Data security controls not fit for purpose, report claims

71% of employees in a new survey report that they have access to data they should not see, putting companies’ data security at high…
Digital grid lines on dark background

Share this article:

Despite a growing number of data breaches occurring under the glare of the public spotlight, 71% of employees in a new survey report that they have access to data they should not see, and more than half say that this access is frequent or very frequent.

As attention shifts from sophisticated external attacks to the role that internal vulnerability and negligence often play, a new survey commissioned by Varonis Systems, Inc. and conducted by the Ponemon Institute suggests that most organisations are having difficulty balancing the need for improved security with employee productivity demands. Employees with needlessly excessive data access privileges represent a growing risk to data security due to both accidental and conscious exposure of sensitive or critical data.

The survey report, “Corporate Data: A Protected Asset or a Ticking Time Bomb?” is derived from interviews conducted in October 2014 with 2,276 employees in the United States, United Kingdom, France, and Germany. Respondents included 1,166 IT practitioners and 1,110 end users in organisations ranging in size from dozens to tens of thousands of employees, in a variety of industries including financial services, public sector, health & pharmaceutical, retail, industrial, and technology and software where data security is critical.

Dr. Larry Ponemon, Chairman and Founder of The Ponemon Institute, a leading research centre dedicated to privacy, data protection, data security and information security policy, observed, “Data breaches are rampant and increasing. The sheer growth of both digital information and our dependence on it can overwhelm organisations’ attempts to protect their sensitive data. This research surfaces an important factor that is often overlooked: employees commonly have too much access to data, beyond what they need to do their jobs, and when that access is not tracked or audited, an attack that gains access to employee accounts can have devastating consequences. ”

Lack of control, data growth hampering productivity

Both IT practitioners and end users are witnessing a lack of control over employee access and use of company data, and the two groups generally concur that their organisations would overlook data security risks before they would sacrifice productivity. Only 22 percent of employees surveyed believe their organisations as a whole place a very high priority on the protection of company data, and less than half of employees believe their organisations strictly enforce security policies related to use of and access to company data. Further, the proliferation of business data is already negatively impacting productivity − making it harder for employees to find data they truly need and should be able to access, and to share appropriate data with customers, vendors and business partners.

Other key findings on control and oversight include:

  • 71% of end users say that they have access to company data they should not be able to see.
  • 54% of those end users who have access they shouldn’t characterize that access as frequent or very frequent.
  • 4 in 5 IT practitioners (80%) say their organisations don’t enforce a strict least-privilege (or need-to-know) data model.
  • Only 22% of employees say their organisation is able to tell them what happened to lost data, files or emails.
  • 48% of IT practitioners say they either permit end users to use public cloud file sync services or permission is not required.
  • 73% of end users believe the growth of emails, presentations, multimedia files and other types of company data has very significantly or significantly affected their ability to find and access data.
  • 43% of end users say it takes weeks, months or longer to be granted access to data they request access to in order to do their jobs, and only 22% report that access is typically granted within minutes or hours.
  • 60% of IT practitioners say it is very difficult or difficult for employees to search and find company data or files they or their co-workers have created that isn’t stored on their own computers.
  • 68% of end users say it is difficult or very difficult to share appropriate data or files with business partners such as customers or vendors.

Uncovering internal vulnerability

The findings also convey that both IT practitioners and end users agree that the compromise of employee accounts that can lead to external data security breaches are most likely to be caused by insiders with too much access who are frequently unaware of the risks that they present. 50% of end users and 74% of IT practitioners believe that insider mistakes, negligence or malice are frequently or very frequently the cause of leakage of company data. And only 47% of IT practitioners say employees in their organisations take appropriate steps to protect the company data they access. When permissions management and auditing capabilities are not in place, employees’ excessive access to data and their negligence for security are increasingly putting company data at risk.

Other key findings on root causes of data security breaches include:

  • 76% of end users say their job requires them to access and use proprietary information such as customer data, employee records, financial reports, and confidential business documents.
  • 38% of end users report that they and their co-workers can see “a lot of data” that they believe they should not have access to.
  • Only 47% of IT professionals say end users in their organisations are taking appropriate steps to protect company data accessed by them.
  • 76% of end users believe there are times when it is acceptable to transfer work documents to their personal devices, while only 13 percent of IT practitioners agree.
  • 49% of IT practitioners say it is not likely or there is no chance that when documents, files or emails are lost or change unexpectedly, the organisation will be able to assess what happened to them.
  • 67% of IT practitioners say their organisation experienced the loss or theft of company data over the past two years, while only 44 percent of end users believe this has happened.

Yaki Faitelson, Varonis Co-Founder and CEO, said, “These findings should be a wake-up call to any organisation that stores information about its customers, employees or business partners, which means almost any business or institution in today’s world. There has been so much focus and investment on protecting the perimeter, but the most fundamental building blocks of security that protect the data inside – access controls and auditing – are often left behind. Unnecessary access combined with a lack of auditing capability adds up to inevitable disaster. Now we see that lack of control and oversight is impacting employee productivity as well, as they struggle to find and get access to data and share it easily and securely with business partners. Varonis is helping thousands of organisations around the world address these challenges in ways that not only reduce risk dramatically but actually improve productivity and efficiency at the same time.”

Links
www.varonis.com/research/why-are-data-breaches-happening

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top