Despite advancements in cybersecurity tools and techniques, data breaches make headlines with troubling regularity. The core reasons behind most breaches remain all too familiar: misconfigured systems, unpatched vulnerabilities, human error… and the massive sprawl of uncategorised and outdated data.
This digital detritus, often labelled ROT (Redundant, Obsolete, and Trivial) information, is an underappreciated liability that threatens to undermine enterprise security from within.
According to 2025 research conducted by Blancco, only 21% of enterprise data is classified at all, meaning that the vast majority of an enterprise’s data exists in a loose state of indefinite storage. Our follow-up research in 2026 showed that 58% of enterprises experienced a data breach in the past year, and nearly a third (32%) admitted that data compromise occurred due to stolen devices or misplaced drives storing sensitive data. This suggests multiple failures – not just of tools, but of policy, process, and mindset.
Real cybersecurity resilience comes from applying best practices consistently, at scale, and in alignment with human behaviour.
Being proactive about your ROT data
ROT data is quietly growing into one of the serious security risks facing enterprises today. When only a fifth of organisational data is classified, it becomes much harder to implement effective data protection or minimisation strategies.
ROT data lurks in forgotten folders, untagged customer files post-campaign, or decades-old reports saved out of habit. ROT data is not just clutter taking up space, but a sprawling attack surface vulnerable to attack or spillage. With more data, there’s more for attackers to compromise. The larger the sprawl, the higher the exposure during a breach.
An important control exists (or should exist) at the point of data creation. CISOs must align policies with how people actually work, embedding classification and erasure logic into everyday workflows. Otherwise, ROT data continues to expand the legal and regulatory exposure that can turn minor oversights into major incidents.
The ghosts in your machines
Our most recent research study uncovered another uncomfortable truth: physical destruction is still one of the most used data destruction processes. 43% of mobile devices, 35% of laptops and desktop PCs, and 44% of data centre assets are physically destroyed to make the data they contain inaccessible, even though the devices are still functional. This approach feels secure, but it’s not scalable, economical, or sustainable – especially with hardware costs increasing. More alarmingly, when devices are not destroyed, they are often repurposed without any form of certified erasure.
Certified data sanitisation, as defined by modern standards like IEEE 2883 and NIST SP 800-88, offers an auditable, environmentally responsible alternative. It ensures that sensitive data is permanently erased, enabling reuse without compromising security. Still, only a fraction of organisations apply these standards consistently.
Strategy over silver bullets
Security leaders often acknowledge that human error is one of the most significant threats to an organisation’s security. Employees use personal devices, store data in unauthorised apps, or overlook basic hygiene like password reuse, compounding enterprise vulnerabilities. The post-pandemic work model, with dispersed workforces and blurred lines between personal and corporate devices, has only exacerbated the challenge.
It’s tempting for CISOs to chase the latest cybersecurity tools or AI-powered threat detection platforms. But without a cohesive data sanitisation strategy, attention on these newer investments may lead to oversight of data security basics. A robust defence begins with improving visibility and knowledge of what data exists, where it resides, and when it should be sanitised.
This is where data classification becomes foundational. A mature data classification system identifies sensitive data, categorises it based on business value and compliance risk, and sets retention timelines that trigger sanitisation processes automatically. Done right, this approach shrinks the data attack surface, supports AI integrity, and ensures compliance.
Security teams should embed this strategy across departments, including legal, compliance, and ESG stakeholders.
Culture change: everyone owns security
Cultivating a security culture around expected employee behaviour is key. This includes security policies which anticipate the paths of least resistance and build in protections that work with human nature, not against it.
Security can no longer be the CISO’s burden alone. Just as phishing simulations are now standard training, employees must be educated on how their everyday actions impact data security. From endpoint hygiene to understanding the “right to be forgotten,” a culture of shared responsibility must be cultivated.
It’s not enough to set policies; they must be scalable, auditable, and understood across all levels. Regular training, cross-functional governance, and investment in certified erasure platforms are all part of the equation.
Say goodbye to data the smart way
As enterprises lean deeper into AI and digital transformation, it’s time to view data disposition not as an afterthought, but as a strategic pillar. Properly retiring data and devices reduces cost, supports sustainability, and closes a backdoor to preventable breaches.
By eliminating ROT data, embracing certified sanitisation, and designing policies that mirror real-world behaviour, security leaders can reduce their risk exposure and boost organisational resilience. The goal isn’t just to protect what you have, it’s to let go of what you no longer need, without fear.
In cybersecurity, what you don’t know can hurt you. And sometimes, the biggest risk isn’t an attacker breaking in to steal, but leaving too much data to steal in the first place.