PROTECT · INFORMATION & DATA
Information & Data — Do You Know What You Need to Protect?
Protecting everything in exactly the same way is neither practical nor necessary. Start by understanding which information really matters.
Information has value because the business uses it
Customer records, employee information, contracts, invoices, designs, financial data and supplier details all support different business activities.
The first security question is not “Where is all our data?” It is “What information do we rely on, and what would happen if we could not trust it, access it or keep it private?”
Think about three consequences
Confidentiality: what happens if information reaches somebody who should not see it?
Integrity: what happens if information is changed, accidentally or deliberately, and people make decisions using the wrong version?
Availability: what happens if the information is unavailable when the business needs it?
These questions turn information security from an abstract technical subject into a business conversation.
Know where important information goes
Information moves. It may begin in an email, enter a cloud service, be downloaded to a laptop, shared with a supplier, copied into a spreadsheet and eventually archived.
That means protection is not only about one database or one server. The business needs enough understanding of the information lifecycle to make sensible decisions about access, sharing, retention and recovery.
Give important information an owner
Technology teams may operate the systems, but the business usually understands why information exists and how it is used. Someone should be able to explain who needs it, how accurate it must be, how long it should be retained and what harm could result from loss, alteration or disclosure.
Ownership makes those decisions visible.
BOI ACTION
Choose one important set of business information.
Write down: why you need it, where it is stored, who needs access, who is responsible for it and what would happen if it were lost, changed or exposed.
If one of those answers is unclear, that is your next check.
A useful question for the business
Which information would hurt the business most if we lost it, could not trust it or disclosed it to the wrong person?
Don’t assume. Check.
Do not assume information is protected simply because it sits inside a reputable system. Check how your organisation actually uses, shares and controls it.
NOT SURE WHERE TO START?
Take the 15-Minute Business Security Check
Ten questions will help you identify three areas worth looking at first.
Useful guidance
BOI’s publication QA will verify current UK-first guidance on protecting business and personal information, supported where useful by recognised international standards and guidance.
Continue exploring
Once you know what information matters, the next question is who can get to the systems that hold it.
Explore the Cyber Security Guides →
Found something that may be outdated or incorrect? Let us know.
Better Decisions. Stronger Organisations.
Understand what matters. Take sensible action. Check whether it worked.