Authors
Organizations spend heavily on tools designed to protect information. Worldwide spending on information security is expected to reach approximately $244 billion in 2026. But there’s a more basic question that can be surprisingly difficult to answer: What information do we actually have – and where is it? That question sits at the intersection of information governance and cybersecurity, and it is the focus of this series for Cybersecurity Awareness Month.
Visibility comes before protection
A robust cybersecurity program requires visibility. To make informed decisions about protecting information, an organization first needs to understand what information exists, where it resides, what it contains, and who is responsible for it.
That sounds straightforward. In practice, it rarely is. Information is no longer confined to traditional records repositories. It lives across shared drives, email, collaboration platforms, cloud applications, employee devices, databases, legacy systems, third-party platforms, backups, and other repositories.
And information has a tendency to multiply. A record that begins in a business application may be exported to a spreadsheet, attached to an email, downloaded to a laptop, uploaded to a collaboration platform, and copied to a shared drive.
Unknown data = Unknown risk
Gaps in visibility create risk. Forgotten repositories, abandoned systems, and uncontrolled copies may contain personal information, confidential business information, regulated records, credentials, or other sensitive material.
Even strong security teams face a fundamental limitation: you cannot deliberately protect information or repositories you do not know exist.
Information governance to the rescue
This is where information governance becomes part of the cybersecurity toolkit. Information governance provides the framework, rules, and processes for understanding and managing information throughout its life cycle, from creation and use through retention and eventual disposition. Familiar information governance tools – including policies, records retention schedules, records inventories, and data maps – can also give cybersecurity teams valuable visibility into the information environment.
- Policies set the rules of the road: Information governance, records management, and data retention policies establish the organization's expectations for managing information. Policies can establish where information should be stored, appropriate handling, responsibilities, and expectations around retention and disposition for both records and non-records.
- Record retention schedules answer “what” and “how long”: A records retention schedule establishes how long categories of records should be maintained based on legal, regulatory, operational/business requirements, and when records may be eligible for disposition. Understanding what information the organization has and for how long can help teams prioritize security controls and response.
- Record inventories tell you where records live: Record inventories bring the retention schedule into the organization's actual information environment. Inventories can identify where records reside, information types, owners, systems of record, sensitivity, applicable retention requirements, and potentially third-party dependencies. From a cybersecurity perspective, that can turn an abstract retention schedule into something much more actionable: a map of where important organizational information actually lives.
- Data maps follow the information: Records inventories and data maps overlap, but they answer somewhat different questions. While a records inventory generally focuses on records and repositories, a data map typically takes a broader view of data and its movement through the organization. Depending on its purpose, particularly in privacy and security programs, a data map may identify what data is collected, its sources, the systems that process it, how it moves between systems, who receives it, where it is stored, and when it leaves the organization or is transferred to third parties.
Know it before you protect it
Before asking, “Is our information secure?” ask three simpler questions: Do we know what we have, where it is, and why we're keeping it? Information governance programs give you the tools to answer those questions, as we will explore this month. None of these information governance tools replaces firewalls, encryption, multifactor authentication, endpoint protection, or other technical security controls. Instead, information governance tools help the organization understand what those cybersecurity controls are protecting.
Authors
/Passle/5db069e28cb62309f866c3ee/MediaLibrary/Images/2026-03-16-17-46-11-348-69b841e33f16261f919a33c9.jpg)