Back to the blog

Information Governance Risk: Breach vs Access Loss

Sep 7, 2026

Information Governance Risk: Breach vs Access Loss

This post accompanies the What Counts episode "Information Governance Risk: Breach vs Access Loss" with hosts Lee Karas and Maura Dunn. Listen to the episode or play it on our podcast page.

Rethinking Information Governance Risk

When executive leadership hears "information governance risk," the conversation almost always turns directly to data breaches, personally identifiable information, and financial records. While exfiltration of sensitive data carries significant regulatory and financial penalties, it is only one component of information risk. For many organizations, the risk of losing access to operational records is far more common and immediate.

Breach versus Inaccessibility

Inaccessibility directly damages operations and revenue. In the episode, Lee Karas and Maura Dunn examine several real-world examples of access loss:

  • Cloud provider failure: When a cloud hosting provider failed, New England PBS stations lost operational access to 70 years of program archives.
  • Ransomware lockouts: Modern ransomware often focuses on locking organizations out of their operational files rather than exfiltrating data, halting operations instantly.
  • Single points of failure: Relying on a single unbacked-up hard drive or a single physical box of paper creates acute operational vulnerability.

Scaling Risk and Organization Age

Information governance risk is not one-size-fits-all. A 1-person mechanic shop may only need to manage 3 critical record types: employment files, hazardous materials disposal records, and financial records supporting tax filings. Conversely, a charter school must manage complex requirements across accreditation, curriculum, teacher credentials, facilities management, and student transcripts that alumni may request 50 years later.

Organizational age acts as its own risk multiplier. Older companies accumulate both volume and exposure risks, such as legacy underwriting files subject to outdated regulatory standards or historical environmental records created when disposal practices differed significantly from modern law. Keeping everything indefinitely compounds exposure while driving up storage costs.

What to Do Next

A risk assessment should never be treated as an academic exercise. It serves as the functional input for core governance actions. To translate risk analysis into practical program elements, take the following steps:

  • Build clear retention schedules: Define specific retention periods based on actual legal obligations, operational necessity, and business risk rather than default indefinite retention.
  • Perform vendor due diligence: Evaluate cloud and software vendors with fiduciary-level oversight. Ensure clear service level agreements, export controls, and disaster recovery strategies are in place.
  • Select compliant repositories: Align storage locations with the risk profile of the records. High-risk or long-term operational records require robust access controls and migration strategies.
  • Establish governance before deploying AI: Avoid putting artificial intelligence systems on top of unmanaged, unverified repositories. Defensible governance must precede automated processing.

To evaluate your organization's risk profile and map out actionable retention policies, explore our IG Navigator tool and download reference materials from our template library.