Data security starts with you…
Ever notice how one topic suddenly pops up everywhere once you’re thinking about it? Like when you’re car shopping and everyone seems to be driving the one you’re considering.
For me right now, it’s multi-factor authentication or MFA I’ve talked about it before, it massively cuts down data breaches.
At the moment it’s the darling of data protection… at least until the Bad Players figure out a workaround and we’re onto the next round of technological leapfrog.
But thinking about multi-factor authentication got me onto a bigger question:
How much responsibility should individual people take for data security in their organisation?
Sure, the organisation itself has to put strong measures in place. But underneath that, how much is it fair to expect from individuals? And what do you do when someone just doesn’t bother?
I’m not talking about people deliberately selling data, I mean the everyday shortcuts that chip away at security:
- Ignoring MFA, even when it’s available
- Saving critical passwords in a browser so logging in is a breeze
- Giving me a password that’s literally the founder’s name plus the charity start date. (Honestly, you might as well write Pa55w0rd! on a Post-it.)
- And my personal favourite: sending sensitive data in an Excel sheet by email. With a password. Which Google will cheerfully show anyone how to break.
And here’s the kicker: stats show it’s smaller organisations (under £1m) that are most at risk. It doesn’t take a massive heist either, 100 rows of personal data is still worth something on the Dark Web.
So, here’s the uncomfortable bit. Maybe it’s time for individuals to face actual consequences for bad habits. Because if an organisation has gone above and beyond with security, but Janet refuses to use MFA, reuses Pa55w0rd! everywhere, and happily emails client details to “whoever asked”… should the blame really fall on the organisation?
I’ll leave you to think about that one.




