Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 6 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Confidential information at greatest risk in new businesses

by The Gurus
January 26, 2017
in Editor's News
Share on FacebookShare on Twitter

Businesses under five years old are twice as likely to compromise the confidentiality of sensitive information than more established businesses. This is one of the findings of recent research into information management and security practices in the mid-market, commissioned by leading storage and information management services company Iron Mountain (NYSE: IRM).
The in-depth study of mid-market businesses across Europe and North America found that staff at recently established organisations expose their businesses to information risk because they are less careful with critical business data. Nearly half (48%) of those surveyed admitted they had left sensitive documents lying about the office, had mislaid them completely or had lost them in a public place. This is twice as many as staff at more established firms, where fewer than one in four (23%) had made similar information management mishaps.
Younger businesses are considerably less clear on how long they are legally required to retain documents such as tax records, contracts and customer data, making these organisations more likely to put the safety of this information at risk. For example, more than half (59%) of business professionals at companies between one and five years old admitted they could be keeping sensitive human resource records beyond their retention deadline, exposing the business to the threat of reputational damage and fines from information regulators. This is compared with just 20% at firms with more than 25 years in business.
Yet young firms are doing little to address the situation, preferring instead to prioritise expansion into new markets (80%) or product development (54%). The majority (76%), for example, have no plans in place to automate key information management processes such as HR. They are also less adept than older firms at managing data protection procedures or extracting value from their information. When asked about their processes for regulatory compliance in data handling, just a third (32%) of respondents at firms under five years old said their processes are “relevant and easy to comply with”. By comparison, 46% of respondents at firms aged 25 years and over said the same. Similarly, just over a quarter (28%) of those at younger firms said they have effective processes in place to monitor where their information is most valuable, compared to two fifths (40%) of respondents at older businesses.
Elizabeth Bramwell, director at Iron Mountain said, “The first five years of a business’s life are often dedicated to rapid growth as the organisation establishes itself in the market. The start-up phase is a busy one, so it’s perhaps understandable that information management mistakes are more likely to happen during this time. However, whether you’re a new or an established business the law is the law, so it’s vital that confidential information is protected. If bad information habits are left unchecked and effective processes aren’t put in place, young businesses face severe legal and reputational consequences that could fast erode customer confidence and threaten the very survival of the business.”
Previous research from Iron Mountain and PWC[i] suggests that many mid-market companies experience an ‘information epiphany’ when the products or services with which they launched the business start to approach their end-of-life, which normally happens around the five to seven years stage.[ii] According to this research, over a third (38 per cent) of younger firms don’t know how information flows through the business, compared to 22 per cent of those aged six and over. To take a more mature approach to handling and harnessing the value of information, young businesses need to put effective information management processes in place from the start, which can then become part of their company culture as they grow.
[i] Iron Mountain and PwC surveyed 1,800 senior business leaders across a broad range of sectors (energy, financial services, legal services, manufacturing and engineering, healthcare (US only) insurance, pharmaceuticals), in North America (US and Canada) and five European countries (France, Germany, Spain, the Netherlands and the UK).
[ii] https://library.e.abb.com/public/a046973f29f765b0c1257c210039f2fb/3ADR025047K0201.pdf  and http://beyondplm.com/2012/12/31/plm-2013-what-is-your-7-years-plan/

ShareTweet
Previous Post

Despite rise in breaches, companies still prioritising network and endpoint solutions over encryption

Next Post

Zero Day Exploits will rise from once per week to once per day in 2021

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol