Most organizations treat information governance as a compliance exercise, until a serious data breach transforms it into a risk management and business imperative. Only after a data incident do most organizations understand that the amount of data the threat actor accessed is directly proportional to what the organization had long kept in its environment.
When a cybersecurity incident occurs, the first question often asked is: "How much data was stolen?" The honest answer is typically: “far more than the threat actors should have been able to access.” This is not because perimeter defenses failed, though sometimes they do, but because the data that was exfiltrated should have been deleted long ago.
This pattern repeats itself with painful consistency: the severity of a breach is almost never determined solely by the sophistication of the attack, but rather by the volume and sensitivity of the data the threat actor encountered. In many cases, the data discovered has accumulated over years of ungoverned retention with no owner, purpose or deletion date.
This is a crucial information governance lesson all organizations should recognize before an incident occurs: the harm from breaches can be proactively mitigated if the amount of data available to steal has already been reduced.
When threat actors gain access to enterprise environments, they typically move laterally through file shares, email archives, collaboration platforms and legacy content repositories. They typically encounter a decade or more of unmanaged content including personnel records never purged after employee offboarding, customer personally identifiable information retained past any business or legal need, contracts with sensitive financial terms stored in shared drives accessible to hundreds of users or draft documents containing proprietary strategies.
All of these examples pose potential liabilities, which can compound during a cybersecurity breach. Notification obligations, regulatory penalties, business impact and litigation exposure are all calculated not just on what was accessed during the incident, but on what data was available with the potential to be compromised. The lesson is that defensible deletion is not just good housekeeping, it is critical to breach risk reduction.
Defensible deletion, the practice of disposing of data in accordance with a legally sound data retention and deletion policy and schedule with documented processes and procedures, is one of the most underutilized breach risk controls available to organizations today. Data that has been defensibly deleted cannot be exfiltrated, trigger notification obligations or become the subject of a regulatory inquiry or class action litigation.
In contrast, data that is perpetually retained remains in scope for any of these scenarios. Following a breach, regulators and counsel will ask what the accessed data contained, who it affected and why it was still being retained. The inability to answer these questions can be a negative finding in itself.
Organizations with mature information governance programs typically respond to cyber incidents more effectively and efficiently than those without them. Well-prepared organizations have typically done four things long before a cybersecurity incident:
The difference of having an information governance program in place is measured in the absence of notification costs, regulatory fines, legal fees and reputational damage, all of which scale directly with the volume of sensitive data that was accessible at the time of an incident.
Organizations rightfully spend enormous amounts on detection, response and recovery capabilities. Yet, the investment in preventing data accumulation in the first place is a fraction of the cost, and its payoff in a breach scenario can be exponential.
The conversation between a chief information security officer and information governance team should not happen for the first time during or after an incident. By then, the window to reduce exposure has already closed. All organizations will likely face a cyber incident, but the ramifications can differ significantly based on the amount of data they leave vulnerable to threat actors.