Just Because You Can Keep It Doesn’t Mean You Should

Most of us have a drawer somewhere in the house filled with things we’re keeping for reasons we can no longer explain. Mine has the usual collection of old charging cables, mystery keys, instruction manuals and at least one adapter that I’m convinced belongs to something important. I don’t know what that something is, but throwing it away still feels risky.
 
Digital information has a way of becoming that drawer.
 
I started thinking about that while reading two of this week’s Security stories. Researchers found more than 16,000 misconfigured Supabase instances exposing information publicly on the internet, including personally identifiable information, authentication tokens, credentials and private communications. In another incident, Japanese car-sharing company Times Car reported a cyberattack affecting approximately 6.6 million user accounts, including sensitive identity information.
 
When stories like these happen, we naturally want to understand how the information was exposed and what could have prevented it. But while reading them, I found myself wondering about something that happens much earlier in the life of that data: why was it collected, and how often does anyone go back later to decide whether it still needs to be there?
 
Organizations collect information for perfectly legitimate reasons. A driver’s license might be needed to verify someone’s identity. An application needs information to provide a service, while support conversations, transaction histories and logs can all have real operational value. The decision to collect the information may have made complete sense at the time.
 
The interesting part is what happens afterward.
 
Technology has made it incredibly easy to keep information. Storage is inexpensive, and deleting something can feel riskier than leaving it alone because somebody might need it again. Over time, databases grow, applications change, customers leave, projects end and the original reason for keeping a particular piece of information can become harder to remember.
 
Security teams inherit responsibility for all of it.
 
That’s what makes data retention more than a records-management exercise. The longer sensitive information remains in an environment, the longer the organization has to protect it. If the business genuinely needs that information, then that responsibility is part of operating the business. But if the information no longer serves a meaningful purpose, we’re accepting risk without getting much in return.
 
One way to think about this is to add a few questions to the ones we already ask about sensitive data. We obviously want to know whether it’s encrypted, who can access it and whether that access is monitored, but it can also be useful to understand when the information was last needed and what requirement is keeping it there. Sometimes the most revealing question may simply be whether anything meaningful would happen if it were deleted.
 
That becomes particularly important when the information is difficult for the person on the other side to change. An organization may only need an identity document briefly to complete a verification process, for example, while the individual represented by that document could live with the consequences of its exposure for years. The useful life of the data to the business and the useful life of that same data to an attacker can be very different.
 
None of this means organizations should start deleting information indiscriminately. There are plenty of legitimate operational, regulatory and legal reasons to retain data, and some information becomes more valuable over time. The point is simply that keeping something should be a decision too.
 
We spend a lot of time in Security figuring out how to better protect the information organizations have. This week’s stories were a good reminder for me that occasionally we should also ask whether we still need to have it.
 
As for the mystery adapter in my junk drawer, I’m giving myself another year. I’m almost certain its moment is coming.

Tiffany Carberry
Pinpoint Security
Pinpoint Protocol lock logo

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Pinpoint Protocol lock logo

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.