The most popular and comprehensive Open Source ECM platform
Data Management: Companies Struggle to Manage Sensitive Data
As organizations amass ever more data, the need to classify, organize, search and analyze large data sets is becoming increasingly important. One area that is proving especially difficult for organizations is the ability to identify sensitive data, data which needs more careful handling. The proper handling of sensitive data is important for ensuring customer privacy and compliance with federal and state privacy laws and regulations.
A recent survey by information management company Protiviti of large companies (70 percent with revenues exceeding $1 billion), about a quarter of respondents said that their senior management had “limited or no understanding” of how to identify sensitive information, while another quarter of those responding said that their management team had an “excellent understanding”. So companies were fairly evenly split between the two extremes.
Cal Slemp, Protiviti managing director and head of IT security and privacy, said that “This basic understanding of what constitutes ‘sensitive’ is absolutely critical because it sets the tone for how data is treated in every phase of its lifecycle – from collection to destruction. Without this foundation, companies open themselves to needless costs and legal, regulatory and reputation risks.”
Kurt Underwood, Protiviti managing director, said that “Organizations have made significant strides over the past decade integrating enterprise applications and collecting terabytes of valuable customer, supplier and employee data. However, our survey shows that many companies are holding onto more data than is prudent and for longer time frames than necessary, which poses significant data security and privacy risks. There are opportunities for executives to significantly reduce legal exposures, while driving sensitive data management improvements and cost savings.”
Other findings of the Protiviti report include:
- 69 percent of companies have defined clear policies for identifying sensitive data, but only 50 percent have a plan in place that actually identifies sensitive data.
- While nearly three-quarter of companies have a crisis response plan in place for how to respond to hacking and data breach incidents, 27 percent do not have a plan in place.
- Increasingly companies are putting ‘data leakage’ policies in place. For example, 81 percent have record retention and destruction policies, 75 percent have an information security policy and 65 percent have a data encryption policy.













