{"id":50550,"date":"2026-09-08T14:47:59","date_gmt":"2026-09-08T12:47:59","guid":{"rendered":"https:\/\/implema.se\/news\/not-all-data-is-an-asset\/"},"modified":"2026-09-08T15:27:38","modified_gmt":"2026-09-08T13:27:38","slug":"not-all-data-is-an-asset","status":"publish","type":"post","link":"https:\/\/implema.se\/en\/insights\/not-all-data-is-an-asset\/","title":{"rendered":"Not All Data Is an Asset"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">For a long time, information security has primarily been associated with technical safeguards against intrusion. But today&#8217;s challenge is broader. Companies need not only to protect their systems, but also to understand what information they have, how sensitive or business-critical it is, and how it can be used.  <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;Many organizations have invested heavily in security, processes, and various technical solutions. But that doesn&#8217;t automatically mean you have control over your information. It&#8217;s only when you start mapping it that you see where the real risks are,&#8221; says Ida Ottosson.  <strong><br\/><\/strong><\/p>\n\n<h2 class=\"wp-block-heading\"><strong>AI Places New Demands on Control<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">The question is not new. Companies have long needed to manage personal data, business-critical information, and access rights. What has changed is the threat landscape, regulations, and the possibilities for using the information.  <\/p>\n\n<p class=\"wp-block-paragraph\">When AI is connected to the organization&#8217;s data, information that was previously difficult to find can suddenly become much more accessible. This creates significant opportunities, but also makes it more important to know what information exists and who should be able to use it. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;AI really puts pressure on this issue. When more people and systems can access information, you first need to have control over it. What information is most important and sensitive? Where is it located? Who has access to it? And should it even still exist?&#8221;     <\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<h2 class=\"wp-block-heading\"><strong>What Information Is Most Important to Protect?<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.imy.se\/privatperson\/dataskydd\/introduktion-till-gdpr\/vad-ar-personuppgifter\/\" target=\"_blank\" rel=\"noopener\">Personal data<\/a> is an obvious area because it is covered by <a href=\"https:\/\/www.imy.se\/verksamhet\/dataskydd\/det-har-galler-enligt-gdpr\/\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>. But the information that is most important to protect does not have to be personal data. <\/p>\n\n<p class=\"wp-block-paragraph\">It can involve pricing and margins, product information, contracts, customer data, business plans, recipes, designs, or other information that is central to the business. What is sensitive and business-critical looks different across different companies. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;A good question is: What would be worst for our specific company if it ended up in the wrong place? When people from different parts of the organization start discussing this, it often turns out that they have quite different views of what is actually sensitive and business-critical,&#8221; says Ida. <\/p>\n\n<p class=\"wp-block-paragraph\">And the information is not only where you first think. Structured data in the business system is <em>one<\/em> part of the picture, but sensitive information can also be found in free-text fields, comments and messages, or in various systems surrounding the business system. <strong><br\/><\/strong><\/p>\n\n<h2 class=\"wp-block-heading\"><strong>Who Has Access to What?<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">Knowing what information needs to be protected is not enough. The company also needs control over who has access to it. <\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/it-ord.computersweden.se\/ord\/behorighet\/\" target=\"_blank\" rel=\"noopener\">Access rights<\/a> are often built up over a long period of time. Employees change roles, the organization evolves, and new systems and functions are added. Then there is a risk that people retain access to information they no longer need in their work.  <\/p>\n\n<p class=\"wp-block-paragraph\">AI makes the question even more important. When it becomes easier to search, find, and compile information, access rights need to work in the new usage as well. A user should not be able to access information through AI that the person should not actually have access to.  <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;Access rights may sound like a technical issue, but fundamentally it&#8217;s about risk. With AI, it becomes even more important to manage them so that people don&#8217;t get access to more information than they actually should have.&#8221; <\/p>\n\n<p class=\"wp-block-paragraph\">It involves quite concrete questions: Who has access to the information today? Does the person still need that access? What happens when someone changes roles? And are access rights removed when they are no longer needed?   <br\/><\/p>\n\n<h2 class=\"wp-block-heading\"><strong>Not All Information Needs to Be Saved<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">Control also involves what information the company chooses to retain. For many years, it has been relatively easy to continue saving data. But information that the organization no longer needs can represent both costs and unnecessary risks.  <\/p>\n\n<p class=\"wp-block-paragraph\">At the same time, old assumptions sometimes persist about how long different types of information must be saved. Before building technical solutions for archiving or anonymization, for example, you therefore need to understand both the organization&#8217;s needs and what requirements actually apply. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;You need to dare to ask the question: Why are we keeping this information? If there is no operational or legal reason to save it, perhaps it shouldn&#8217;t exist either. It&#8217;s about making conscious decisions about your information.&#8221;  <\/p>\n\n<h2 class=\"wp-block-heading\"><strong>Start with the Current State and Prioritize<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">Many companies already know they need to work more on data quality, access rights, information security, or large volumes of historical data. The challenge is rather knowing where to start. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;It can feel overwhelming. You know you need to do something, but where do you start? That&#8217;s why prioritization is so important. What is most important for us? Where are the biggest risks? And what do we actually need to address first?&#8221;     <\/p>\n\n<p class=\"wp-block-paragraph\">The work must begin by identifying and mapping the organization&#8217;s most important information and prioritizing the areas where the need for action is greatest.<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;The point is not to solve everything at once. It&#8217;s to create a shared picture and make the issue manageable. When you know what information is most important, where the risks are, and what needs to be prioritized, it becomes much easier to move forward with concrete actions.&#8221;  <\/p>\n\n<p class=\"wp-block-paragraph\">For Ida, it is also not only about reducing risks. Having control over information creates better conditions for companies that want to use AI more and in larger parts of the organization. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;This is a security issue, but it&#8217;s also a prerequisite for AI. If you know what you have, what is important, and who should have access to it, you have a completely different foundation for using your data in a good way.&#8221; <br\/><br\/><\/p>\n\n<h2 class=\"wp-block-heading\"><strong>FAQ \u2013 Data, Information Security, and AI<\/strong><\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1788781734486\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Why does control over data become more important when companies start using AI?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>AI makes it possible to quickly find, combine, and use large volumes of information. Therefore, companies need to know what data they have, where it is located, and who has the right to access it. Without control over information, it becomes harder to both manage risks and use AI in a secure and effective way.  <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785558849\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What does it mean to have control over your data?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Having control over your data means knowing what information the organization has, where it is located, how it is used, and who has access to it. It also involves understanding what information is business-critical, what is sensitive, and what data is no longer needed. <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785583592\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What type of data do companies need to protect?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>It varies across different organizations. It can involve personal data, customer information, contracts, pricing and margins, product information, business plans, or other information that could harm the business if it ended up in the wrong hands. The important thing is that the organization itself identifies what information is most worth protecting.  <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785631670\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Why are access rights an important issue when companies use AI?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>When AI makes it easier to find and compile information, it becomes even more important that the right people get access to the right data. If access rights are not updated or managed, there is a risk that users will gain access to more information than they need. <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785713052\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Why is it not enough to just have technical security solutions in place?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Technical solutions are important, but they don&#8217;t solve the entire problem. Organizations also need to understand what information exists, how it is used, and which people and systems have access to it. Information security is therefore as much about governance and working methods as it is about technology.  <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785753232\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Do companies really need to save all the data they have?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. More data is not always an asset. Information that is no longer needed can represent unnecessary costs and risks. Therefore, companies need to regularly decide what information should be saved, why it should be saved, and when it can be deleted.   <\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1788785812007\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How do you start the work toward better control over your data?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>A first step is to create a shared picture of the current state: What information exists? Where is it located? What risks exist? And what areas are most important to prioritize? When the organization has that picture, it becomes easier to make decisions about the next steps.    <\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For a long time, information security has primarily been associated with technical safeguards against intrusion. But today&#8217;s challenge is broader. Companies need not only to protect their systems, but also to understand what information they have, how sensitive or business-critical it is, and how it can be used. &#8220;Many organizations have invested heavily in security, [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":50534,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[2721,2720],"tags":[],"class_list":["post-50550","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expert-article","category-insights"],"acf":[],"_links":{"self":[{"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/posts\/50550","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/comments?post=50550"}],"version-history":[{"count":2,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/posts\/50550\/revisions"}],"predecessor-version":[{"id":50552,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/posts\/50550\/revisions\/50552"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/media\/50534"}],"wp:attachment":[{"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/media?parent=50550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/categories?post=50550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/implema.se\/en\/wp-json\/wp\/v2\/tags?post=50550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}