Sign up for our daily briefing
Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.
Stay on top of the latest market trends
Subscribe to Axios Markets for the latest market trends and economic insights. Sign up for free.
Sports news worthy of your time
Binge on the stats and stories that drive the sports world with Axios Sports. Sign up for free.
Tech news worthy of your time
Get our smart take on technology from the Valley and D.C. with Axios Login. Sign up for free.
Get the inside stories
Get an insider's guide to the new White House with Axios Sneak Peek. Sign up for free.
Catch up on coronavirus stories and special reports, curated by Mike Allen everyday
Catch up on coronavirus stories and special reports, curated by Mike Allen everyday
Want a daily digest of the top Denver news?
Get a daily digest of the most important stories affecting your hometown with Axios Denver
Want a daily digest of the top Des Moines news?
Get a daily digest of the most important stories affecting your hometown with Axios Des Moines
Want a daily digest of the top Twin Cities news?
Get a daily digest of the most important stories affecting your hometown with Axios Twin Cities
Want a daily digest of the top Tampa Bay news?
Get a daily digest of the most important stories affecting your hometown with Axios Tampa Bay
Want a daily digest of the top Charlotte news?
Get a daily digest of the most important stories affecting your hometown with Axios Charlotte
File folders at a Wal Mart in August 2017. Photo: Patrick T. Fallon / Bloomberg via Getty Images.
The security firm Varonis found that 41% of large companies on which it performed data audits gave all employees access to at least a thousand sensitive files.
Why it matters: Giving employees too much access to sensitive files risks problems with insider threats and increases the likelihood hackers are able to access vital information.
If you start from the assumption there's no guaranteed way to prevent hackers from breaking into your network, limiting access to files a no brainer.— John Carlin, a former assistant attorney general focused on national security and current chair of Morrison & Foerster’s global risk and crisis management practice
Other results of the study:
- 58% of companies let all employees access at least 100,000 folders.
- 21% of all folders are accessible by all employees.
- 34% of user accounts in corporate servers are "stale but enabled," meaning that no employee uses the accounts, but the accounts still have access to data.
- 65% of companies have users with passwords that never expire.
Yes, but: Clients seeking data audits are a self selecting group. While 65 percent of companies Varonis audited have at least 500 users with passwords that never expire, only one in 10 businesses have more than 20 employees. You do the math.
- Still, the data is in keeping with what Carlin has seen in both the public and private sector: "By default, too many firms leave a majority of folders open to everyone."