top of page

The Monthly Cyber Resilience Series: What Data Do You Actually Hold?

  • May 14
  • 3 min read

The information you keep determines how attractive you are to attackers


When cybersecurity is discussed, the conversation usually begins with technology. We talk about firewalls, antivirus software, cloud security, artificial intelligence, and sophisticated attacks.


Yet one of the most important questions is often overlooked: What exactly are you trying to protect?


For most organisations, the answer is not a server, a laptop, or a network. The answer is data.


Data is the reason attackers invest time, resources, and expertise into breaching systems. Whether the target is a small NGO, a municipality, a school, a media outlet, or a multinational corporation, the objective is remarkably similar: gain access to information that has value.


That value may come from personal information, financial records, business plans, intellectual property, customer databases, or simply information that can be used to facilitate further attacks.


This is why the first step towards effective cybersecurity is much less technical than many people assume. The first step is understanding what information you actually possess.


The problem most organisations do not see


Imagine being asked to produce a complete inventory of all the information your organisation holds. Not only databases, but also spreadsheets, archived project files, shared folders, cloud repositories, employee email accounts, and backup systems. How long would it take?


For many organisations, the answer is days, weeks, or even months.


Over time, information accumulates. Projects begin and end. Staff move on. Systems are replaced. New cloud services are adopted. Old data remains. The result is often an environment where vast amounts of information exist without anyone maintaining a complete overview.


That is not merely an operational challenge. It is a security challenge. You cannot adequately protect something if you do not know it exists.


Every piece of information carries risk


There is a common assumption that more data is always beneficial. From a cybersecurity perspective, the opposite can also be true. Every piece of information you retain creates a responsibility.

  • If you store employee records, you must protect them.

  • If you store customer information, you must protect it.

  • If you retain old databases from projects completed years ago, you must protect those too.


Attackers do not care whether the information remains useful to you. If it can be monetised, exploited, or used for fraud, it retains value. This is why modern security programmes increasingly focus on data minimisation. Collect what you need. Keep what you must. Remove what no longer serves a legitimate purpose.


Not all information has the same value


One of the most common mistakes organisations make is treating all information equally. In reality, there is a significant difference between publicly available website content and a database containing personal records. Understanding that difference is critical.


A simple classification model often provides an excellent starting point:

  • Public information can be disclosed without significant consequences.

  • Internal information supports daily operations but is not intended for public release.

  • Confidential information includes contracts, financial reports, strategic plans, and sensitive business documents.

  • Sensitive information includes personal data, health information, payment details, and other records whose exposure could create serious consequences.


Once information is classified, security efforts can be prioritised accordingly.


Start with simple questions


Improving awareness does not require a major transformation programme. It starts with asking:

  • What information do we collect?

  • Why do we collect it?

  • Where is it stored?

  • Who can access it?

  • How long do we retain it?

  • Do we still need it?


The answers often reveal risks that have gone unnoticed for years.


Awareness before protection


When a security incident occurs, organisations often respond by purchasing new tools or implementing additional controls. Those measures may help. However, no technology can compensate for a lack of awareness. Effective protection begins with understanding. Before deciding how to protect information, you must first know what information you possess. That is why data inventories remain one of the most important, and most neglected, elements of cybersecurity.


Conclusion


Cybersecurity is not simply about protecting systems and devices. At its core, it is about protecting information. Before investing in new technologies, encryption solutions, or security platforms, take a step back and ask a simple question:


Do you truly know what data you hold?


The answer may reveal more about your security posture than any technical assessment ever could.

Comments


Badge.png

t. +387 33 448 280

e. csec_official@csec.ba

a. Gradačačka 114

    Sarajevo, Bosnia and Herzegovina

White BA logo.png

The establishment of CSEC has been supported by the UK Government.

Subscribe to Our Newsletter

Thanks for submitting!

Follow Us On:

  • Facebook
  • LinkedIn
  • Instagram
  • Twitter
bottom of page