Southwest Networks - Managed IT Services & Cybersecurity
Network Security · Cybersecurity · 7 min read

In Palm Springs: The Season Ends, But Their Logins Don't

By Matt Disher, CISSP, HCISPP ·
A Palm Springs hotel front desk with a manager reviewing employee access credentials on a desktop computer, stack of seasonal staff onboarding folders nearby, warm afternoon light through windows showing desert palms outside

When seasonal employees leave a Palm Springs hospitality business, their logins to systems like POS, email, and booking often stay active for months. These orphaned accounts are a serious security and cyber-insurance liability, and the fix is to disable each account the day the employee leaves and follow a documented offboarding checklist.

When the season wraps in Palm Springs, dozens of temporary employees head home. Their keys get turned in, their uniforms get returned, and their user accounts quietly stay active for months.

That last part is the problem.

Every seasonal hire accumulates accounts: point-of-sale, email, the booking system, the scheduling app, maybe a few others depending on the property. When April comes and the staff disperses, those accounts rarely get closed. Nobody is malicious about it. Offboarding just falls through the cracks when everyone is exhausted from a long season and scrambling to close things down. An active account attached to a former employee is an open door, and attackers know exactly how to find unlocked doors. In thirty years securing Coachella Valley businesses, it is one of the most common gaps we find when we first audit a Palm Springs hospitality property.


Why Orphaned Accounts Are a Real Problem

An orphaned account is any login that still works after the person who used it no longer works there. The former employee might never touch it again. But someone else might.

Credentials get reused across sites. People share passwords with friends or family members. Disgruntled ex-employees sometimes stay curious about their old workplace. And phishing attacks that target former employees still work fine if the account is active. None of these scenarios require sophisticated hacking. They just require an account that should have been closed but wasn’t. Stolen and reused credentials are consistently among the top ways attackers get in. The Verizon Data Breach Investigations Report has ranked the use of stolen credentials as a leading breach action year after year.

Hospitality businesses are particularly exposed because staffing spikes so dramatically with the season. A property that runs with five year-round employees might bring on thirty more between October and March. That’s thirty sets of accounts cycling in and out. If even half don’t get fully deprovisioned, you end up with a lot of open doors by the time summer arrives.

Beyond the security exposure, orphaned accounts show up as a documented failure on most cyber insurance applications. Carriers ask direct questions about access control and offboarding practices. “We close accounts when we remember to” is not a reassuring answer, and underwriters know exactly what seasonal businesses look like from the inside.


The Shared Login Problem

Before getting into offboarding, there’s a conversation worth having about shared logins, because they’re common in hospitality and they undercut everything else.

A shared login is when multiple employees use the same username and password to access a system. One POS login for the whole front desk. One email account that three managers check. One set of booking credentials written on a sticky note near the terminal.

Shared logins feel practical. In a fast-moving hospitality environment, they seem to reduce friction. The problem is that you lose all visibility into who actually did what. If something goes wrong and you need to trace it, you can’t. Everyone touched that account, so nobody is individually accountable.

They also make offboarding nearly impossible to execute cleanly. When one employee leaves, do you change the shared password and push it out to everyone still using it? Do you just leave it, knowing the departing employee still has access? Neither answer is good, and you’re stuck making that call every single time someone walks out the door.

Individual accounts for each employee solve this. Yes, that creates more accounts to manage. It also means when someone leaves, you close one account that belonged to one person, and everyone else’s access is unaffected.


The Offboarding Checklist

Offboarding should not be a memory exercise. It should be a list you run through every time someone leaves, regardless of how busy things are or how the parting went.

Recognized security frameworks expect exactly this. The CIS Critical Security Controls call for maintaining an inventory of user accounts and disabling dormant ones promptly, precisely so orphaned logins don’t linger after someone leaves.

The basics:

  1. Disable the account immediately, not at the end of the week, not after their last shift, but the day they leave.
  2. Revoke access to every system they used: POS, email, booking, scheduling, property management, any third-party apps connected to the business.
  3. Remove them from shared drives and document folders.
  4. Retrieve any physical access items: keys, keycards, access codes, company devices.
  5. Change any shared passwords they had access to (which is another reason to avoid shared logins entirely).
  6. Check for personal devices connected to business systems. Some employees sync company email or apps to their personal phones when they first start.

That last item gets missed often. Disabling the account handles the phone access too, which is one more reason the account should go down promptly rather than sitting in some kind of grace period.

The checklist should live somewhere accessible, not just in someone’s head. It should be part of how every departure is handled, whether the person is a seasonal hire finishing their contract or a year-round employee leaving unexpectedly.


Why MFA Doesn’t Solve This

Multi-factor authentication is worth having. For active accounts belonging to current employees, it adds a meaningful layer of protection. But MFA is not a substitute for closing accounts that should be closed.

An orphaned account still works if the former employee still has access to their authentication method. If they set up MFA on their personal phone, they still have that phone. MFA protects against someone stealing credentials. It does not protect against the person who legitimately owns those credentials deciding to log in after they’ve left.

The account closure is the protection. MFA on an account you’ve left open is like putting a deadbolt on a door you’ve decided to leave permanently unlocked.


Running This as a Seasonal Rhythm

The goal is to make this a business process rather than a last-minute scramble. For a seasonal operation in the Coachella Valley, that means building the offboarding cadence into how the season ends.

A few things that help:

  1. Audit accounts before the season starts. Pull a list of every active user in your key systems before onboarding new staff. Close anything that shouldn’t still be active from the previous season. This takes maybe an hour and prevents last year’s problem from compounding into this year’s.
  2. Assign one person ownership. In a small hospitality business, nobody owns offboarding by default. It either falls to the GM, the owner, or whoever happens to be present. Naming one person as responsible for running the checklist means it actually gets done.
  3. Set a review date in March. Before the season fully closes out, schedule a specific day to audit active accounts against your current staff list. Any mismatch gets closed. Do this while you still have the bandwidth to do it right.
  4. Document what systems each hire gets access to during onboarding. This sounds bureaucratic, but it solves a real problem. When someone leaves, the question is never “which systems did they have?” because it’s already written down. Without documentation, offboarding becomes a reconstruction exercise, and you will miss things.

If nobody on staff has the bandwidth to own this, it is exactly the kind of thing a managed IT provider handles as a matter of routine. At Southwest Networks, Inc. our network security services include access control and user provisioning for hospitality and small businesses across Palm Springs and the wider Coachella Valley. We set up individual accounts, run the offboarding checklist when staff leave, and keep an auditable record your insurance carrier can actually see. As a CISSP- and HCISPP-certified team with a 15-minute average response time, that is the kind of gap we close before it becomes a claim.


The Insurance Angle

Cyber insurance applications ask about access control. Specifically, carriers want to know whether former employees lose access promptly when they leave. This is not a hypothetical risk category for them; orphaned accounts are a well-documented attack vector, and carriers have paid out plenty of claims that trace back to a login that should have been closed. The IBM Cost of a Data Breach report consistently finds that breaches involving stolen or compromised credentials are among the most common and the slowest to detect, which is exactly the profile of an orphaned account nobody is watching.

Businesses that can demonstrate a documented offboarding process are in a better position, both for getting coverage and for the rate they pay. Businesses that can’t tend to find the access-control questions uncomfortable.

Palm Springs properties are in a particularly visible position on this because of how dramatically staffing cycles. A carrier looking at a hospitality account in the desert knows exactly what seasonal hiring looks like. Showing that you manage it deliberately is worth something.


The season ending is a natural forcing function. Staff disperses, things slow down, and it’s easy to assume the security exposure goes with them. The accounts stay active until someone closes them, though. That part doesn’t happen on its own.

Running a clean offboarding process is mostly just remembering to do it and having a list to follow when you do. The properties that treat it as routine are the ones that don’t spend next October explaining to their insurance carrier how a former employee ended up back inside their systems.

FAQ

What is an orphaned account and why is it a security risk?

An orphaned account is any login that still works after the employee who used it has left the business. It’s a risk because the account can still be accessed: by the former employee, by someone they shared the password with, or by an attacker using reused or phished credentials. Because no current employee is watching it, a login through an orphaned account often goes unnoticed until damage is done.

How quickly should a former employee’s access be revoked?

The day they leave, not at the end of the week. Access to every system (POS, email, booking, scheduling, property management, and any connected third-party apps) should be disabled immediately, along with retrieval of keys, keycards, and company devices. A grace period is just an open door left open longer.

Does multi-factor authentication protect against orphaned accounts?

No. MFA protects an active account against stolen credentials, but it does nothing to stop the legitimate owner of those credentials from logging in after they’ve left, especially if they set up MFA on their own phone. Closing the account is the actual protection.

How does offboarding affect cyber insurance for a Palm Springs hospitality business?

Cyber insurance carriers ask directly about access control and how promptly former employees lose access. A documented offboarding process helps with both getting coverage and the rate you pay. Businesses that can’t demonstrate one tend to struggle with those questions, and orphaned accounts are a well-documented source of paid claims.


If you want a straightforward answer on where your network security actually stands, start with our FREE 15-minute call. We will look at what you have, tell you honestly what needs to change, and give you a clear picture of the cost before any work begins.

Southwest Networks, Inc. has protected Coachella Valley businesses since 1996. CRN MSP 500 (2024-2026), rated 4.9★ by our clients on Google.

Local IT Support in Palm Springs

See the specific managed IT services, local challenges, and response coverage we deliver in your area:

Ready to Protect Your Business?

Schedule a free consultation with our team. No obligation, no pressure — just a clear picture of where you stand.

Or take the free IT security assessment first — see exactly where you stand in minutes.