Episode Transcript
[00:00:00] Speaker A: Welcome to the lightning round of information governance. We will discuss how do you would we did we should you Over a variety of interesting topics, over a series of episodes.
Hello and welcome to what Counts. Every organization hides a story in their data. This is a podcast that digs into the governance problems people inherit, ignore and discover too late. Hi, I'm Lee and as always, this is my co host, Maura Dunn. Maura, this lightning round is going to be around IG risk.
How do you think about information governance risk in an organization?
What does that mean?
[00:00:42] Speaker B: No, I want to ask you what even is information governance risk?
[00:00:48] Speaker A: So when I think of information governance risk, I think of data breaches right off the bat.
And so what does that mean? Even like what gets breached in an organization?
It's the information that's not supposed to be public, it's supposed to be private, or it's supposed to be sensitive.
And so what is that even?
So financial records that your organization has, pricing or whatever other your accounting records, those are financial records that shouldn't be shared with the rest of the world unless you're a publicly public company.
Other sensitive information. Now we're getting into personally identifiable information that's important stuff that shouldn't be shared either because I know organizations keep this information.
So the risk is having this information, not securing it and having it get out in the wrong to the wrong parties. That's IG risk.
[00:01:53] Speaker B: So I think that's. That is one good answer about IG risk, but I want to throw a different one at you.
What if the risk related to your information governance is you can't find things when you need them? That's a different risk.
Or you depend on someone else to hold important information.
[00:02:12] Speaker A: If you can't find it, how is somebody. How is a hacker gonna find it?
[00:02:16] Speaker B: But anyway, a hacker could find it because they have more patience and different tools maybe, but mostly it's about patience. They're only.
Because the difference between you looking for information is you're trying to find the right thing to do the next piece of work that you need to do. A hacker is looking for, like you said, any kind of financial information that they can use against you or that they can use to make money or in some other nefarious way.
It's a whole different. I'm going to call that a secondary use of your data, but in a very malicious sense. But I was thinking about a story I read this week about several New England, I think it was New England PBS stations who had been depending on a cloud provider to hold Archives of their shows and the cloud provider, I don't know if they went out of business or if they, they had a breach or they had a technology failure, but 70 years worth of data from that belonged to the PBS stations has currently disappeared from view.
Yeah, it's pretty serious. They. So it's not accessible. It may still exist.
Like I said, the story is new and, and I don't think they know exactly what happened. So hopefully that data still exists.
But right now nobody knows how to get to it because the path is broken.
So that's an information governance risk.
[00:03:52] Speaker A: Yeah, I like that one better. Not being able to get to information because that directly goes to a company's bottom line. Right?
A data breach does too. But there are companies out there that might not care about a breach because they've never been stung before. They never had any incidences that caused them any scares.
So they're not so worried about it and they feel like their security system is good enough.
[00:04:20] Speaker B: They also might feel like their data isn't that sensitive.
If you're not a, if you don't, if you don't hold as a company, if you don't hold a lot of privacy protected information, then your risk is lower as a target for a data breach because who's going to bother to try and steal the names of six public vendors that everybody knows about from you as opposed to you're a hospital and you have tens of thousands of patient records that have all kinds of identifying information covered by HIPAA and covered by the Privacy act and potentially useful in identity theft.
That's a much bigger target for somebody than a small company that buys, you know, paper clips from Staples.
So, so I think that that is a way to think about risk is okay, we have risk from data breaches, everybody has them. But is our risk from a data breach high or low?
And it's higher depending on the type of data you're storing and, and where you're storing it.
You also have risk of not being able to access your information.
So there have been a number of stories in the news lately about hospital systems, school systems being held hostage by hackers where you can't reach your own data because they've locked it down somehow, maybe through a phishing email that somebody clicked on or something like that.
And you, this isn't even valuable data to anybody else and nobody's even trying to use it. They're just preventing you from using it, which makes your business dead in the water.
And that's a problem. So that's a Different risk.
Keeping all your stuff on a hard drive, on one hard drive is a risk because what if your hard drive dies or what if you forget your laptop or it gets stolen?
[00:06:20] Speaker A: My mechanic thinks that if he scans all of his receipts and all of his paperwork and it's in one machine or one drive or something like that, and if he loses that, it's over with. Like that's his biggest concern.
And so he has everything in paper and keeps everything in boxes all throughout the office.
[00:06:43] Speaker B: And yeah, and that's, I get, I get where he's coming from. First of all, he's one guy in one office.
Paper is secure. Unless it catches fire, it's pretty much going to be accessible, it's going to be legible. We have paper going back thousands of years to the beginning of paper.
So certainly in the lifetime of a garage and the lifetime of a mechanic, he's going to be able to access those receipts. It's not going to be easy at all. He's going to have to go, remember what year was that we had?
[00:07:19] Speaker A: That's exactly what happened. Hold on, I have that, what was it, three weeks ago? Okay, hold on, I have that one in this box over here.
[00:07:26] Speaker B: Yes, the geologic strata method of organizing information.
As one of our former clients once said.
Just how long ago was that in the pile on my desk? Yeah, boxes are the same way.
But his risk is low. His risk related to his information is low. And that's what we're really talking about here is think about the risk that you have related to information.
If you're a one man shop, one man mechanic shop, you keep in all your paperwork, you do have some risk because you probably have employees and you have some record keeping requirements and reporting requirements related to them and you have some regulated substances because there's hazardous materials involved in a mechanic shop and you have to be able to demonstrate that you disposed of them properly so you someday don't become a Superfund site.
So some records are more important than others there. And you have your financial records to support your tax returns. Those are the three key records that he has to worry about. And, and is if his business isn't so big and volume isn't so big, he can probably do that in a paper method in boxes a year at a time.
And okay, but if you are a charter school and you have certification records to go through, whatever certifying body is saying you are an active and an approved school, you have the local school board, you have the possibly a state institution, you have a charter School certifying body, possibly you might have one, an independent organization like Middle States school accreditation process.
If you are a charter school, middle States being the one that's in the Mid Atlantic region. I'm just the one I'm familiar with.
You might have a, a charter school that subscribes to an international program like the International baccalaureate. And then you have accreditation requirements to be able to say, yes, we are an IB school.
And so all the records for all that certification process, those have, those have a lot of requirements.
And those requirements include student records maybe because they have to include that students were taught the right things. So you have curriculum records, you have student records. Did they pass the classes? Did they take all the right tests, did they do all the projects? Did the projects meet all the standards? You have teacher evaluations and certifications and credentials records. So now you've got the process of accreditation, the building of the curriculum, the content of the curriculum, the quality of the curriculum. You've got the student activities related to the curriculum, you got the teacher activities and certifications related to the curriculum.
And that's just programmatically, that's if the school doesn't have a building and doesn't have other classes and doesn't have to meet other requirements for safety or you know, occupational safety and health, for having good lighting and good desks and decent chairs and lab equipment and security and a roof that doesn't leak and all of the maintenance pieces.
So now you've got a lot of records and student records have a very long life because students come back and ask for transcripts 50 years after they graduate. And where do you keep all that?
That's hard to keep in paper and your risk goes up.
[00:11:17] Speaker A: So, so wait a minute. Okay, I, I got all that.
Age is what I was trying was going around in my head. Does it how long a company has been in existence, does that relate to IG risk?
The it. Okay, go ahead.
[00:11:36] Speaker B: It does, I think in two ways. I think the first way is sheer volume because if you have just kept all your stuff for all these years, then it's harder to find things.
I think the other thing is that the business changes and the rules that you followed early on might not be good rules for later.
And if you have information that showed that you followed those old rules and it's still around and somebody sues you, you have to produce it and then that could bite you. And we've seen clients have that issue where, you know, underwriting policies changed in 50 years time, but the original underwriting policy records were still around and underwriting records for specific policies were still around and they ended up having to account for that or environmental policies have changed a lot in the last hundred years from none to a lot.
And if you were in an infrastructure or any, any organization, any organization that had an impact on the, the geography where it, where it was, the location where it was, if you were, we talked about that. Your mechanic and the toxic substances that he has to dispose of. Well, 75 years ago, people, people just dumped that stuff in the ground, on the ground, in a lake, in a river. And it had an impact.
So your age as a company, if you were here at the beginning of time doing things like that, then your records about when you realized it was a problem and you changed your process and why your new processes meet the current requirements. Like all of that becomes really important so that, that longitudinal look at your records becomes important.
I think similar to. So we talked about size, we talked about age, we've talked a little bit about regulations.
Should we talk about industry?
[00:13:52] Speaker A: We could go there. But what does it mean?
Like, I don't know if we got to that yet.
We said that information would be lost. You can't find things. So if you don't have an information governance program or some sort of process.
Right, you can't find things.
Auditors will have a field day with you, which means regulators will have a field day with you if you can't prove what it is that you need to prove, which then means that the courts could have a field day with you. If you can't prove what it is you need to prove to get your business out of trouble, that you had insurance, didn't have insurance, didn't have something, or. Or should have had something.
[00:14:31] Speaker B: Yes. And that goes both ways. Either you have stuff from a long time ago that you could have gotten rid of that shows that you did something wrong, or you don't have things that you should have that would show that you did something right. Could go either way. So the risk is, is something bad going to happen because you don't have the. Because the information that you have is not being managed correctly, the information that you created is not being managed correctly. And the bad things that could happen are you can't find your data, you lose your data somehow through hacking, through a data breach, through something else. You can't demonstrate that you were in compliance with laws and regulations either because you do have information and it demonstrates that you weren't in compliance, or you don't have information that would have demonstrated that you are in compliance, you have too much information and you can't find it.
Which. That one. If it's too much information and you can't find it and it just takes a long time, then it's kind of an efficiency hit. But maybe the impact isn't as big as you're the PBS station whose archive got lost because you're fly by night cloud provider.
That, that is not fair. I do not know anything about this cloud provider. But because your cloud provider failed and you no longer have access, if you were a publicly traded company and you used a cloud provider that failed and your access to critical information was cut off, then as a publicly traded company, you could be in breach of your fiduciary responsibilities to your shareholders.
So this is a due diligence, let
[00:16:15] Speaker A: alone lose stock price, stock value.
[00:16:18] Speaker B: Right, your stock value for sure. But also you might owe people on top of that because you did a bad job running the company, because you didn't do a good job by picking your provider or due diligence piece is important.
[00:16:35] Speaker A: I kind of jumped to the end with my. Or. I was going to say or you put an AI system in place without having an IG program and things go haywire.
[00:16:46] Speaker B: So an AI system, just like any other provider, if you don't understand what you're asking for and you don't understand who's responsible for what, and that includes you, what are your responsibilities in using an AI or putting data in the cloud or whatever the other options are, whatever the other things you could do are, then, yeah, that's a. That's bad management.
It's bad governance.
And in the case of shareholders or stockholders, it's a breach of fiduciary responsibility because you're supposed to be protecting that data. You said you needed that data to do your business. We paid you money to get that data to protect it, to do the business, and you didn't.
So I think that's. When we think about IG risk, we. We take all of this into account and then what do we do with that information?
Like that's part of. It's not just enough to know the risk, it's now we know the risk and we make better decisions about how do we set up a retention schedule, what repositories do we choose, what providers do we choose?
Do we follow the retention schedule and actually get rid of data when we should have we correctly assessed the value of the data and how long it needs to be kept in order to meet all the legal and regulatory requirements as well as all the business needs of your organization or operational needs.
So this risk assessment piece is one part of how you decide to build your IG program.
And that's the reason that we bring it up all the time.
So this is another one of those that we think you should do it. And these are how you do that is these different questions that you, that you ask yourself and ask anybody who's working on it with you. So a potential vendor, a partner, somebody who's sharing, sharing your data and sharing your risk.
[00:18:46] Speaker A: Well, that was plenty long. That was an episode in itself.
[00:18:52] Speaker B: There's a lot. There's a lot in there.
[00:18:54] Speaker A: That was just a lightning round episode. That was the whole episode. If you have any questions, please send us an email at info trailblazer.us.com or find us on the web at www.trailblaz.
check us out at the Learning Academy or on the Microsoft Store, the Apple Store, the Google Store. We have apps and items that people will appreciate.
That's Trailblazer Consulting. Just do that search. You'll find us. Thank you for listening. Please tune in to our next episode if you like this one. Please be a champion and share it with people in your social media network.
As always, we appreciate you, the listeners. Special thanks goes to. Jason Blake created our music.
[00:19:39] Speaker B: Thanks everyone.