Key Takeaways
- The cause is structural: the gap between HR onboarding and IT provisioning opens security holes before the first working day even starts.
- Shadow IT is the symptom: impatient employees reach for personal tools and cloud services when the official IT setup takes too long.
- New hires are the target: attackers deliberately exploit the fact that new colleagues do not yet know how things work internally.
- Automation is the fix: deeploi sets up devices, accounts and access rights in 3–5 minutes, automatically and according to the rules you define, whether your company has no IT team at all or your IT team simply needs relief from routine work.
A new employee starts, but does not wait for IT. Their company account is not fully set up yet, so they download their own copy of Notion, log in with a personal ChatGPT account, or save documents to their private Google Drive. That is the moment shadow IT appears, and with it a very real security risk for your company.
Avoiding onboarding security risks therefore means more than getting the hardware there on time. It means setting up access, devices and accounts in a controlled and traceable way from the very beginning.
Why manual onboarding becomes a security risk
In many companies, HR onboarding and IT provisioning run on separate tracks. The contract is signed and the welcome pack is ready, but the laptop is not configured, software access is missing and the email account does not exist yet.
That gap is rarely one person's oversight. It is a structural problem: HR systems often know the start date weeks in advance without that information automatically triggering anything on the IT side. We looked at this handover in detail in why HR and IT keep talking past each other.
The current threat landscape shows how real the risk behind it is. According to the Cyber Security Report DACH 2025, two out of three mid-sized companies in Germany, Austria and Switzerland say they have fallen victim to a cyberattack at least once in the past two years. Every unstructured account setup widens that attack surface a little further.
Shadow IT: the invisible consequence of onboarding gaps
When the official route is too slow, employees take the unofficial one. A tool request sitting in an approval queue for two weeks stops nobody from helping themselves in the meantime with private cloud storage, a free project management app or a personal AI account.
This rarely happens out of bad intent. It happens because people are trying to get work done. Remote work makes the effect worse, because there is no IT colleague nearby to ask. Personal devices end up on the company network, private cloud folders replace shared drives, and browser extensions get installed without anyone checking them.
A survey commissioned by DXC Technology shows how widespread unvetted AI use has already become: in Germany, one in three companies has no defense at all against unauthorized AI usage. Every approval that takes too long is also an invitation to shadow IT.
Unconfigured devices and over-privileged accounts
A device handed over without disk encryption, without device management (MDM) and without current security patches is exposed from the first login. For a company with no IT team, that is not a small oversight but a systemic risk, because nobody is routinely going back to fill in the missing steps. Smaller IT teams face the same problem from a different direction: under time pressure there is simply no capacity to configure every single device properly, because the team is already busy with more complex projects.
Assigning access rights under time pressure is just as critical. When a new hire needs to be productive fast, they often end up with more permissions than their role actually requires. A marketing hire gets admin access to the finance dashboard, or a sales rep gets write access to an internal development repository.
Accounts like these violate the principle of least privilege. It gets worse when credentials are shared to save time, because from that point on nobody can reconstruct who accessed what and when. The audit trail is broken.
New employees as a preferred target
Attackers know exactly why new employees are an easy target. They lack context on internal processes, they do not yet know the usual communication channels, and in their first few weeks they often want to be as helpful as possible.
A fake welcome email from HR, a plausible-looking IT setup guide or an urgent request from a "new manager" gets questioned far less than it would by an experienced colleague. That combination of uncertainty and eagerness is what makes phishing and social engineering so effective during the ramp-up period.
Letting new employees work through this phase without clear security policies and without multi-factor authentication leaves the single most vulnerable stage of the entire employment relationship down to luck.
Compliance risk: ISO 27001, GDPR and the burden of proof
Manual setup processes are not only a security risk, they are a compliance risk too. Standards such as ISO 27001 require companies to demonstrate that access rights are granted according to role and reviewed regularly. With improvised processes that is almost impossible to prove, because there is usually no record of who received which permission and when. A written IT security policy gives you something to measure those decisions against.
The zero trust principle offers useful orientation here, and it works both for companies with no IT team and as a way to take load off a small existing one. It assumes that no access is automatically trustworthy: every request is verified, and systems are designed so that one compromised account does not automatically open everything else.
One important distinction: deeploi as a platform is ISO 27001 certified and GDPR compliant, but meeting your own compliance obligations always remains your company's responsibility.
How deeploi closes onboarding security risks automatically
deeploi automates exactly these steps, backed by our in-house IT experts. The all-in-one IT management platform handles automated onboarding and offboarding, and cuts setup time from an average of 2–3 hours of manual work to 3–5 minutes.
New devices are pre-configured through zero-touch provisioning and shipped ready to use, while device management (MDM), disk encryption and security updates run automatically in the background.

Access rights are granted through predefined role templates following the least privilege principle. That reduces manual IT effort by up to 95% overall and turns access decisions into something documented and traceable rather than improvised.
For companies without an IT department, this means IT security is part of the process from minute one, instead of another task HR or management has to squeeze in on the side.
For companies with a small existing IT team, the benefit looks different. Routine work like device setup and permission assignment runs automatically in the background, so the team can focus on more complex IT projects instead of the same onboarding admin every few weeks.
Automation instead of a checklist: the sustainable route to secure onboarding
Onboarding security risks are not caused by individual carelessness. They are caused by missing structure between HR and IT. A longer checklist does not solve that on its own, because it still depends on manual execution and stays error-prone.
Onboarding security only becomes sustainable when devices, accounts and permissions are set up automatically and to a single standard, regardless of whether there is an IT team in the building.
deeploi provides that automation as a platform, so responsibility for secure onboarding no longer sits with one person but with a process you can rely on.
Secure onboarding, without the extra IT work
More than 200 companies already rely on deeploi to set up devices, accounts and permissions automatically and securely, in 3–5 minutes instead of 2-3 hours.
{{cta}}
FAQ
Why is the onboarding process a security risk specifically for companies without an IT department?
Without a dedicated IT department, HR leads or founders usually take on the technical setup alongside everything else, with no security background and no time for a clean process.
Steps like disk encryption, device management (MDM) or role-based permissions are easy to miss in that situation. Attackers target exactly these gaps, because they know nobody inside the company is routinely checking how the setup was done.
How exactly are shadow IT and poor onboarding connected?
When the official IT setup takes too long, new employees improvise with private cloud services, their own devices or personal AI accounts. What starts as a pragmatic stopgap quickly becomes a habit. Those unauthorized tools sit outside any central control and turn into blind spots in your company IT.
What role does zero trust play in employee onboarding for SMBs without an IT team?
Zero trust means no access is automatically considered trustworthy, not even inside your own network. Small and mid-sized companies can apply the principle without a security team by granting permissions through fixed role templates and monitoring access continuously, rather than setting it once during onboarding and never looking at it again.
How quickly should a new device be ready for an employee?
Done manually, fully setting up a device including software, accounts and security policies usually takes 2–3 hours. With an automated platform like deeploi the same setup drops to 3–5 minutes, because configuration, permissions and security updates run in the background instead of being worked through step by step.
What can HR leads without IT knowledge actually do about onboarding security risks?
The most effective step is not a longer checklist but automating the setup itself. A platform that connects HR systems like Personio directly to device and permission assignment makes sure security is built into the process, without HR teams having to become IT specialists.










