File folders at a Wal Mart in August 2017. Photo: Patrick T. Fallon / Bloomberg via Getty Images.

The security firm Varonis found that 41% of large companies on which it performed data audits gave all employees access to at least a thousand sensitive files.

Why it matters: Giving employees too much access to sensitive files risks problems with insider threats and increases the likelihood hackers are able to access vital information.

If you start from the assumption there's no guaranteed way to prevent hackers from breaking into your network, limiting access to files a no brainer.
— John Carlin, a former assistant attorney general focused on national security and current chair of Morrison & Foerster’s global risk and crisis management practice

Other results of the study:

  • 58% of companies let all employees access at least 100,000 folders.
  • 21% of all folders are accessible by all employees.
  • 34% of user accounts in corporate servers are "stale but enabled," meaning that no employee uses the accounts, but the accounts still have access to data.
  • 65% of companies have users with passwords that never expire.

Yes, but: Clients seeking data audits are a self selecting group. While 65 percent of companies Varonis audited have at least 500 users with passwords that never expire, only one in 10 businesses have more than 20 employees. You do the math.

  • Still, the data is in keeping with what Carlin has seen in both the public and private sector: "By default, too many firms leave a majority of folders open to everyone."

Go deeper

Updated 54 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 7 p.m. ET: 12,859,834 — Total deaths: 567,123 — Total recoveries — 7,062,085Map.
  2. U.S.: Total confirmed cases as of 7 p.m. ET: 3,297,501— Total deaths: 135,155 — Total recoveries: 1,006,326 — Total tested: 40,282,176Map.
  3. States: Florida smashes single-day record for new coronavirus cases with over 15,000 — NYC reports zero coronavirus deaths for first time since pandemic hit.
  4. Public health: Ex-FDA chief projects "apex" of South's coronavirus curve in 2-3 weeks — Coronavirus testing czar: Lockdowns in hotspots "should be on the table"
  5. Education: Betsy DeVos says schools that don't reopen shouldn't get federal funds — Pelosi accuses Trump of "messing with the health of our children."

Scoop: How the White House is trying to trap leakers

Illustration: Sarah Grillo/Axios

President Trump's chief of staff, Mark Meadows, has told several White House staffers he's fed specific nuggets of information to suspected leakers to see if they pass them on to reporters — a trap that would confirm his suspicions. "Meadows told me he was doing that," said one former White House official. "I don't know if it ever worked."

Why it matters: This hunt for leakers has put some White House staffers on edge, with multiple officials telling Axios that Meadows has been unusually vocal about his tactics. So far, he's caught only one person, for a minor leak.

11 GOP congressional nominees support QAnon conspiracy

Lauren Boebert posing in her restaurant in Rifle, Colorado, on April 24. Photo: Emily Kask/AFP

At least 11 Republican congressional nominees have publicly supported or defended the QAnon conspiracy theory movement or some of its tenets — and more aligned with the movement may still find a way onto ballots this year.

Why it matters: Their progress shows how a fringe online forum built on unsubstantiated claims and flagged as a threat by the FBI is seeking a foothold in the U.S. political mainstream.