What Data You Delete Before a Cyber Incident Matters More Than You Think
Steven Stein

By: Steven Stein on September 10th, 2026

Print/Save as PDF

What Data You Delete Before a Cyber Incident Matters More Than You Think

Information Governance  |  Information Security

Most organizations treat information governance as a compliance exercise, until a serious data breach transforms it into a risk management and business imperative. Only after a data incident do most organizations understand that the amount of data the threat actor accessed is directly proportional to what the organization had long kept in its environment.

When a cybersecurity incident occurs, the first question often asked is: "How much data was stolen?" The honest answer is typically: “far more than the threat actors should have been able to access.” This is not because perimeter defenses failed, though sometimes they do, but because the data that was exfiltrated should have been deleted long ago.

This pattern repeats itself with painful consistency: the severity of a breach is almost never determined solely by the sophistication of the attack, but rather by the volume and sensitivity of the data the threat actor encountered. In many cases, the data discovered has accumulated over years of ungoverned retention with no owner, purpose or deletion date.

This is a crucial information governance lesson all organizations should recognize before an incident occurs: the harm from breaches can be proactively mitigated if the amount of data available to steal has already been reduced.

What data do threat actors actually find?

When threat actors gain access to enterprise environments, they typically move laterally through file shares, email archives, collaboration platforms and legacy content repositories. They typically encounter a decade or more of unmanaged content including personnel records never purged after employee offboarding, customer personally identifiable information retained past any business or legal need, contracts with sensitive financial terms stored in shared drives accessible to hundreds of users or draft documents containing proprietary strategies.

All of these examples pose potential liabilities, which can compound during a cybersecurity breach. Notification obligations, regulatory penalties, business impact and litigation exposure are all calculated not just on what was accessed during the incident, but on what data was available with the potential to be compromised. The lesson is that defensible deletion is not just good housekeeping, it is critical to breach risk reduction.

The role of defensible deletion

Defensible deletion, the practice of disposing of data in accordance with a legally sound data retention and deletion policy and schedule with documented processes and procedures, is one of the most underutilized breach risk controls available to organizations today. Data that has been defensibly deleted cannot be exfiltrated, trigger notification obligations or become the subject of a regulatory inquiry or class action litigation.

In contrast, data that is perpetually retained remains in scope for any of these scenarios. Following a breach, regulators and counsel will ask what the accessed data contained, who it affected and why it was still being retained. The inability to answer these questions can be a negative finding in itself.

Building governance to reduce breach severity

Organizations with mature information governance programs typically respond to cyber incidents more effectively and efficiently than those without them. Well-prepared organizations have typically done four things long before a cybersecurity incident:

  1. Maintain a current data inventory. The organization knows what sensitive data exists, where it lives, who owns it and what classification it carries. During an incident, this compresses the scoping timeline from weeks to days.
  2. Define, apply and enforce the retention policy and schedule. Across all enterprise data, a retention and deletion policy is in place, maintained and enforced. Data past its retention period has been disposed of and not just archived indefinitely.
  3. Minimize the sensitive data footprint. Through periodic data minimization initiatives, the volume of sensitive content is reduced to what is actively needed for business or only what is legally required.
  4. Document deletion decisions. When regulators or opposing counsel ask why data was deleted, there is an answer: an approved retention schedule, a deletion certificate and an auditable process.

The difference of having an information governance program in place is measured in the absence of notification costs, regulatory fines, legal fees and reputational damage, all of which scale directly with the volume of sensitive data that was accessible at the time of an incident.

Governance is incident mitigation

Organizations rightfully spend enormous amounts on detection, response and recovery capabilities. Yet, the investment in preventing data accumulation in the first place is a fraction of the cost, and its payoff in a breach scenario can be exponential.

The conversation between a chief information security officer and information governance team should not happen for the first time during or after an incident. By then, the window to reduce exposure has already closed. All organizations will likely face a cyber incident, but the ramifications can differ significantly based on the amount of data they leave vulnerable to threat actors.

About Steven Stein

Senior Managing Director within FTI Technology, is a data privacy and information governance leader and former civil litigation attorney with more than 20 years of experience developing and implementing data risk and compliance programs. Mr. Stein co-leads FTI Technology’s Advertising Technology practice and focuses on serving clients in the financial services, streaming and advertising, retail, health care and life sciences and power and utilities industries, in the areas of privacy, adtech, records management, information lifecycle, legal hold, defensible data disposition, data protection and litigation readiness.