Every day, your data is at risk, not only from external hackers but also from internal weaknesses.
It can start with ordinary behaviour: an old spreadsheet in your inbox, an “Anyone with the link” share, or an ex-employee whose access was never removed. Any of these oversights could have a major impact. IBM’s 2025 Cost of a Data Breach Report places the global average cost of a breach at USD 4.44 million (IBM 2025).
Beyond financial loss, there are regulatory, reputational, and ethical consequences. Customers, partners, and colleagues have trusted us with their information, protecting it is everyone’s responsibility, not just the security team’s.
This article shows how data governance and data security start with you, plus give you practical steps you can apply today.
Two Trends Make the “Human Element” More Important Than Ever
Human behaviour remains the top risk.
- Verizon’s 2025 Data Breach Investigations Report found that around 60% of breaches involve the human element, with phishing one of the top initial access vectors.
AI is increasing risk and exposure.
- IBM reports that 1 in 6 breaches now involve attackers using generative AI, while employees are increasingly access GenAI systems on corporate devices, often with personal accounts (2025).
Resulting in AI used both to create attacks (deepfakes, phishing) and to accidentally leak sensitive information when employees paste confidential data into public tools.
Why You Matter: Governance Is Built on IndividualsData governance is about decision rights, accountability and standards for how data is valued, created, used, and controlled. It’s not just a policy binder, it’s who decides, who’s accountable, and how that accountability is proven (World Bank 2022).
Data security enforces those decisions through a control layer of access, encryption, logging and monitoring (NIST Cybersecurity Framework 2.0). When governance and security align through clear stewardship, policy, and auditability, risk drops dramatically. But many breaches happen not because people are careless, but because they’re uncertain about what they should or shouldn’t do. When employees lack clarity, they make well-intentioned but risky decisions, like using personal AI accounts or sending sensitive data to their Gmail.
That uncertainty represents a governance failure as much as a security one. “Strong, clear policies and procedures are at the foundation of security governance.” (DMBOK 2). Governance’s role is not just to write those policies, but to ensure they’re understood and lived out by every employee.
Security depends on informed behaviour, and governance ensures that people know their responsibilities, understand why they matter, and have clear guidance to act correctly. The individual sits at the centre where governance meets security.
Practical Actions You Can Implement Right Now
PII Spring Clean
- Delete old spreadsheets, files and archives that contain personally identifiable information (PII) or company confidential data that are no longer needed. If retention is required, move the files into a governed location and label them appropriately. Tools such as Microsoft Purview Information Protection, or the Databricks newly released Data Classification in Unity Catalog which can automatically detect and classify sensitive data (Databricks 2025). Remember that old Excel sheet you downloaded last year with customer names and addresses? If you still have it, it’s a ticking risk.
Access Review
- Check who has access to dashboards, drives, and shared folders. Remove ex-employees and contractors and replace any “Anyone with the link” shares with named access only.
Phishing Readiness
- Users with recent phishing-awareness training report simulated phishing attempts 21% of the time versus 5% without training (Verizon 2025). Review your training schedule and report (not forward) any suspicious emails to reduce exposure.
Password & MFA Sweep
- Use unique passwords and multi-factor authentication (MFA) for all systems handling sensitive or financial data, including email, CRM, Git, and collaboration tools. Review your companies governance processes to strengthen your understanding of what best practice looks for you.
Information Transfer Review
- Stop sending confidential or sensitive data to personal email or consumer cloud storage (Gmail, Dropbox). Use approved corporate systems with audit trails.
GenAI Hygiene
- Do not paste customer or company data into public GenAI tools. Verizon (2025) highlights “the potential for corporate-sensitive data leakage to GenAI platforms.” Ensure your organisation uses approved AI tools with corporate sign-on and clear data-handling terms.
API Tokens and SaaS Permissions
- Supply-chain compromise is now the second most common breach vector (Verizon 2025). Revoke unused API tokens, rotate secrets regularly and require multi-person approval for any new connector that can read or export sensitive information.
Data Incident Readiness
- Know your internal incident response contacts, confirm that access logs and backups are enabled, and test how long it takes to detect and contain a simulated breach.
Physical Security
- Lock your computer when away from your desk, store printed documents securely and shred any hard copies containing confidential information.
Final Thought
Firewalls, frameworks, and monitoring tools matter, but your habits determine whether security and governance truly work in practice. Start small by deleting one risky file, removing one unnecessary share, or reporting one suspicious email. Challenge your team to see who can remove the oldest, forgotten “data time bombs.”
The best defence isn’t just technology, it’s people who understand their responsibility and act accordingly.

Ryland Stanmore
Data Consultant
Certified Data Management Professional






