Ida Ottosson beskuren

Not All Data Is an Asset

Cyber threats are becoming more sophisticated while the volume of information in corporate systems continues to grow. And as AI makes it possible to find, combine, and use data in entirely new ways, the requirements for how information is managed are increasing. According to Ida Ottosson, project manager for Business Transformation at Implema, the ability to know what information the organization has—and how it is used—is therefore becoming increasingly important for both information security and the ability to leverage AI. What information do we have, where is it located, and most importantly, who actually has access to it?

Sammanfattning

  • AI makes control over data more important than ever. As AI gains access to more of the organization’s information, the requirements increase for knowing what data exists, where it is located, and who has access to it.
  • Not all data is an asset. Information that is sensitive, outdated, or lacks a clear purpose can represent both risks and costs.
  • Security is not just about technology. Companies also need control over information classification, data lifecycle, and access rights.
  • Proper access rights become critical in an AI-driven world. As it becomes easier to find and combine information, organizations must ensure that the right people get access to the right data—and nothing more.
  • Start by creating a shared picture. Identifying which information is business-critical and where the risks lie is the first step toward better information governance.
Porträtt av Ida Ottosson

Jag hjälper er!

Ida Ottosson

Project Manager, Business Transformation

Kontakta Ida

Dela med dig:

For a long time, information security has primarily been associated with technical safeguards against intrusion. But today’s challenge is broader. Companies need not only to protect their systems, but also to understand what information they have, how sensitive or business-critical it is, and how it can be used.

“Many organizations have invested heavily in security, processes, and various technical solutions. But that doesn’t automatically mean you have control over your information. It’s only when you start mapping it that you see where the real risks are,” says Ida Ottosson.

AI Places New Demands on Control

The question is not new. Companies have long needed to manage personal data, business-critical information, and access rights. What has changed is the threat landscape, regulations, and the possibilities for using the information.

When AI is connected to the organization’s data, information that was previously difficult to find can suddenly become much more accessible. This creates significant opportunities, but also makes it more important to know what information exists and who should be able to use it.

“AI really puts pressure on this issue. When more people and systems can access information, you first need to have control over it. What information is most important and sensitive? Where is it located? Who has access to it? And should it even still exist?”

What Information Is Most Important to Protect?

Personal data is an obvious area because it is covered by GDPR. But the information that is most important to protect does not have to be personal data.

It can involve pricing and margins, product information, contracts, customer data, business plans, recipes, designs, or other information that is central to the business. What is sensitive and business-critical looks different across different companies.

“A good question is: What would be worst for our specific company if it ended up in the wrong place? When people from different parts of the organization start discussing this, it often turns out that they have quite different views of what is actually sensitive and business-critical,” says Ida.

And the information is not only where you first think. Structured data in the business system is one part of the picture, but sensitive information can also be found in free-text fields, comments and messages, or in various systems surrounding the business system.

Who Has Access to What?

Knowing what information needs to be protected is not enough. The company also needs control over who has access to it.

Access rights are often built up over a long period of time. Employees change roles, the organization evolves, and new systems and functions are added. Then there is a risk that people retain access to information they no longer need in their work.

AI makes the question even more important. When it becomes easier to search, find, and compile information, access rights need to work in the new usage as well. A user should not be able to access information through AI that the person should not actually have access to.

“Access rights may sound like a technical issue, but fundamentally it’s about risk. With AI, it becomes even more important to manage them so that people don’t get access to more information than they actually should have.”

It involves quite concrete questions: Who has access to the information today? Does the person still need that access? What happens when someone changes roles? And are access rights removed when they are no longer needed?

Not All Information Needs to Be Saved

Control also involves what information the company chooses to retain. For many years, it has been relatively easy to continue saving data. But information that the organization no longer needs can represent both costs and unnecessary risks.

At the same time, old assumptions sometimes persist about how long different types of information must be saved. Before building technical solutions for archiving or anonymization, for example, you therefore need to understand both the organization’s needs and what requirements actually apply.

“You need to dare to ask the question: Why are we keeping this information? If there is no operational or legal reason to save it, perhaps it shouldn’t exist either. It’s about making conscious decisions about your information.”

Start with the Current State and Prioritize

Many companies already know they need to work more on data quality, access rights, information security, or large volumes of historical data. The challenge is rather knowing where to start.

“It can feel overwhelming. You know you need to do something, but where do you start? That’s why prioritization is so important. What is most important for us? Where are the biggest risks? And what do we actually need to address first?”

The work must begin by identifying and mapping the organization’s most important information and prioritizing the areas where the need for action is greatest.

“The point is not to solve everything at once. It’s to create a shared picture and make the issue manageable. When you know what information is most important, where the risks are, and what needs to be prioritized, it becomes much easier to move forward with concrete actions.”

For Ida, it is also not only about reducing risks. Having control over information creates better conditions for companies that want to use AI more and in larger parts of the organization.

“This is a security issue, but it’s also a prerequisite for AI. If you know what you have, what is important, and who should have access to it, you have a completely different foundation for using your data in a good way.”

FAQ – Data, Information Security, and AI

Why does control over data become more important when companies start using AI?

AI makes it possible to quickly find, combine, and use large volumes of information. Therefore, companies need to know what data they have, where it is located, and who has the right to access it. Without control over information, it becomes harder to both manage risks and use AI in a secure and effective way.

What does it mean to have control over your data?

Having control over your data means knowing what information the organization has, where it is located, how it is used, and who has access to it. It also involves understanding what information is business-critical, what is sensitive, and what data is no longer needed.

What type of data do companies need to protect?

It varies across different organizations. It can involve personal data, customer information, contracts, pricing and margins, product information, business plans, or other information that could harm the business if it ended up in the wrong hands. The important thing is that the organization itself identifies what information is most worth protecting.

Why are access rights an important issue when companies use AI?

When AI makes it easier to find and compile information, it becomes even more important that the right people get access to the right data. If access rights are not updated or managed, there is a risk that users will gain access to more information than they need.

Why is it not enough to just have technical security solutions in place?

Technical solutions are important, but they don’t solve the entire problem. Organizations also need to understand what information exists, how it is used, and which people and systems have access to it. Information security is therefore as much about governance and working methods as it is about technology.

Do companies really need to save all the data they have?

No. More data is not always an asset. Information that is no longer needed can represent unnecessary costs and risks. Therefore, companies need to regularly decide what information should be saved, why it should be saved, and when it can be deleted.

How do you start the work toward better control over your data?

A first step is to create a shared picture of the current state: What information exists? Where is it located? What risks exist? And what areas are most important to prioritize? When the organization has that picture, it becomes easier to make decisions about the next steps.

Ida Ottosson

Ida Ottosson

Project Manager, Business Transformation

Whether you have a question, want to learn more about our solutions, or are simply curious how we can support your business – we’d love to hear from you.

Contact us directly using the form below!

Relaterat