Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Information Management Bad Habits Begin In The Boardroom How Can Today’s Information Sinners Quit The Habit?
Study & Research

Information Management Bad Habits Begin In The Boardroom How Can Today’s Information Sinners Quit The Habit?

ISBuzz TeamBy ISBuzz TeamNovember 16, 20166 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Information Governance
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Employees at every level and across every industry are reminded regularly that information is vital to their business. In order to make the most of business information, easy access is critical. Whether it’s an email with the latest financial figures, a marketing strategy PDF, a print out of a CV including hand-written notes or a customer contact list, having the information readily to hand enables businesses to serve their customers and employees.

Given the importance of information to business success, you would expect employees to take every possible step to manage information securely. Yet, with file servers overflowing and increased pressure on resources, it would appear that many, from the CEO to the admin team, have become complacent about information security. We may well want to question whether or not modern businesses have put good information governance practices in place.

Bad habits from the top down

Despite understanding the value of the information their business holds, when it comes to safeguarding the information, business leaders often fail to follow the processes and policies designed to keep it secure.

In a recent survey commissioned by Iron Mountain, over half (57%) of the CxOs questioned admitted to having left business-sensitive or confidential information on the printer for all to see, with over a third (39%) admitting to having lost it in a public place. This admission reveals just how easy it could be for information to get into the wrong hands. There is much at stake: if data is mishandled or breached, companies could face fines of up to 4% of annual turnover under the General Data Protection Regulation. When customer information is breached as a consequence of malicious intent or employee error, the organisation’s reputation may be damaged and customer loyalty eroded. Seemingly small misdemeanours can have serious consequences.

It’s not just careless data handling that could land a company in hot water. The processes companies put in place to protect the integrity of information and ensure compliance are often not followed, leaving the organisation exposed to unnecessary risk.

One in five (21%) CxOs we spoke to found the information management processes in their organisations too complicated and so chose to bypass them. A worrying 6% were completely unaware of any processes governing information security. Company bosses, more than employees in any other roles, found procedures for information filing (16%) and document retention (15%) to be overly complex and chose to avoid them where possible.

Instead of leading by example, business leaders are guilty of sidestepping company policy to get things done or are simply unaware that what they are doing goes against any policy. Although our research found that CxOs top the list of information sinners in most information-handling scenarios, the actions of facilities managers reveal a similar story. Over half (56%) admit to taking sensitive or confidential information out of the workplace and 48% have sent sensitive information to the wrong recipient.

Departments tasked with handling sensitive information are also at fault. Nearly half (44%) of HR staff said they were in possession of HR documents they should no longer hold under data retention regulations, 32% of finance managers acknowledge the same with tax records and 47% of legal professionals admit potential storage errors with contracts and other legal documents.

Administrative staff rate well in comparison but are still guilty of mismanaging information, with one in five (21%) admitting to having mislaid data or sent it to the wrong person, and 15% admitting to losing company documents in a public place.

The growing complexity                                                                           

So what’s behind such widespread mismanagement of information and how can businesses change the culture and improve information management and handling practices among staff? It won’t be easy. The rise of cloud services and mobile device usage, along with the emergence of the Internet of Things (IoT) has led to an explosion in data generation within organisations. This has put pressure on people to manage more information than ever before. At the same time, business leaders want decisions to be data driven. As a result, employees must now analyse company information and find ways to derive insight from it while still understanding and ensuring compliance with data retention and protection regulations.

It is imperative that everyone within the organisation has a clear understanding of their responsibilities when it comes to managing the information they process or have access to – no matter what format it is in – as well as understanding the consequences for the business if that information is not managed correctly. But with time and resource pressures causing familiar strain across all sectors, good information governance is not necessarily a reality for many. Businesses need to foster a culture in which employees protect and value organisational information. This will require a continual cycle of information security training for all employees and it will need those at the very top to lead by example.

 The solution should start at the top

Information responsibility is shared by everyone: from the CEO and CIO, to sales, marketing, HR and even temporary staff. The basis of good information governance is comprehensive information management policies that covers all types of information, no matter whether it’s electronic or on paper and no matter where it resides, whether it’s in the office or in the cloud, on a USB stick or a laptop,  stored in the home office or offsite with a trusted third party.

Making sure these policies are clear and easy to follow will encourage good information governance. In order to build an organisational culture that values and protects information, policy must be understood, followed and promoted by those at the very top of the business. This can be achieved through example, regular communication and training. When it comes to paper documents, off-site storage, in conditions compliant with relevant market regulations, will help the company to follow retention rules. A digitisation programme for frequently accessed or newly created information will also help to keep track of information and ensure it is stored centrally and compliant with relevant data protection laws.

Iron Mountain research with PwC showed around three quarters of companies (72% in Europe and 79% in North America) regard information as a business asset, yet on average just 35% employ data analysts to extract the value from information and many (43 per cent) obtain little tangible benefit from their information. It is clear that companies still have a long way to go before they can overcome the challenge presented by the variety, volume and velocity of today’s flow of information.

Implementing a strong information governance policy requires a consistent, clear and cohesive approach to managing information in all formats. For business leaders in particular, this starts with getting their information management habits in order. Only then can they expect best practice to be followed throughout the organisation.

The research was undertaken for Iron Mountain by Opinion Matters and questioned a total of 4,006 workers in mid-market companies (with between 250 – 3,000 employees (250-5,000 in North America)) across the UK, France, Germany, The Netherlands, Belgium, Spain and North America.

[short_info id=’60884′]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}