Outside of ignoring the fundamental principles of information security, there’s hardly anything that can lead to a security breach faster than someone’s careless handling of sensitive data. It’s a problem that I’ve been witnessing for the last decade, and it seems to be getting worse, given all the data being generated, processed and stored in today’s business world.

Data mismanagement doesn’t even have to be attributed to carelessness, an oversight or lack of budget on the part of IT. Any regular employee, contractor or other individual who has access to data that would be considered critical can create issues. Whether intentional or not, the mishandling of sensitive data can get your organization into hot water very quickly.

Understanding Sensitive Data

I think the elephant in the room is the number of IT professionals who don’t know where their sensitive data resides on the network. The 2014 survey “The State of Data-Centric Security” found that anywhere from 7 to 16 percent of professionals know where their critical data is located, while a 2015 study from Perspecsys found that 57 percent don’t have a complete understanding of where sensitive data is.

Those numbers are a bit too low if we’re going to make any progress in terms of locking down business assets. You’re certainly not going to be able to account for all data across all systems, but I think anything short of around 90 percent is asking for trouble.

Real-Life Examples

Let me give you some examples of data risks that I’ve seen in my own work experience:

  • Software developers using production cardholder data (i.e., debit and credit card numbers) scattered across unsecured systems in their development and quality assurance (QA) environments. This is probably the most common example I see. I once asked a developer why he had so many structured database files and unstructured files (i.e., text files, PDFs and word processing docs) containing critical data stored on an open network share. His response was that those files contained outdated data; he didn’t realize that the date doesn’t matter. Old, new or somewhere in between, sensitive data is sensitive data.
  • Sensitive production data finds its way to disaster recovery servers, tape backups and third-party cloud services that likely do not meet the same security standards as the production environment. These vendors become attractive targets for cybercriminals searching for critical information.
  • Managers, such as those working in HR and finance, frequently store files on their local desktops or laptops, often so they can work on certain projects outside of the office. I once asked an HR manager if she had any sensitive data on her unencrypted laptop. She didn’t believe there was; however, after performing a scan of personally identifiable information (PII), there ended up being over 40,000 records containing Social Security numbers, credit card numbers, bank account details and the like. This is a prime example of a data breach waiting to happen.
  • Customers or business partners emailing sensitive spreadsheets, PDF files or scanned images containing PII. This is especially common for those in businesses outside of the U.S. that might not know about the federal regulations mandating the security of sensitive information.

Acknowledging Critical Data Is the First Step

You cannot secure what you don’t acknowledge. Take a step back and look at your data — where it’s located, how you’re storing it and how it’s being handled — all from an outsider’s perspective. Look for it in the obvious places that are being overlooked (e.g., workstations, network shares and backups), but also think about the other areas of your network and cloud environment where sensitive data might be stored outside of your typical security controls. All it takes is one small oversight to lead to big security challenges.

More from Data Protection

Cost of a data breach 2023: Pharmaceutical industry impacts

3 min read - Data breaches are both commonplace and costly in the medical industry.  Two industry verticals that fall under the medical umbrella — healthcare and pharmaceuticals — sit at the top of the list of the highest average cost of a data breach, according to IBM’s Cost of a Data Breach Report 2023. The health industry’s place at the top spot of most costly data breaches is probably not a surprise. With its sensitive and valuable data assets, it is one of…

Cost of a data breach 2023: Financial industry impacts

3 min read - According to the IBM Cost of a Data Breach Report 2023, the global average cost of a data breach in 2023 was $4.45 million, 15% more than in 2020. In response, 51% of organizations plan to increase cybersecurity spending this year. For the financial industry, however, global statistics don’t tell the whole story. Finance firms lose approximately $5.9 million per data breach, 28% higher than the global average. In addition, evolving regulatory concerns play a role in how financial companies…

Advanced analytics can help detect insider threats rapidly

2 min read - While external cyber threats capture headlines, the rise of insider threats from within an organization is a growing concern. In 2023, the average cost of a data breach caused by an insider reached $4.90 million, 9.6% higher than the global average data breach cost of $4.45 million. To effectively combat this danger, integrating advanced analytics into data security software has become a critical and proactive defense strategy. Understanding insider threats Insider threats come from users who abuse authorized access to…

One simple way to cut ransomware recovery costs in half

4 min read - Whichever way you look at the data, it is considerably cheaper to use backups to recover from a ransomware attack than to pay the ransom. The median recovery cost for those that use backups is half the cost incurred by those that paid the ransom, according to a recent study. Similarly, the mean recovery cost is almost $1 million lower for those that used backups. Despite this fact, the use of backups is actually falling. This was one of the…