GCC Offboarding Gaps: Hyderabad's Quiet Cybercrime Epidemic
Hyderabad's IT corridor now hosts dozens of global capability centers, and a specific dispute pattern has become recurring rather than exceptional: a departing employee's system access — repositories, internal tools, shared drives — is not revoked on the actual exit date, because offboarding sits split across HR and IT functions that don't always communicate on the same timeline, especially during high-volume hiring and attrition periods.
The legal exposure this creates runs in both directions. A company that discovers post-termination access used inappropriately has a genuine Section 66 unauthorized-access claim, but only if it can actually prove the access occurred after termination rather than during a legitimately overlapping notice period — a distinction that becomes genuinely difficult to establish once the company's own offboarding delay has made the timeline ambiguous.
An offboarding gap doesn't just create a security risk. It creates an evidentiary problem that undermines the company's own legal position if the access is ever actually misused.
For companies operating in this corridor, the practical fix is less about legal strategy and more about operational discipline: access revocation tied automatically to the HR exit-interview timestamp, not to a separate IT ticket that can lag by days; and access logs retained for a defined minimum period specifically because they are the evidence that determines whether a dispute, if it arises, is even winnable.
As hiring velocity in the corridor continues, this is not a risk that resolves itself with better intentions. It resolves with a specific technical and procedural fix that most companies discover they need only after the dispute that made it necessary.