“Shadow data” may cost your business money

--

A new report from Symantec suggests there’s a good chance your company files could be stored on a cloud service your IT department doesn’t know about, widely shared and may contain personally identifying information.

This grim warning comes courtesy of the Internet Security Threat Report released this week. We read through it and one bit in particular that stood out was the idea of “shadow data.”

Symantec defines shadow data as “business data stored in the cloud without IT’s consent or knowledge.” The idea that your company data could be held somewhere without you knowing about it is definitely bad.

But wait, it gets worse!

According to Symantec’s research, 25 percent of that shadow data is “broadly shared” either “internally, externally, and/or with the public.”

Your corporate data could be floating around without you knowing about it. That’s really bad.

Well, sadly, it gets worse still. From the report:

Even more concerning is that of the 25 percent of files broadly shared, three percent contained compliance-related data such as Personally Identifiable Information (PII), Payment Card Information (PCI), or Protected Health Information (PHI). If this sensitive data leaks, it can lead to substantial compliance penalties and mitigation costs for the affected company.

So, there’s a good chance your sensitive data could be stored somewhere in a cloud service you don’t know about, shared with people you are unfamiliar with — and if leaked, could cost your company money as well as your trust and reputation.

To avoid your data falling into the shadows, Symantec recommends implementing smart data governance policies into your business. We agree. You should absolutely know what type of data is being stored and where.

And once you have pulled all your files into the sunlight, we recommend running a Marshal scan for exposed sensitive data in your cloud services. It’s a free, fast and secure way to identify any Social Security Numbers, credit card numbers, email addresses or phone numbers that are being stored out in the open.

--

--