Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Are Your Employees Unconvinced About Your Processes?
Study & Research

Are Your Employees Unconvinced About Your Processes?

ISBuzz TeamBy ISBuzz TeamMay 13, 2017Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Centrify
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Businesses around the world are upgrading the way they manage their information, moving from records and information management (RIM) to information governance (IG). More operational or tactical in scope, RIM describes the activities and tasks required to organise, secure, access and ultimately destroy information. IG can be described as the strategy that guides the management of information. It includes all the metrics, structures, policies, controls that establish how the organisation’s information is managed.

The move makes sense for business reasons — information governance treats information as a business asset and assures that appropriate and well-curated information is a key business resource that can have a positive impact by informing policy, supporting legal and financial affairs and giving companies a commercial edge. An organisation’s strategic and risk management goals can all be supported by information governance. Effective information governance also allows businesses to comply with regulatory demands, avoiding costly – and potentially irreparable – damage from legal action and sanctions.

The move to information governance is not, however, without its challenges. Some of these are technological, such as a lack of appropriate tools to enable the automated deletion of eligible and sensitive information when it reaches its retention deadline. Recent research from Iron Mountain, for example, has found that 65% of businesses have very little automation in place to facilitate their HR processes at present, and 52% have no current plans to implement HR process automation at all.[i]

According to another new study, Transforming Information Management, from Cohasset Associates and ARMA International, of which Iron Mountain is an underwriter, many of the major impediments to information governance are also rooted in corporate habits. A ‘keep everything’ culture persists in 81% of businesses, and 84% cite resistance to change as a key challenge.[ii]

Another significant challenge – also identified in the Cohasset study – is that of effective employee engagement. The active involvement of employees in carrying out and supporting activities related to information lifecycles is absolutely crucial to the establishment of good practice, and in achieving the ultimate goal of making information governance a seamless, ordinary part of day-to-day business. Yet the research tells us that while most management personnel (83%) are engaged and enthusiastic about information governance, amongst other employees, active engagement and support runs at just 68%. This is dangerous for organisations because if information governance is not embedded in daily activities, and its value is not understood by all employees, the dangers of non-compliance and ineffectual data management are greatly increased.

The dangers of non-compliance

We know that most companies have robust records and information management policies in place[iii], and of course that is very encouraging, but all the policy in the world is pointless if employees are not acting on it. When it comes into force in May 2018, the General Data Protection Regulation (GDPR) will result in swift and severe punishment for businesses that fail to comply with its regulation regarding the acquisition, use, transmission, storage, destruction and breach of personal data, with fines of up to 4% of annual world turnover or EUR 20 million, whichever is greater. [iv] If employees do not act upon legal requirements such as those set out in the GDPR, perhaps because they lack training, lack resources or simply do not understand why they must, an organisation is likely to find itself non-compliant and thus open to very unpleasant sanctions that could have lasting negative impact on the business.

Clearly, good information governance training for all employees would help to solve this problem — but the Cohasset study tells us that just 26% of businesses are providing it.

It is therefore vital that businesses take action now to engage staff in information handling and lifecycle issues, and educate them about the importance of treating information responsibly and in line with the law. This will not only protect the business involved, but also streamline the transition from records and information management to information governance and allow organisations to fully exploit the benefits that brings. The obvious way to do this is by introducing mandatory training and information governance-specific performance measurements for both individuals and departments.

Training and awareness matter

Training is essential because without it, employees may find it very difficult to handle data in line with policy; they cannot be expected to make good decisions unless they understand what to do and why it matters. Thus, employee engagement is important to ensure compliance with existing policy and the ability to use business information to the fullest advantage and stay on the right side of the regulations. Yet the advantages of training are not limited to these.

Training and awareness in information governance contributes to employees’ engagement, their ability and willingness to advocate good data handling behaviours across the organisation, their effectiveness and job satisfaction. Furthermore, the commitment and advocacy that training generates are indicators of a successful movement towards information governance. By contrast, low levels of advocacy can dampen the success of a business’s transformation.

There are lots of ways to train employees in information management. E-learning, face-to-face training, drop in sessions — these are just a few of the options. What matters is that staff at all levels understand what their responsibilities are, the risks and the benefits associated with them and the rationale underpinning company policy. When training is complete, the outcomes must be evaluated, not only to ensure that the training has been effective but also so that the organisation can assure itself that employees understand how they can contribute to compliance and have the resources they need to do so, and to provide evidence of the same to the regulators if it is required.

As the nature and volume of business information evolves, so must the demands of relevant regulations, and business techniques for dealing with these. The good news is that with good policy, forward planning and effective training, organisations can make a smooth and efficient move to information governance, and thus find themselves well-placed to enjoy a bright future.

[su_box title=”About Sue Trombley” style=”noise” box_color=”#336588″][short_info id=’60469′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}