Simple solution, "don't do that". Don't let the user connect directly to the server. Change the password. If they know the sys password, change it too.

Use a client installed program.

If they try "connect / as sysdba", they'll get "ORA-01031 - Insufficient Privileges"

Oh, and, yea..., don't forget to submit that TPS report, K