What Happened
Sudhish Kasaba Ramesh worked as an engineer at Cisco Systems until he resigned in roughly April 2018. Five months later, in September 2018, he still had a way to reach Cisco’s cloud infrastructure. According to the Department of Justice, Ramesh accessed Cisco’s systems without authorization by deploying code from his own personal Google Cloud Project account into Cisco’s environment, which was hosted on Amazon Web Services.
The code he ran did real, deliberate damage. It deleted 456 virtual machines that supported Cisco’s WebEx Teams application. The immediate effect was that more than 16,000 WebEx Teams accounts were shut down, some for as long as two weeks, while Cisco worked to rebuild what had been destroyed. The DOJ press release notes no customer data was compromised in the incident, but the operational damage alone was substantial: Cisco spent approximately $1.4 million on employee time to restore the environment and issued more than $1 million in refunds to affected customers.
Ramesh pleaded guilty in August 2020 to one count of intentionally accessing a protected computer without authorization and recklessly causing damage, under the federal Computer Fraud and Abuse Act. He faced up to five years in prison and a $250,000 fine, with sentencing handled by Judge Lucy H. Koh in the Northern District of California.
What stands out isn’t the sophistication of the attack, it wasn’t sophisticated. It’s the timeline. This wasn’t a hacker breaking through Cisco’s defenses from the outside. It was a five-month gap between an employee’s last day and the moment his access to company infrastructure was actually, fully cut off.
Why This Matters If You’re Not a Big Company
Cisco has an entire security operations team, and it still took an intentionally destructive former employee five months to get caught doing this. A small or mid-size business doesn’t have that team, and it usually doesn’t have Cisco’s ability to absorb a two-week outage across a third of its customer base and simply write a $2.4 million check to make it right.
What makes this case relevant to a 20-person accounting firm or a regional manufacturer isn’t the scale, it’s the mechanism. Offboarding is one of the most routine things a business does. Someone quits, someone gets fired, someone gets laid off, and it happens constantly, often without a formal IT step built into the process at all. If a company as resourced as Cisco can leave a five-month hole in its access controls, a smaller business without a dedicated IT or security function is at least as likely to leave an old employee’s login, VPN credential, or cloud account sitting active long after that person has stopped showing up to work.
What Actually Would Have Stopped This
The fix here isn’t exotic. It’s a documented, enforced offboarding checklist that runs the same way every single time someone leaves, whether they quit on good terms or get walked out the same day. That means disabling accounts, revoking VPN and remote access, pulling API keys and cloud credentials, and removing the person from every system they ever touched, not just email and the badge reader. The Cisco case involved cloud infrastructure access specifically, the kind of access that’s easy to overlook because it doesn’t live in the same list as someone’s email login.
The second piece is a regular access audit, not just an offboarding event. A quarterly review of who has access to what, cross-checked against current employees, catches the account that offboarding missed. Ramesh had access for five months after he resigned. A quarterly audit would have caught that within ninety days, and depending on timing, potentially before the September damage occurred at all.
Security Checklist for Your Business
Build one offboarding checklist. Cover every system, not just email, VPN, and file shares, but cloud consoles, API keys, and any personal-device access tied to work accounts.
Revoke access the same day someone leaves, regardless of whether the departure is voluntary, and regardless of how the person left on good terms.
Run a quarterly access audit that cross-references active accounts against current employees, so a missed revocation gets caught in weeks, not months.
Treat cloud and infrastructure credentials as seriously as email. They’re often the ones offboarding checklists forget, and they’re the ones that can do the most damage.
A five-month gap in access revocation turned one departing engineer into a two-week outage and a seven-figure bill for a company with a full security team behind it. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: U.S. Attorney’s Office, Northern District of California, “San Jose Man Pleads Guilty to Damaging Cisco’s Network”.



