More often they'll ask three things: does a documented disciplinary procedure exist and is it referenced in your information security policy suite; can you produce evidence that it's been communicated to personnel (typically through the same channel as your security awareness and training program under control 6.3); and can you show at least one real (or realistic, in a young ISMS) example of the process being followed end to end. If your organization genuinely hasn't had a policy violation since certification scope was defined, I still recommend a tabletop walkthrough documented as evidence — auditors respect a rehearsed process almost as much as a proven one.
Control 6.5: Responsibilities after termination or change of employment
Control 6.5 gets summarized in most training materials as "offboarding," and that's not wrong, but it undersells the scope. The control explicitly covers two distinct events: termination (voluntary resignation, involuntary termination, contract expiry, retirement) and change of employment (promotion, demotion, transfer, a contractor converting to employee, a change in job function that alters what systems and data someone needs). Most organizations have a reasonably mature process for the first and almost nothing for the second — and role changes are, in my experience, the more common source of access creep I find during gap assessments.
"Everybody remembers to offboard the person who quits. Almost nobody remembers to offboard the old role of the person who got promoted. Six months later they've still got warehouse-floor access from before they moved into finance, and nobody can tell me why." — Marcus Feld, HR Director, Kestrel Manufacturing
Termination vs. role change: different triggers, same discipline
Scenario | What must happen | Typical failure mode |
|---|---|---|
Involuntary termination (for cause) | Immediate access revocation, often same-day or same-hour; asset recovery scheduled before departure if possible | Delay between HR decision and IT notification (exactly the Halcyon gap) |
Involuntary termination (redundancy/layoff) | Access revocation timed with formal notice; asset recovery logistics (shipping labels, drop-off) | Bulk layoffs overwhelming IT's manual deprovisioning capacity |
Voluntary resignation | Access revocation effective last working day; NDA and post-employment obligations reiterated in exit interview | Long notice periods leaving access live for weeks with no re-review |
Contract/fixed-term expiry | Access set to expire automatically at contract end date | Manual processes forgetting contractors who were never in the automated HR feed |
Role change (promotion/transfer) | Old access removed, new access provisioned — not just added on top of the old | "Access accretion": new rights granted, old rights never removed |
Extended leave (parental, medical, sabbatical) | Access suspended or restricted for duration; reinstated on return with a fresh review | Access left fully active and unmonitored for months |
The offboarding and role-change checklist
This is the table I hand to clients and tell them to laminate. It exists to make sure the actions required by 6.5 are actually distributed across the controls that execute them — 6.5 defines the obligation, but 5.18 access rights and 5.11 return of assets do the operational work.
Task | Related control | Owner | Timing | Evidence retained |
|---|---|---|---|---|
HR notifies IT Security and line manager of departure/change | 6.5 | HR | Same day decision is finalized | Notification timestamp in HR/ITSM system |
Full inventory of systems, applications, and data the individual can access | 5.18 | IT Security | Prior to or on last day | Access review report |
Revoke or modify access rights (accounts, VPN, shared drives, SaaS apps, physical badges) | 5.18 | IT Security | Same day for involuntary termination; last working day otherwise | Deprovisioning ticket with timestamps |
Recall company-issued endpoint devices (laptop, phone, tokens) | 5.11 / 8.1 | Line manager / IT | Last working day, or scheduled courier for remote staff | Signed asset return form |
Remove or wipe corporate data from any personal (BYOD) devices | 6.7 / 8.1 | IT Security | Same day as access revocation | MDM wipe confirmation |
Retrieve or invalidate physical assets: keys, access cards, uniforms, ID badges | 5.11 | Facilities / Line manager | Last working day | Signed asset return form |
Reiterate surviving confidentiality and NDA obligations in exit interview | 6.5 / 6.6 | HR | Exit interview | Signed acknowledgment |
Redirect or archive email and reassign ownership of shared files/accounts | 5.18 | IT Security | Within 1–3 business days | Ownership transfer log |
Update org chart, access registers, and asset registers | 5.9 / 5.18 | IT Security / HR | Within 5 business days | Updated register with version date |
Notify third parties/vendors who granted the individual direct access | 5.19 | IT Security | Within 3 business days | Vendor notification record |
Close out with confirmation to HR that all steps completed | 6.5 | IT Security | Within 5 business days | Signed-off offboarding checklist |
That last row matters more than it looks. Every audit finding I've written against control 6.5 traces back to the same root cause: no single person confirmed the checklist was complete. Individual steps got done in isolation, nobody closed the loop, and three months later a departed contractor's VPN credential was still technically live.
Offboarding flow across 6.5, 5.11, and 5.18
flowchart TD
A[Termination or Role Change Decision] --> B[HR Notifies IT Security and Line Manager]
B --> C[Access Inventory and Review — Control 5.18]
C --> D[Revoke or Modify System Access]
D --> E[Recall Endpoint Devices — Control 8.1]
E --> F[Return of Physical Assets — Control 5.11]
F --> G[Exit Interview: Reaffirm NDA and Post-Employment Duties — Control 6.5]
G --> H[Update Access and Asset Registers]
H --> I[IT Security Confirms Closure to HR]
I --> J{Role Change?}
J -->|Yes| K[Provision New Role Access — Least Privilege]
J -->|No| L[Archive Case File]Timing is the control
If I had to reduce control 6.5 to one design principle, it's this: the gap between the decision and the action is where all the risk lives. Halcyon's entire $340,000 loss happened inside a 64-hour gap between a Friday termination decision and a Monday IT ticket. I push every client toward a same-business-day SLA for involuntary terminations specifically, with access suspension (not necessarily full deprovisioning, which can wait for asset recovery) happening before the employee leaves the building, not after. For voluntary resignations with notice periods, I recommend a mid-notice access review — trimming access to only what's needed for a productive handover, rather than leaving full privileges live until the final day.
Control 6.6: Confidentiality and non-disclosure agreements
Control 6.6 requires organizations to identify, document, regularly review, and get personnel and relevant external parties to sign confidentiality or non-disclosure agreements that reflect the organization's actual protection needs. The phrase that trips people up is "reflect the organization's needs" — ISO 27001 isn't satisfied by a generic template pulled off the internet and signed once at onboarding. It wants an NDA framework that's deliberately scoped, reviewed, and current.
"I've reviewed hundreds of NDAs in litigation. The ones that hold up in court are never the longest ones — they're the ones that actually define what 'confidential' means for that specific business, instead of copying boilerplate from a template nobody customized." — Sana Okafor, Legal Counsel, Bramwell & Voss LLP
NDA types you actually need
Most organizations need more than one NDA template, and I typically build a small family of them rather than one document trying to cover every relationship.
NDA type | When used | Key parties | Typical duration |
|---|---|---|---|
Employee confidentiality agreement | Signed at onboarding, part of the employment contract or as a standalone document | Employer and employee | Duration of employment plus a defined survival period (often 3–5 years, sometimes indefinite for trade secrets) |
Contractor/consultant NDA | Signed before engagement begins, before any access is granted | Organization and contractor/consultant | Duration of engagement plus survival period, aligned to contract terms |
Mutual NDA | Used when both parties will exchange confidential information (e.g., due diligence, joint ventures, partnerships) | Two organizations | Fixed term of negotiation/relationship plus survival period |
Unilateral (one-way) NDA | Used when only the organization is disclosing (e.g., to a prospective vendor evaluating a solution) | Organization (discloser) and third party (recipient) | Fixed term, often 1–3 years |
Executive/board-level NDA | Signed by directors, executives, or advisors with access to strategic, financial, or M&A information | Organization and executive/board member | Duration of role plus extended survival period given sensitivity |
What a defensible NDA actually contains
I keep a standing checklist of the clauses an NDA needs to be enforceable and useful, not just present. This isn't legal advice — every NDA should be reviewed by qualified counsel in the relevant jurisdiction — but it's the practical content list I bring to that legal review.
Clause | Why it matters |
|---|---|
Clear definition of "confidential information" | Vague definitions are the single most common reason NDAs fail to hold up; tie the definition to your information classification scheme under control 5.12 |
Explicit exclusions (publicly available info, independently developed info) | Protects enforceability and shows the agreement is reasonable, not overbroad |
Obligations of the receiving party | What they must and must not do with the information |
Duration of confidentiality obligation, including post-relationship survival | Confidentiality that expires the day someone leaves is functionally worthless |
Permitted disclosures (e.g., legally compelled disclosure, disclosure to auditors) | Prevents the agreement from being technically breached by legitimate activity |
Return or destruction of information on termination | Ties directly to control 5.11, return of assets |
Remedies and governing law | Establishes what happens on breach and where disputes are resolved |
Signature, date, and version reference | Enables the review cadence below — an unversioned NDA can't be tracked |
Review cadence: NDAs are not sign-once documents
The "regularly review" language in control 6.6 is often the part organizations skip entirely, because it's easy to treat a signed NDA as a permanent artifact. I build the review cadence around defined triggers rather than a blanket annual review of every signed document, which doesn't scale past a few hundred people.
Trigger | Review action | Owner |
|---|---|---|
New hire onboarding | Sign current version of employee confidentiality agreement | HR |
Role change granting access to new sensitivity tiers | Sign supplemental confidentiality acknowledgment scoped to new data | HR / Line manager |
New contractor/vendor engagement | Sign contractor NDA before any system or data access is granted | Procurement / Legal |
Annual policy review cycle | Legal reviews NDA templates against current legal, regulatory, and business context | Legal |
Material change in law or jurisdiction | Ad hoc review and re-issuance where required | Legal |
Termination or offboarding | Reaffirm ongoing obligations in exit interview, provide copy of surviving terms | HR (as part of the 6.5 checklist above) |
Organizations building a full ISMS documentation set often want to go deeper into NDA drafting than a single section here can cover — templates for each relationship type, jurisdictional variations, and specific trade secret language are worth their own reference, which is exactly what our dedicated Control 6.6: Confidentiality and NDAs guide covers.
Control 6.7: Remote working
Control 6.7 requires security measures whenever personnel work remotely, to protect information that's accessed, processed, or stored outside organizational premises. Since 2020, this control has gone from a niche requirement mostly relevant to field sales and traveling executives to one of the highest-risk controls in the entire framework for most organizations, because "remote" now describes a meaningful fraction of the workforce, not an edge case.
"Remote working used to mean a VP checking email from a hotel lobby twice a year. Now it means forty percent of my workforce processing customer data from home networks I have zero visibility into. The risk didn't get smaller when it became normal — it got bigger and quieter." — Tom Reyes, IT Security Manager, Duvalier Logistics
The risk landscape remote work actually creates
Home and hybrid work introduce risks that simply don't exist inside a controlled office: unmanaged home networks (a router that hasn't been patched in three years, sitting on the same network as a smart TV with known vulnerabilities), shared living spaces where screens are visible to family members or roommates, public Wi-Fi at cafés and airports, devices left in vehicles or hotel rooms, and — as with Derek Voss's iPad — informal exceptions to device policy that never get formalized or reviewed. None of these are exotic; they're the ordinary conditions of working from somewhere that isn't the office, and control 6.7 exists to make sure "ordinary" doesn't mean "unmanaged."
The remote working control stack
I organize remote working controls into four layers, because trying to solve "remote work security" as one undifferentiated problem produces vague policies nobody can actually implement. Each layer has a distinct owner and distinct tooling.
Layer | Control objective | Implementation examples | Related Annex A control |
|---|---|---|---|
Device | Only managed, secured endpoints process organizational data remotely | Full-disk encryption, mandatory OS and patch updates, endpoint detection and response, screen-lock timeout, remote wipe capability | 8.1 User endpoint devices |
Network | Connections to organizational systems are authenticated and encrypted | Mandatory VPN or zero-trust network access, MFA on all remote logins, prohibition or restriction of public Wi-Fi for sensitive work, secured home router baseline guidance | 8.20 Networks security, 8.5 Secure authentication |
Physical | Information isn't exposed through the physical environment the person works in | Privacy screens, clean desk practice at home, locking devices when unattended, guidance on confidential calls in shared spaces | Aligned with physical controls theme (7.x) applied to a non-organizational location |
Data | Information itself remains protected regardless of where it's processed | Restriction on local storage of sensitive data (cloud-only processing where feasible), data loss prevention tooling, classification-aware access restrictions | 8.12 Data leakage prevention, 5.12 Classification of information |
Control 8.1 (user endpoint devices) doesn't yet have a standalone deep-dive in this series, so treat the device-layer guidance above as the working baseline until that technological controls coverage is published.
Home, hybrid, and travel: not the same risk profile
Not every remote scenario deserves the same controls. I've seen organizations write a single "remote work policy" that's simultaneously too strict for someone working from a spare bedroom and too loose for someone working from an airport lounge.
Scenario | Primary risks | Baseline controls |
|---|---|---|
Fixed home office | Household network security, shared device access, family/visitor exposure | Managed router baseline guidance, screen lock policy, dedicated work device |
Hybrid (office + home, irregular) | Devices moving between environments, inconsistent connectivity, physical loss in transit | Full-disk encryption, cable locks or secure transport bags, VPN required outside office network |
Business travel (domestic) | Public Wi-Fi, shoulder-surfing in transit, device left unattended in hotels | Mandatory VPN, privacy screen, hotel safe usage guidance, no sensitive calls in open areas |
International travel | All of the above, plus border search risk, foreign surveillance risk, data residency/export concerns | Loaner/burner devices for high-risk destinations, minimal data at rest, legal review of destination-specific risk |
Field/customer-site work | Access from client networks, physical document handling on someone else's premises | VPN mandatory before any access, no use of client-provided Wi-Fi for internal systems, document handling procedure |
A note on BYOD
Bring-your-own-device arrangements sit at the collision point of controls 6.7 and 8.1, and they're where I find the most policy-reality gaps. Organizations frequently have a written policy prohibiting or tightly restricting BYOD, and a parallel informal reality — exactly like Derek Voss's iPad — where individual exceptions get granted verbally, never documented, and never revisited. If you're going to allow BYOD at all, do it deliberately.
BYOD approach | What it requires | Risk if ungoverned |
|---|---|---|
Prohibited entirely | Technical enforcement (conditional access blocking unmanaged devices), clear policy communication | Shadow IT: employees route around the prohibition using personal devices anyway |
Allowed with MDM enrollment | Mobile device management agent, minimum OS version, remote wipe capability, containerized corporate data | Employees resist enrollment due to privacy concerns over personal device |
Allowed for email/calendar only, no document access | Conditional access policies scoped narrowly, app-level protection | Scope creep — "email only" quietly expands to file access over time |
Fully unmanaged (not recommended) | None — by definition ungoverned | Exactly the Halcyon Freight Brokers scenario: an unmanaged personal device with live access and no offboarding hook |
If BYOD is allowed under any model, it needs to appear explicitly in your terms and conditions of employment under control 6.2 and in the offboarding checklist above — a personal device enrolled for corporate access is an asset that has to be un-enrolled at termination just as reliably as a company laptop has to be returned.
Common mistakes across 6.4–6.7
I see the same handful of failure patterns across nearly every organization I assess, regardless of industry or size.
Mistake | Why it happens | Fix |
|---|---|---|
Disciplinary action taken with no reference to a documented policy clause | HR and Legal handle discipline as an employment-law matter disconnected from the ISMS | Every disciplinary decision cites the specific security policy clause violated |
Offboarding treated as an IT ticket instead of a cross-functional checklist | No single owner accountable for confirming full completion | Assign an offboarding checklist owner (see the table above) who signs off completion |
NDAs signed once at onboarding and never revisited | "Set and forget" mentality treats signature as a one-time compliance box | Trigger-based review cadence (new role, new engagement, annual legal review) |
Remote work policy exists but BYOD exceptions are granted informally outside it | Managers want to be helpful and grant one-off access without going through IT | Formal exception process with expiry date and mandatory review |
Role changes update systems access but never revoke the old role's access | Provisioning teams add new access on request; nobody proactively removes old access | Treat every role change as a mini-offboarding: remove first, then provision |
Remote working policy assumes a home office and doesn't address travel or field work | Policy written before hybrid/travel became common, never updated | Segment the policy by scenario, as in the home/hybrid/travel table above |
Disciplinary severity varies by manager rather than by violation | No shared reference point exists before a real case forces the decision | Adopt and train on a severity matrix (see the Tier 1–4 table above) |
Case studies
Halcyon Freight Brokers: closing the offboarding gap
I've already walked through what went wrong at Halcyon. What matters for this article is what changed afterward. Working with their HR and IT leadership, we rebuilt the termination-to-deprovisioning path as a same-business-day SLA: HR's termination decision now triggers an automated, time-stamped ticket to IT Security the moment it's finalized in the HR system, not a manually forwarded email. Access suspension for involuntary terminations happens before the employee is informed, not after. Every device — company-issued or the handful of formally approved BYOD exceptions — is now tracked in an asset register with an explicit revocation step tied to the offboarding checklist. Eighteen months after implementation, Halcyon has processed eleven involuntary terminations and thirty-four voluntary departures with zero repeat incidents, and their cyber insurance renewal premium dropped 12% after the insurer's underwriter reviewed the new offboarding evidence during renewal.
Solenne Cosmetics: a laptop, a café, and a delayed launch
A mid-market cosmetics brand I'll call Solenne Cosmetics had a marketing manager working from a café ahead of a major product launch. She stepped away from her table for roughly four minutes to collect an order; her laptop, unlocked and displaying the unreleased Q3 product roadmap, was gone when she returned. The laptop wasn't encrypted at the disk level — a gap that predated any formal remote work policy — and while the company couldn't confirm the data was actually exfiltrated rather than the device simply being resold for hardware value, they had no way to prove it hadn't been, which under their disclosure obligations meant treating it as a confirmed exposure. Incident response, forensic device-history review, and legal consultation cost roughly $85,000, and the product team elected to shift the launch timeline by seven weeks out of caution about competitive positioning — a delay Solenne's own finance team estimated cost approximately $400,000 in lost first-mover advantage. The fix was almost embarrassingly basic: mandatory full-disk encryption enforced through device management before any laptop could connect to corporate systems, a screen-lock timeout reduced to two minutes, and a remote working policy that explicitly required devices to be secured (locked, out of sight, or on the person) whenever unattended in a public space. Solenne's next annual audit cited this as a positive corrective action closure rather than a finding.
Prairie Grain Cooperative: the inconsistency that became a lawsuit
Prairie Grain Cooperative, an agricultural cooperative with about 400 employees across several regional offices, had two employees in different offices independently email spreadsheets containing member financial data to their personal accounts — both, they later stated, intending to "work on it over the weekend," a rationalization neither of us found persuasive but which mattered less than what happened next. One employee, in an office where the branch manager was risk-averse and had recently read about a data breach in the trade press, was terminated the same week. The other, in a different office under a different manager, received a verbal warning and no documentation at all. Eleven months later, the terminated employee filed a discrimination claim, correctly pointing out that the disparate treatment for materially identical conduct had no documented rationale — because none existed. Prairie Grain settled for $210,000 rather than litigate a case they knew they'd struggle to defend, given they had no severity matrix, no documented process, and no record of the second employee's incident at all. Post-settlement, we built exactly the kind of tiered severity matrix described earlier in this article, trained every manager and HR partner on it, and made joint IT Security and HR sign-off mandatory for any Tier 3 or Tier 4 decision — removing individual managers' discretion on the cases where discretion had proven most dangerous.
Roles and responsibilities across the four controls
Because these controls cut across HR, Legal, IT Security, and line management, I always document an explicit responsibility matrix rather than assuming it's obvious who owns what.
Activity | HR | IT Security | Line Manager | Legal | DPO/Privacy |
|---|---|---|---|---|---|
Classify severity of a policy violation | Consulted | Accountable (jointly with HR) | Informed | Consulted | Informed if personal data involved |
Investigate a disciplinary matter | Accountable | Supports (evidence/logs) | Consulted | Consulted | Consulted if personal data involved |
Revoke access on termination | Informs | Accountable | Informed | — | — |
Recover physical/technical assets | Informed | Supports | Accountable | — | — |
Draft and maintain NDA templates | Consulted | Consulted | — | Accountable | Consulted |
Trigger NDA re-signature on role change | Accountable | Informed | Consulted | Consulted | — |
Approve BYOD exceptions | Informed | Accountable | Requests | — | Consulted |
Maintain remote working policy | Consulted | Accountable | Informed | Consulted | Consulted |
Evidence auditors expect to see
When a certification body auditor samples these four controls, I brief clients to have a specific evidence packet ready rather than scrambling to assemble it during the audit itself.
Control | Documentary evidence | Operational evidence |
|---|---|---|
6.4 | Documented disciplinary procedure; reference in information security policy; training records | At least one worked example (real or tabletop) of the process end to end |
6.5 | Offboarding/role-change procedure; termination checklist template | Sample of completed offboarding checklists with timestamps; access review logs |
6.6 | NDA templates by relationship type; review cadence policy | Signed NDA register; evidence of re-signature on role change or new engagement |
6.7 | Remote working policy; BYOD policy (if applicable) | MDM enrollment records; VPN/MFA enforcement configuration; device encryption compliance report |
Most of this evidence should already exist as a natural byproduct of your Statement of Applicability documentation and your broader mandatory documents set — if you're still assembling that baseline, our Mandatory Documents Checklist walks through exactly what a certification body expects to find, control by control. Before your next surveillance audit, it's also worth running this evidence packet against our Internal Audit Checklist, which includes a dedicated section for People controls sampling.
Turning the back half of the employee lifecycle into a business advantage
It's tempting to treat controls 6.4 through 6.7 as pure compliance overhead — the unglamorous paperwork of firing people, taking back laptops, and telling remote workers to lock their screens. I'd push back on that framing. Every one of the case studies above is really a story about operational maturity, not just security: Halcyon's insurer rewarded their rebuilt offboarding process with a lower premium; Prairie Grain's disciplinary consistency directly reduces their employment litigation exposure going forward, independent of any security benefit; and Solenne's encryption mandate protects intellectual property regardless of whether the threat is a stolen laptop or a lost one. These controls, done well, make an organization more defensible in front of a regulator, more attractive to enterprise customers running vendor security questionnaires, and measurably less exposed to the kind of six-figure incident that tends to follow a Friday-afternoon termination or an unlocked laptop in a café.
These four controls also sit at the intersection of ISO 27001 with other frameworks your organization may already be answerable to. A SOC 2 Type II audit will scrutinize your HR-and-offboarding evidence trail almost identically to how an ISO 27001 auditor does — a well-run SOC 2 offboarding and termination control satisfies much of the same evidence expectation. And if your remote workforce processes personal data of EU residents, your remote working controls under 6.7 directly support your GDPR obligations around technical and organizational security measures, since a lost unencrypted laptop containing personal data is a notifiable breach under GDPR regardless of what ISO 27001 says about it.
If you're building out this part of your ISMS from scratch, don't try to solve all four controls simultaneously with a single sprawling policy document. Start with the disciplinary severity matrix and the offboarding checklist — they're the two most likely to surface a real gap immediately, exactly as they did at Halcyon and Prairie Grain — then layer in the NDA review cadence and the remote working control stack once the personnel foundation is solid. Our Information Security Policy Template includes starting language for all four of these controls that you can adapt to your organization's actual risk profile rather than writing from a blank page, and PentesterWorld's Complete ISO 27001 Implementation Guide walks through sequencing these People controls against the rest of your Annex A rollout.
"The organizations that pass their audit on these controls without a finding are never the ones with the fanciest policy document. They're the ones where I ask an HR generalist and an IT admin the same question about a hypothetical termination and get the same answer from both of them." — Elena Castillo, Internal Auditor, Northgate Assurance
"We rebuilt our BYOD program after a near-miss that never made it into a case study anywhere, thankfully. The lesson that stuck with my team wasn't 'ban personal devices.' It was 'nothing informal survives contact with an offboarding.' If it's not in the register, it's not going to get revoked." — Diego Marsh, Head of People Ops, Fenwick Digital
If your organization is still mapping how these four controls fit into your broader Statement of Applicability, or you want a second set of eyes on whether your disciplinary and offboarding evidence would hold up under a certification body's scrutiny, PentesterWorld's ISO 27001 advisory team runs exactly this kind of gap assessment — reach out and we'll walk your HR and IT Security leads through a joint readiness review before your auditor does.
