Drawing a Data Inventory
Without knowing what you hold, you cannot know what to protect. IBM’s report measures that gap in money. Scattered data costs more to breach than data sitting in one place. The reason is simple. Nobody knows what sits where, so detection drags on.
A data inventory makes that scatter visible. Half a day to build, useful for years. It needs no software. Just a table.
What Is the Problem?
BU BÖLÜMÜN ÖZETİ
- Nobody knows where the data sits
- Access never gets cleaned up
- Scope cannot be established when something goes wrong
Three scenes recur without an inventory.
Nobody knows where the data sits
Part in the cloud, part on a laptop, part in an old programme. Nobody holds the whole picture. When something needs finding, the question goes to whoever knows. If they are away, the search drags on.
Access never gets cleaned up
A departed employee’s account can stay open for years. Permission for a temporary job outlives the job. Nobody reviews the list, so it grows. Over time who reaches what becomes unknowable.
Scope cannot be established when something goes wrong
After a leak the first question is simple. Which data was affected? Without an inventory it goes unanswered for days. The cost grows as the time stretches. And what to tell customers stays unclear.
Why Does It Happen?
BU BÖLÜMÜN ÖZETİ
- Data accumulates by itself
- The inventory gets treated as technical work
- There is no urgency
Three reasons.
Data accumulates by itself
Nobody sits down and decides to collect data. Records form as work gets done. What piles up without a plan sits without a plan. It never occurs to anyone that it needs organising.
The inventory gets treated as technical work
Yet the real decision is commercial. Which data is critical and which is not? The person who knows is not on the technical team. They are running the work. Given to the wrong person, the job does not get done.
There is no urgency
Until something goes wrong, the missing inventory bothers nobody. By then it is too late. A classic deferral. The cheap preparation waits and the expensive crisis arrives.
How Is It Done?
BU BÖLÜMÜN ÖZETİ
- Step 1: fill in a four-column table
- Step 2: mark the critical ones
- Step 3: review the access
Three steps.
Step 1: fill in a four-column table
One table is enough. Four columns: which data, where it sits, in whose name, who reaches it. Draw the rows from your work. Customer records, contracts, financial records, personnel files, production data. Keep it under twenty rows. A long list never gets opened.
Step 2: mark the critical ones
Ask one question of every row. What happens if this is lost or gets out? If the answer is “work stops” or “we lose customers”, that row is critical. Four headings usually stand out. Customer lists, pricing, contracts, personal data. Protection starts there. The rest waits.
Step 3: review the access
Look at who reaches the critical rows. Two questions suffice. Are departed employees’ accounts closed? Does everyone need access to everything? Closing what is unnecessary is the most effective free measure there is. Half an hour of work. The data terms scan completes it.
How Long, Where to Start?
BU BÖLÜMÜN ÖZETİ
- Half a day to build, refreshed yearly
- The return shows in three places
- First step: write one row today
Short work, long-lived output.
Half a day to build, refreshed yearly
The first inventory takes half a day. With the team it goes faster. Later updates drop to an hour. New systems add rows, so an annual look suffices.
The return shows in three places
First, risk. Knowing what sits where saves days when something goes wrong. Second, decisions. Only an inventory shows what you can share. Third, portability. Which data is locked into which tool becomes visible.
First step: write one row today
Open the table and write your most critical data in the first row. Usually the customer list. Where does it sit? In whose name? Who reaches it? Even that row produces an uncomfortable answer in most firms. The list usually sits in several places at once. Then you can move to the portability test.
The Common Mistake
BU BÖLÜMÜN ÖZETİ
- Going into too much detail
- Delegating it to the technical team
- Building it once and forgetting
Three traps.
Going into too much detail
An inventory listing every file never finishes. Stay at process level. “Customer records” is enough, not individual files. A twenty-row inventory gets used. A two-hundred-row one gets opened by nobody.
Delegating it to the technical team
The technical team knows where the data sits. It does not know which parts are critical. That distinction is commercial, not technical. Draw the inventory with whoever runs the work.
Building it once and forgetting
New tools, new systems, new employees. All of them age the inventory. One left two years does not reflect reality. An hour a year is enough. An out-of-date inventory is no better than none.
Frequently Asked Questions
Sık Sorulan Sorular
Yes, and it is easier. In a five-person business the inventory rarely exceeds ten rows. The benefit is identical. When someone leaves you know which access to close. When something goes wrong you know which data was hit. “We all know it anyway” is a common assumption in small teams. When you actually ask, it turns out everyone knows something different — and the inventory surfaces those differences.
They do, and that is usually the riskiest line. A customer list kept on someone’s own machine sits outside the organisation’s control. Seeing it in the inventory gives you the first chance to fix it. Critical data moves from the personal device to a shared space. The question of what happens if the device is lost comes onto the agenda too, and in most businesses that question has never been asked.
Three jobs, in order. First close the unnecessary access; free and fast. Then check the backups of your critical data. Does one exist? Is it readable? Can it move to another system? Finally look at your tools’ data terms. Together they take about a day and none costs money.
