Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • IT Management

    Keeping Data Sanitization Policies Square With Enterprise Security

    Written by

    eWEEK EDITORS
    Published March 18, 2020
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      As data privacy legislation continues to expand across the globe, enterprise data management is quickly becoming a major headache for enterprise IT decision-makers responsible for compliance with new and existing consumer data privacy regulations, including the GDPR (2018) and the new California Consumer Privacy Act.

      Senior IT leaders shouldn’t be alarmed, but concern over financial penalties and reputation damage for non-compliance is warranted. In Blancco’s recent report on the topic, research firm Coleman Parks surveyed 1,850 senior leaders at enterprises with 5,000+ employees in the U.S., Canada, U.K., France, Japan, India, Singapore, Australia and Philippines. It found that while most enterprises have policies in place (96%), an astounding 56% are not effectively communicating these policies companywide on a regular basis. This lack of consistent communication on data sanitization policies and processes increases the potential for data breaches. 

      In this eWEEK Data Points article, Fredrik Forslund, vice president of enterprise and cloud erasure at Blancco, offers the top five takeaways from the study. He also shares the significance of these findings for enterprises seeking compliance with data privacy laws and regulations that aim to protect consumer privacy and give individuals more control over how their data is being used and stored.

      Data Point No. 1: Successful communication of data sanitization policies relies upon both the policy owner’s experience and organizational structure.

      The study’s findings show that while 68% of respondents believed that ownership of data sanitization policies is clearly communicated within their organization, 32% do not share this belief. According to survey respondents, the executives that “own” the policy vary widely from organization to organization: 18% of enterprises stated the data protection officer (DPO), 18% pointed to the head of operations, 17% said the head of IT operations, and 11% said the chief information security officer (CISO).

      The inconsistency in policy ownership may contribute to varying levels of efficiency and success in communicating the policy companywide, but what’s more important is the individual’s experience and the overall organizational structure. Equally important is the owner’s awareness of the importance of communicating data policies and ability to execute.

      Data Point No. 2: Equipment left in storage areas is putting companies at risk of insider threats and data breaches.

      According to Verizon’s 2019 Data Breach Investigations Report, 34% of all breaches in 2018 were caused by employees. An even more alarming 2018 Forrester survey indicated that 53%of data breaches were the result of insiders, and more than half of those incidents were malicious in nature. While keeping old IT assets in storage is not in itself a threat, a risk of theft of unused equipment that might contain residual customer or company data is certainly real. 

      Of the global enterprise executives surveyed our study, 87% admitted to not sanitizing assets as soon as they reach end-of-life, while 31% reported taking more than a month to sanitize these devices. Only 13% reported immediately sanitizing assets once they reach end-of-life.

      Delays increase the risk of equipment loss, theft and data breaches as well as insider threats. Another interesting finding is that sanitization takes the longest in Germany and Singapore, with well over 50% of companies taking more than a month to sanitize or destroy equipment. 

      The bottom line: Organizations should immediately sanitize end-of-life equipment as part of their overarching data sanitization policy, preferably by embedding a process that integrates data sanitization of all end-of-life IT assets into existing remote asset management processes. This removes unnecessary risk during asset decommissioning. 

      Data Point No. 3: Flexible workers are most likely to compromise company data policy.

      The gig economy and remote work have become part of the business landscape in the U.S. and across the globe. Unfortunately, one-third of respondents at the global enterprises we surveyed believed that flexible workers were the least likely to comply with data sanitization policies, while 40% believed contractors or freelancers were the least likely to understand or comply with data sanitization policies. This number drops slightly (33%) for respondents in the U.S. and Canada. To ensure compliance with regional, national and global consumer data privacy regulations, organizations must have a consistent data management and sanitization policy that applies to all employees—whether they are contractors, seasonal workers or full-time employees, both remote and onsite.

      Data Point No. 4: Senior management is not taking direct responsibility for IT asset erasure.

      While perhaps hard to fathom, 22% of respondents said that employees are responsible for the management and control of their own end-of-life IT equipment when they leave the organization. Another 22% said the responsibility is with their line manager.

      One key concern with this process is whether the exiting employees or line managers are fully aware of or trained on the company’s data sanitization policy. And if not, who is verifying the PC or laptop has been sanitized correctly and no personally identifiable information remains? Again, communication and training are critical to maintaining company-wide data sanitization policies.

      Data Point No. 5: Outsourcing data sanitization comes with risks.

      More than a third of our respondents (34%) are sanitizing PCs, laptops, servers and data center equipment offsite at end-of-life. Outsourcing isn’t inherently a bad thing, but it does pose some risks, especially if organizations lack visibility into the chain of custody of their IT assets and have no way to prove that the data wasn’t compromised during the transportation process. If an organization has a data sanitization policy that requires all data is to be destroyed beyond recovery at end-of-life, it also should have the ability to prove this has been accomplished during an internal or external audit. It’s the company’s responsibility to require a detailed audit trail for the entire chain of custody and certified erasure at end-of-life for these assets.

      If you have a suggestion for an eWEEK Data Points article, email [email protected].

      eWEEK EDITORS
      eWEEK EDITORS
      eWeek editors publish top thought leaders and leading experts in emerging technology across a wide variety of Enterprise B2B sectors. Our focus is providing actionable information for today’s technology decision makers.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.