Protecting Sensitive Information

About this module

Not all data is equal, and this data protection training module shows you how to treat the data that matters. You'll learn the classify-minimize-control framework: label everything from public to restricted, keep only what you genuinely need, and limit access to the people who need it.

You'll also walk through the five most common handling mistakes, unencrypted email attachments, personal USB drives, shared credentials, unattended printouts, and why each one is preventable.

With the average breach costing $4.45 million and 83% involving human error, careful handling isn't bureaucracy. By the end you'll know exactly which data deserves special care and how to give it.

Key takeaways

  • If exposure would harm a person or the company, the data deserves special handling
  • Classify, minimize, control: the three-step framework for sensitive data
  • 83% of breaches involve human error, and each record costs about $150
  • Every extra copy (a USB, an email) is another exposure point

Full Transcript

Not all data is equal. A customer's financial record carries far more risk than a public blog post. Knowing which data is sensitive and how to handle it is one of your most critical responsibilities.

The average data breach costs four point four five million dollars, covering legal fees, fines, notification, and reputational damage. Most traces back to improperly handled sensitive data.

Sensitive data includes customer PII, financial records, health information, legal documents, trade secrets, and credentials. Simple rule: if its exposure would harm a person or your company, it deserves special handling.

First: classify. Label every piece of data: public, internal, confidential, or restricted. Classification determines how you store, share, and dispose of it.

Second: minimize. Only collect and keep the data you genuinely need. Every extra copy (on a USB, in an email) is another exposure point.

Third: control. Limit access to people who need it. Encrypt sensitive data in transit and at rest.

Never share credentials: every person must use their own. Classify. Minimize.

Control.

Internal data stays within the company: no external emails or personal accounts.

Restricted data, including PII, financials, and legal files, requires encryption, manager approval, and strict need-to-know access.

Emailing sensitive files without encryption. Unencrypted email can be intercepted: use secure transfer for anything confidential.

Saving customer data to personal USB drives. Personal devices aren't secured. A lost USB is a reportable breach.

Sharing credentials so a colleague can access a confidential system. Every person must use their own login. No exceptions.

Leaving printed sensitive documents unattended. A page left on a desk is a data exposure with no technology involved.

Each is preventable. Don't let convenience override security.

Eighty-three percent of breaches involve human error. Nineteen percent are accidental exposures. Two hundred and seventy-seven days to detect.

One hundred and fifty dollars per record.

Data is the new oil. And like oil, a spill is expensive, hard to clean up, and damages everything it touches. Handle it accordingly.

Classify what you handle. Minimize what you keep. Control who can access it.

Module Seven covers malware and ransomware.