BUSHEY

Data Protection Is Not a Technology Project. It Is a Business Change Programme. 

Data Protection Is Not a Technology Project. It Is a Business Change Programme. 

Explore answers, insights, and guidance—your go-to hub for everything you need to know

Data Protection Is Not a Technology Project. It Is a Business Change Programme. 

The Bushey team recently completed the second stage of a multi-year Data Protection Programme for a large APAC financial services organisation. Having been involved since the original Proof of Concept project, it has reinforced something I have observed repeatedly throughout my career. 

The conversation around cybersecurity is changing. 

For years, organisations focused on protecting their networks, servers and applications. Investment was directed towards firewalls, endpoint security, monitoring platforms and threat detection. While these capabilities remain essential, many organisations are now turning their attention towards something that has been quietly growing inside their business for years. 

Their data. 

The challenge is that data protection is often viewed as a technology project when, in reality, it is a business challenge supported by technology. 

The business owns the data. The business creates it, uses it, shares it and relies on it every day. Yet many business teams do not fully understand the technology required to protect it. At the same time, executive teams are under pressure to prioritise investments that drive growth, improve customer experience or generate revenue. 

When viewed through that lens, Data Protection can be a difficult business case to justify. 

Until something goes wrong. 

What many organisations fail to recognise is that the greatest threat to sensitive information often comes from inside the organisation rather than from a sophisticated cyberattack. Employees have access to customer data, intellectual property, commercial information and confidential business records every day. 

A loss of sensitive information can have serious consequences. 

It can damage customer trust, impact future business opportunities, attract regulatory attention and create significant disruption while investigations take place. 

That assumes the organisation is even aware the data has been lost. 

Without the appropriate controls, many organisations would never know information had been copied, downloaded or removed. 

One recent Data Protection engagement highlighted this perfectly. 

During the programme, Data Loss Prevention controls identified a departing sales employee attempting to copy the organisation’s customer database onto a USB device. Because the appropriate controls and monitoring capabilities were in place, the activity was detected, investigated and the device recovered before the information left the organisation. 

Without those controls, the organisation would likely never have known the data had been taken. 

Months later, they may simply have wondered why customers were moving to a competitor. 

Stories like this illustrate why Data Protection has become such an important business capability. 

Most organisations know where their critical systems are located. 

Far fewer know where all of their sensitive information resides. 

That challenge sits at the heart of every Data Protection programme. 

In the financial services programme we recently supported, the organisation had accumulated approximately 200 million unstructured files spread across seven countries. When the programme began, estimates suggested the volume would be measured in tens of millions of files. The reality was significantly larger. 

What initially appeared to be a straightforward classification exercise quickly revealed a much more complex problem. 

Governance was unclear. 

Data ownership was inconsistent. 

Solution design was incomplete. 

Delivery arrangements were not aligned to programme objectives. 

The technology itself was not the biggest challenge. 

The real challenge was determining how the organisation wanted to manage and protect its information. 

That is a very different conversation. 

Many organisations begin their Data Protection journey by purchasing a technology platform. They invest in Data Loss Prevention solutions, information protection tools or file classification products believing the technology will solve the problem. 

Unfortunately, it rarely works that way. 

I remember working with another organisation that purchased a classification tool and immediately began applying restrictions to emails and documents. Within weeks, business users found themselves unable to send information they needed to perform their daily roles. 

Frustration grew rapidly. 

The business pushed back. 

The controls were disabled. 

When Bushey arrived, there was still a considerable divide between the business and technology teams. 

The technology was functioning exactly as designed. 

The organisation simply had not agreed how information should be classified and protected before switching it on. 

That experience highlights the questions every organisation eventually faces. 

Who owns the data? 

Which files contain sensitive information? 

What information should be retained? 

What information should be deleted? 

What labels should be applied? 

Who makes those decisions? 

These questions sound simple until they are asked across multiple business units, countries and regulatory environments. 

Most organisations have information that nobody truly owns. Employees leave. Teams restructure. Departments merge. Documents remain. 

Data continues to accumulate. 

Over time, enormous repositories develop containing information of varying value, importance and sensitivity. 

The challenge is that attackers do not distinguish between well-governed data and poorly governed data. 

Neither do regulators. 

When information is exposed, every file matters. 

One of the biggest obstacles we encounter is achieving agreement on what constitutes sensitive information. 

Ask ten departments and you will often receive ten different answers. 

Legal teams may classify almost everything as confidential. 

Marketing teams may classify very little. 

Neither approach is wrong from their perspective, but both create challenges. 

Over-classification frustrates users and slows productivity. 

Under-classification increases exposure and risk. 

Finding the balance requires leadership, governance and collaboration across the organisation. 

Scale creates another challenge. 

When organisations begin discovering the true volume of information they hold, the numbers can be staggering. 

Millions of files. 

Hundreds of thousands of folders. 

Decades of records. 

At that point, manual effort becomes impossible. 

Automation becomes essential, but automation is only effective when clear rules and governance already exist. 

Technology can apply labels. 

Technology can enforce controls. 

Technology cannot determine the business value or intent behind a document. 

That responsibility remains with the organisation. 

Perhaps the most overlooked aspect of Data Protection is the human element. 

Employees create, share and access information every day. If they do not understand why controls are being introduced, resistance is inevitable. 

People worry they will be slowed down. 

They worry about additional administration. 

They worry about making mistakes. 

Successful programmes acknowledge these concerns early. 

They invest in communication, education and change management alongside the technology implementation. 

In our financial services engagement, change management became one of the most important components of the programme. Once users understood the purpose behind the initiative, conversations shifted from compliance obligations towards protecting customers, intellectual property and business value. 

That shift changed everything. 

Data Protection is becoming a foundational business capability. 

As organisations embrace AI, expand their cloud footprint and increase digital collaboration, the volume of information continues to grow. Every new platform generates more data. Every new business initiative creates additional content. 

Without effective governance, the challenge only becomes larger over time. 

The organisations that succeed will not necessarily be those with the most technology. 

They will be the organisations with the clearest governance, the strongest executive sponsorship and the most practical approach to managing information. 

The lesson from our customer story is not simply that a stalled programme was successfully recovered. 

It is that meaningful Data Protection requires business leaders, technology teams, governance professionals and service providers to work towards a common objective. 

Data Protection is not just about protecting files. 

It is about protecting customers, protecting intellectual property and protecting the future value of the business. 

And that starts with understanding the data you already have. 

Data Protection is no longer just a cybersecurity issue. As organisations adopt AI, cloud services and digital collaboration, understanding and protecting sensitive information has become a critical business capability that requires strong governance, clear ownership and active engagement from the business, not just technology teams. 

The most successful Data Protection programmes recognise that technology is only part of the solution. Protecting customers, intellectual property and business value requires organisations to understand what data they have, where it resides, who owns it and how it should be managed before controls and tools can deliver meaningful outcomes. 

Bushey provides independent governance and assurance for technology transformation. Through structured oversight and disciplined programme control, we ensure outcomes are achieved with clarity, accountability, and confidence, supported by specialist capability across change, project leadership, Artificial Intelligence, Cybersecurity, Data Centre, and M&A capabilities. Our focus is on aligning transformation to business objectives, applying proven frameworks, and enabling secure, resilient, and future-ready environments. 

Comments are closed