Not every data breach starts with a shadowy hacker and an external attack. Sometimes it’s not malicious third parties that overwhelm network defenders. It’s regular employees failing to follow established information governance guidelines that gets organisations into trouble. Or data-handling rules that break down on contact with reality.
In these situations, even the most sophisticated cybersecurity technology in the world might not be enough to prevent a damaging data leak or compliance breach. It’s something that UK Government Investments (UKGI) recently found out to its cost after leaking potentially sensitive data online for close to two days.
This is not the first and won’t be the last cautionary tale of its kind. The right approach to building business resilience is to balance security technology with information governance.
What Happened at UKGI?
The incident at UKGI, which manages the state’s commercial interests in companies, comes with a hint of irony attached, given that it describes itself as an expert in corporate governance. The Treasury agency said in its annual report in August that a 2025-26 data breach involved the accidental leaking of an internal file. It included “high-level management information and the names and work email addresses of 51 government officials”, which were made publicly accessible for around 40 hours. The culprit was “a member of staff who did not follow established information security policies”.
UKGI reported the incident to the Information Commissioner’s Office (ICO) and undertook an external review which provided recommendations on ways to strengthen its incident preparedness and controls – the “overwhelming majority of which” it has or is going to implement.
Governance Challenges Are Everywhere
Although this incident passed without any major repercussions, similar cases have had a much bigger impact. A few spring to mind:
The Post Office was reprimanded by the ICO in 2025 after publishing an unredacted legal document on its website about the ongoing Horizon IT scandal. It contained the name, home address and postmaster status of over 500 people involved in litigation with the Post Office, with the information remaining public accessible for almost two months. The Post Office narrowly escaped a £1m fine.
Hammersmith & Fulham council was also reprimanded by the ICO last year after accidentally leaking the details of 6,528 people, including 2,342 children, in response to an FoI request. The Excel spreadsheet in question featured 35 hidden workbooks containing the information, which included details on asylum-seeking children. The personal information was left exposed for nearly two years.
The Police Service of Northern Ireland (PSNI) put countless officers and staff members at risk when it leaked their personal information including names, ranks and roles in a spreadsheet-based response to a FoI request. Although the details were only publicly accessible for a few hours, the information is thought to have been obtained by dissident republicans. The PSNI avoided a £5.6m fine only because of a post-Covid public sector policy on financial penalties adopted by the ICO.
What Does Best Practice Look Like?
Such incidents illustrate a growing problem: that investment in technical security controls has in many organisations dramatically outpaced funding for information governance, according to Muhammad Yahya Patel, vCISO EMEA at Huntress.
“Information governance, knowing what data you hold, where it lives, who can access it, how it should be handled, and whether those rules are actually being followed in practice is unglamorous work,” he tells IO (formerly ISMS.online). “It’s the bit that gets forgotten in most conversations. It doesn’t generate exciting board presentations. But it’s the control layer that sits between a policy document and the moment a staff member makes a decision about a sensitive file at 4pm on a Friday.”
Patel argues that taking a proportional approach to risk management means accepting that not every risk demands a technical solution. “Sometimes the right control is a clearer process, better training delivered at the moment of relevant risk rather than annually, or a simple peer review step before sensitive information is published or shared,” he continued.
Jake Taylor, head of public sector at Filigran, agrees, arguing that organisations can’t protect what they don’t know they have.
“As government departments and organisations get restructured and re-organised, the UK threat landscape will widen dramatically, leaving gaps for malicious actors to exploit. Data governance here becomes as important if not more important than technical defences,” he tells IO.
“Leaders must understand that security cannot exist without control, balance and clear visibility.”
Taylor encourages teams to audit activity regularly, logging and reviewing who accesses sensitive folders to catch unusual behaviour early. And he urges organisations to minimise user friction.
“Ensure security rules do not stop employees from doing their jobs, or they will find dangerous workarounds,” he continues. “Also, try to bridge the silos. Force your legal, IT, compliance, and security teams to work together under one unified data strategy.”
Introducing a Continuous Monitoring Approach
Experts IO spoke to agree that a continuous approach to governance and compliance should be the preferred option. It means collecting evidence and monitoring for compliance drift on an ongoing basis to spot problems and remediate drift early, rather than waiting for audit time to surface historic problems that have snowballed.
“Point-in-time checks like annual audits, and penetration tests only show your data status, and vulnerabilities for a single day, creating a false sense of security,” argues Taylor. “Continuous monitoring ensures your data map, access rules, and retention policies remain accurate every single second.”
Huntress’s Patel adds that continuous monitoring is already well established in cybersecurity, and information governance needs to follow suit.
“Automated monitoring that flags when sensitive documents are made publicly accessible, a risk flag raised when sensitive data is being shared – when access permissions change unexpectedly, or when data moves outside authorised pathways – turns a 40-hour exposure into a four minute one,” he says.
“The technology to do this exists and is mature. The organisational will to implement it as rigorously as technical security controls is what’s typically missing.”
The good and bad news is that AI will make this task both easier and more challenging. On the one hand, shadow AI is introducing new risks. IBM claims that 43% of breach incidents last year involved unsanctioned use of AI. However, AI tools could make governance more streamlined through automated classification of sensitive documents, continuous monitoring of data flows, anomaly detection, and policy enforcement at machine speed, Huntress’s Patel explains.
“The organisations that will get the most value from AI in information governance are those that have invested in understanding their data estate well enough to know what needs protecting and why,” he concludes.
“AI amplifies good information governance practice. It also amplifies the consequences of bad practice, and that’s the part most leaders haven’t fully reckoned with yet.”
Expand Your Knowledge
Blog: Closing the Resilience Gap: Where the Government Says UK PLC Is Still Failing
Podcast: Phishing for Trouble S2 E10: Built to Last: How Compliance Enables Business Resilience
Blog: The NVD Pullback Should Prompt A Resilience Approach To Vulnerability Management







