Yet Another Data Breach
All Posts
Data Governance

Yet Another Data Breach

By Günter Richter

At an event yesterday evening, I talked to several business owners and business leaders, from small and mid-size organisations, about their data challenges. There were a number of themes that emerged, but the common one was that of customer data. How best the data can be used to drive business value and improve customer experience, but more importantly, how to do this in a safe and legal way.

These conversations left a positive imprint on me, knowing that small and medium-sized organisations are recognising, not only the value of data, but the importance of protecting it and managing it accordingly.

Switch to this morning, where one of the first emails in my inbox is from Westfield (Shopping Centre), reading “We have recently been made aware of unauthorised access to one of our databases containing certain information relating to customers...”. It seems the information involved (a bit of a euphemism) is my name, email address, telephone number, postcode, and date of birth. Just enough to make identity theft easier for criminals.

It would be unfair to single out Westfield here, because they are just one organisation in a long list of personal data breaches; Soundcloud, Substack, Trello, Planet Ice, Twitter, Canva, MyFitnessPal, Adobe, Dropbox, and the list goes on.

As we all know, there are harsh penalties for running afoul of the relevant regulator. The Information Commissioner’s Office lists 204 enforcement actions against organisations and individuals, including 55 monetary penalties and three prosecutions.

Why then do organisations continue to suffer these data breaches, with alarming regularity?

Taking off my data hat and putting on my organisational change hat, I would reframe the question into five parts.

  1. Awareness. Are organisations not aware of the importance of good data management practices, and the legal implications of poor ones?
  2. Desire. Are organisations aware of the risks of poor data management practices (or, if done right, the rewards of good data practices)?
  3. Knowledge. Does the organisation collectively have the knowledge to manage data in a safe and secure way?
  4. Ability. If the organisation (and its people) have the necessary knowledge, are they able to translate it into ability?
  5. Reinforcement. Having ticked the previous four boxes, is the organisation able to sustain the changes they have made over time? Do they consider good data management practices a one-off paper-based exercise? Or an ongoing effort as the organisation and its environment evolve?

My experience is that different organisations are at different stages of this journey. I would love to hear your thoughts on this. Let me know in the comments where you think the stumbling block for many organisations is.

Share:LinkedInX
Günter Richter

Günter Richter

Founder & Principal Consultant, Umlaut Consulting

30+ years of experience in strategic consulting and data transformation. Helping organisations unlock the real value of their data.

Related Posts