July 22, 2015 By Kevin Beaver 3 min read

Outside of ignoring the fundamental principles of information security, there’s hardly anything that can lead to a security breach faster than someone’s careless handling of sensitive data. It’s a problem that I’ve been witnessing for the last decade, and it seems to be getting worse, given all the data being generated, processed and stored in today’s business world.

Data mismanagement doesn’t even have to be attributed to carelessness, an oversight or lack of budget on the part of IT. Any regular employee, contractor or other individual who has access to data that would be considered critical can create issues. Whether intentional or not, the mishandling of sensitive data can get your organization into hot water very quickly.

Understanding Sensitive Data

I think the elephant in the room is the number of IT professionals who don’t know where their sensitive data resides on the network. The 2014 survey “The State of Data-Centric Security” found that anywhere from 7 to 16 percent of professionals know where their critical data is located, while a 2015 study from Perspecsys found that 57 percent don’t have a complete understanding of where sensitive data is.

Those numbers are a bit too low if we’re going to make any progress in terms of locking down business assets. You’re certainly not going to be able to account for all data across all systems, but I think anything short of around 90 percent is asking for trouble.

Real-Life Examples

Let me give you some examples of data risks that I’ve seen in my own work experience:

  • Software developers using production cardholder data (i.e., debit and credit card numbers) scattered across unsecured systems in their development and quality assurance (QA) environments. This is probably the most common example I see. I once asked a developer why he had so many structured database files and unstructured files (i.e., text files, PDFs and word processing docs) containing critical data stored on an open network share. His response was that those files contained outdated data; he didn’t realize that the date doesn’t matter. Old, new or somewhere in between, sensitive data is sensitive data.
  • Sensitive production data finds its way to disaster recovery servers, tape backups and third-party cloud services that likely do not meet the same security standards as the production environment. These vendors become attractive targets for cybercriminals searching for critical information.
  • Managers, such as those working in HR and finance, frequently store files on their local desktops or laptops, often so they can work on certain projects outside of the office. I once asked an HR manager if she had any sensitive data on her unencrypted laptop. She didn’t believe there was; however, after performing a scan of personally identifiable information (PII), there ended up being over 40,000 records containing Social Security numbers, credit card numbers, bank account details and the like. This is a prime example of a data breach waiting to happen.
  • Customers or business partners emailing sensitive spreadsheets, PDF files or scanned images containing PII. This is especially common for those in businesses outside of the U.S. that might not know about the federal regulations mandating the security of sensitive information.

Acknowledging Critical Data Is the First Step

You cannot secure what you don’t acknowledge. Take a step back and look at your data — where it’s located, how you’re storing it and how it’s being handled — all from an outsider’s perspective. Look for it in the obvious places that are being overlooked (e.g., workstations, network shares and backups), but also think about the other areas of your network and cloud environment where sensitive data might be stored outside of your typical security controls. All it takes is one small oversight to lead to big security challenges.

More from Data Protection

Defense in depth: Layering your security coverage

2 min read - The more valuable a possession, the more steps you take to protect it. A home, for example, is protected by the lock systems on doors and windows, but the valuable or sensitive items that a criminal might steal are stored with even more security — in a locked filing cabinet or a safe. This provides layers of protection for the things you really don’t want a thief to get their hands on. You tailor each item’s protection accordingly, depending on…

What is data security posture management?

3 min read - Do you know where all your organization’s data resides across your hybrid cloud environment? Is it appropriately protected? How sure are you? 30%? 50%? It may not be enough. The Cost of a Data Breach Report 2023 revealed that 82% of breaches involved data in the cloud, and 39% of breached data was stored across multiple types of environments. If you have any doubt, your enterprise should consider acquiring a data security posture management (DSPM) solution. With the global average…

Cost of a data breach: The evolving role of law enforcement

4 min read - If someone broke into your company’s office to steal your valuable assets, your first step would be to contact law enforcement. But would your reaction be the same if someone broke into your company’s network and accessed your most valuable assets through a data breach? A decade ago, when smartphones were still relatively new and most people were still coming to understand the value of data both corporate-wide and personally, there was little incentive to report cyber crime. It was…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today