There is a legend about Team Fortress 2, the video game that refuses to die, that somewhere in its files there is a coconut.
No purpose. No function. Just sitting there.
And if you deleted it, the whole game would break.
That was not true, as it turns out. The coconut was real, but it was not holding the game together. Still, the rumour stuck because it felt true. Anyone who has spent time inside a large organisation understood it straight away.
Yes. We have one of those.
Only it is not a coconut.
It is a spreadsheet.
Obviously.
It is called something like Final_Final_Updated_v9.xlsx and it lives in a shared drive folder called Old Stuff, Do Not Delete. Someone built it years ago on a Tuesday afternoon because the actual system could not do what the business needed. It was meant to be temporary. Just a workaround. Just something to get through the week.
But it worked.
So they sent it around. Other teams started using it. A manager asked for a monthly version. Someone added a pivot table. Someone else added colour coding. A few more columns appeared. Then a tab for exceptions. Then a tab for the board report. Then a tab nobody understands but everyone is afraid to delete.
Quietly, without anyone approving it or even really noticing, the spreadsheet became part of how the business runs.
Nobody designed it as infrastructure. But here we are.
One person knows how it works. They know the formula in column H breaks if you sort the data. They know the extract has to run on Wednesday because Thursday numbers are off, and nobody asks why. They know which tabs matter, which ones are dead, and which cells should never be touched.
They know that if the number looks wrong, you check the lookup table first. They know that one supplier has two names in the system. They know that customer status means one thing in finance and another thing in operations. They know the dashboard only works because they clean the file before anyone sees it.
They are not just using the system.
They are the system.
And at some point, they are going to leave.
The risk is not dramatic. That is the problem.
Nobody loses a spreadsheet in a blaze of glory. It is quieter than that. A formula references a row that no longer exists. A pivot table stops refreshing and nobody notices because the numbers look close enough. Someone copies a figure into the wrong cell and it ends up in a board pack.
A senior leader makes a decision. A compliance report goes out. A forecast gets accepted. A project gets funded. Everyone assumes the data came from a controlled process because the final number appeared in a clean dashboard.
But behind the dashboard is a file.
Behind the file is a person.
Behind the person is a set of habits nobody wrote down.
IT thinks the platform is running the process. The data team thinks the pipelines are clean. Leadership sees the report. Each group is technically right, but none of them sees the full chain.
Nobody sees the spreadsheet at the bottom of the stack, holding the whole thing together with hope and conditional formatting.
This is where data risk often lives. Not in the systems everyone audits. Not in the platforms with formal owners, security roles and change logs. It lives in the gaps between those systems. The small manual steps that became normal. The copy and paste routine nobody questions. The reconciliation that happens because the official numbers never quite match. The file that is too useful to retire and too risky to admit.
So how do you find yours?
Ask this in the right room: “What would actually break if your files disappeared tomorrow?”
Not the big systems. Everyone knows about those. Look for the gaps. The Monday morning manual extract. The reconciliation someone runs before the board pack goes out. The report is still emailed from a personal account because that is how it was set up in 2019, and nobody changed it.
Ask where numbers are adjusted before they are published. Ask which reports depend on one person. Ask which files cannot be moved, renamed or deleted. Ask which spreadsheet everyone uses but nobody owns.
These things are not hiding.
They are just not where anyone thinks to look.
And then what?
Do not ban spreadsheets. That kind of policy gets announced in an all-staff meeting and ignored by Thursday. Spreadsheets are not the enemy. They are useful, flexible and often the fastest way for a business to solve a real problem.
The issue is not that spreadsheets exist.
The issue is when they quietly become business-critical without the controls that business-critical things need.
The goal is simpler. Work out which files have become important enough to care about, then care about them properly.
Where does the data come from? Who owns it? What do the numbers mean? Who checks the output? What happens when the owner is away? Is there a documented process? Is the file using current definitions? Is the process still manual because it needs to be, or because nobody got around to fixing it?
This is not just a technology problem. It is a data management problem. It is about ownership, meaning, quality, lineage and risk. It is about knowing which data assets matter and making sure they are managed in a way that matches their importance.
Because the spreadsheet may look harmless.
It may even look boring.
But if it is driving decisions, reporting risk, feeding dashboards, supporting compliance or shaping what leadership believes to be true, it stopped being a side file a long time ago.
Treat it like what it is.

Renzo Ramirez
ConsultantnCDMP Associate






