Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Confidential Information At Greatest Risk In New Businesses
Articles

Confidential Information At Greatest Risk In New Businesses

ISBuzz TeamBy ISBuzz TeamFebruary 19, 2017Updated:April 30, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Mid-market companies are the engine room of our global economy. In the UK alone, the sector employs 50 per cent more people now than it did in 2010[1]. Despite this vital role, when it comes to managing and safeguarding one of its most key assets – information – the mid-market can often be found guilty of missing a few vital information management steps.

The challenge of properly processing and managing data today is exacerbated by a complex information landscape. The associated compliancy regulations, including the imminent General Data Protection Regulation (GDPR)[2], is matched by other challenging factors such as the widespread digital transformation on an army of time-poor but information-rich employees. Understandably in this environment, it is difficult to put effective and compliant information management processes in place.

So, what can mid-market businesses do to make life easier for themselves? How can they avoid putting themselves at risk of breaching regulations? This year Iron Mountain conducted research[3] into the mid-market’s information management habits to understand where businesses are going wrong. A full write up of the research results can be found ironmountain.co.uk/Information-Management-in-the-Mid-Market

Information management blunder one: the distracted youth

Our research found that younger firms have inherently bad habits with private information, little faith in their own data protection procedures and little inclination to automate processes. This is because they generally still have their heads in start-up phase, where chasing the next sale and the race to the next product cycle get their full attention.

Staff at younger mid-market firms are more careless with confidential and business-sensitive data. Nearly half (48%) of employees at companies that have been in business for less than five years have left private documents either lying about the office, have mislaid them completely, or have lost them in a public place. This is twice as many as at more established firms, where fewer than one in four (23%) have done the same.

In general, familiarity with the legal requirements governing business information comes with maturity. Indeed, younger firms are considerably less clear on how long they are required to retain documents such as tax records, contracts and customer data. More than half (51%) of respondents at companies between one and five years old admitted they could be in possession of sensitive human resource records beyond their retention deadline, compared with just 20% at firms older than 25 years.

When it comes to breaching regulations, the law is not going to give younger firms a free pass. While chasing the next sale, growing the team, or expanding into new markets is admirable, younger businesses in the mid-market need to think carefully about putting information management policies and processes in place. Get it right from the start and muscle memory will help shape the culture and protect the business as it grows.

Information management blunder two: not setting the right example

Despite the majority of respondents having a good grasp of how long their company is legally entitled to retain documents subject to data protection laws, over a quarter admitted to be in breach of the rules by still having these documents on their computer or stored in their files.

In particular, company bosses have emerged as being unaware or, perhaps, cavalier about how long their business should retain documents such as tax records, contracts and customer data. Half of business leaders admit they could have documents on their computers that are well beyond their legally determined destruction dates. This is despite the Information Commissioner’s Office (ICO) making it clear in its information standards principles[4] that businesses should retain personal data no longer than is necessary for the purpose it was obtained for. Getting this wrong could be a serious risk to the business, not only in terms of reputation and financial penalties – it could also erode customer trust and threaten the long-term survival of the business.

It’s time that company bosses in the mid-market set a good information management example. Only when the C-suite champions information policies, cultural change and better habits will these filter through the rest of the business to create a culture of information responsibility.

Information management blunder three: keeping hold of the sensitive stuff

Despite great steps forward in the digitisation of information, paper processes still prevail. They account for a large number of information mismanagement cases, when it comes to the loss of physical documents or indiscriminate filing, with a disregard for associated retention and destruction regulation.

Mid-market companies across the globe must cut out bad habits when handling sensitive information if they are to minimise the risk of inadvertent leaks and breaches of data regulation. Having a central repository for the safe storage of sensitive information is a good place to start and consideration should be given to storing securely off-site with an established third party. Thinking about how this information is shared within the business is also important. Once information such as a contract or CV is shared within your organisation, make sure you have processes in place to monitor where and how far this information travels before it becomes impossible to trace.

There’s no doubt that the mid-market is faced with challenges when it comes to information management. Getting it right isn’t easy but avoiding these common mistakes can go a long way towards helping businesses remain compliant amidst the complexity of evolving regulations.

Building processes today that can be followed by the whole business in the future can only help the entire mid-market to continue growing successfully. It is with this in mind that Iron Mountain is working with companies to make sure they take a consistent, clear and cohesive approach to managing data – whatever their industry or heritage.

[su_box title=”About Elizabeth Bramwell” style=”noise” box_color=”#336588″][short_info id=’60884′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}