You didn’t tell me not to murder someone!

You didn’t tell me not to murder someone!

Over the last few years I’ve had to flag up several cases where a client has sent me data in a manner that poses a security risk.

I’m not going to make out that is a frequent occurrence – it really isn’t, although risk-averse me has a mild panic when it does. I’m also not going to infer that it’s done maliciously. It’s quite scary how little people understand about the basics of data security and the risk points.

What I am going to tell you is the story of the two most common reasons.

(1) I sent it from my-email@org.org.uk to their-email@org.org.uk so it’s secure.

This one has me scratching my head. Non techy people often think that sending an email to another email on the same domain presents a protected-from-the-outside closed loop, that is impervious to outside intruders. It’s not like you’ve sent it down the string between two baked bean cans, although sometimes I think that people imagine it very similar to this.

Emails aren’t a secure transfer method by default – even when they’re sent within the same organisation.

(2) You didn’t tell me not to.

If someone committed murder and their entire defence was based on “You didn’t tell me not to, so I’m not guilty” you’d understandably have an issue.

Your organisation should have guidance, processes and functionality in place for transmitting data to third parties. Either these exist and you don’t know about them, or your organisation doesn’t have them. Neither of those scenarios is great, but in the first scenario you have the ability to make changes and adopt good practice. In the second you may not be able to make the decisions, but you can become an ambassador for change and encourage your organisation to be better.

We live in a world of technology and most people cannot remember a time it didn’t exist. Normalcy breeds complacency, and we start to treat these things as someone else’s problem: IT will have things in place, someone else will tell me what to do. But data security is everyone’s problem. IT, SLT and the Board are not omniscient and cannot police everything everyone does all the time. We are entrusted to behave in a way that ensures we don’t generate unnecessary risk, be it safeguarding, health and safety, or protecting data.

If any of this feels a bit close to home, I’ve got some availability from mid-May to help teams put a few simple, sensible practices in place.

And if you know a team that’s a bit stuck with their data – whether that’s processes, their CRM, or just getting things to work as they should – I’d really appreciate an introduction.

#DataQuality
#CRM
#CharitySector
#DataGovernance
#Nonprofits