Is BYOD still a thing in 2026?
The practice is universal and the term is not. Personal devices reach work systems almost everywhere, including at organisations whose written policy forbids it. What disappeared was the idea that this needed a dedicated policy category rather than being the ordinary condition that access control has to assume.
What replaced BYOD as the unmanaged thing staff bring to work?
Tools they signed up for themselves, and increasingly AI services. The pattern is identical: something genuinely useful arrives faster than the approval process can consider it, prohibition produces concealment rather than compliance, and the workable answer is to define what the tool may touch instead of whether it may exist.
How costly are breaches involving unsanctioned AI tools?
Published figures vary considerably by methodology. One widely cited set puts incidents involving shadow AI at around 20% of breaches, adding roughly $670,000 to the average cost; another reports the share climbing to 43% with an average near $5.39m. The direction is consistent across sources even where the levels are not.
What is dark data?
Data an organisation holds but does not classify, monitor or use. Analyst estimates put it at more than half of enterprise data, and unmonitored stores of it have been associated with roughly $900,000 of additional cost per breach. Most of it accumulated one copy at a time for questions somebody asked once.
Does deleting data actually reduce risk?
It is the only control that removes the thing being protected instead of wrapping a layer around it. Breach cost scales with the number of records exposed, so halving what you hold halves the largest term in that calculation, and it costs nothing to run afterwards.
How long should we keep customer data?
As long as a named obligation requires, and no longer, with the obligation written next to the period. The common failure is not a period that is too long but a period nobody can attribute to anything — seven years is what people reach for when there is no number, and it is rarely the number any rule actually specifies.
Are logs an exception to data minimisation?
Largely, yes, and they are usually the one category kept too briefly rather than too long. With a mean of roughly six months between compromise and discovery, retaining authentication and administrative logs for a few months guarantees the investigation begins after the evidence has rotated away.
Why do old backups and snapshots matter?
They hold the records as they were, including fields since removed from production and accounts since closed. A deletion request honoured in the live system and not in a 2019 snapshot has not been honoured, and the snapshot is usually outside whatever enforces retention elsewhere.
Should we ban staff from using AI tools?
A prohibition that people need to break in order to do their work produces concealment, which removes the visibility that made the prohibition enforceable. The BYOD decade tested this thoroughly. Defining which data may go to which category of service is harder to write and considerably more likely to hold.
How do you find data stores nobody remembers creating?
Start with what pays for storage rather than with what stores data. Cloud billing, expense claims and supplier invoices name systems that no inventory contains, because the bill had to be paid by someone. It is a less elegant method than discovery tooling and it finds a different set.
Who should own data retention?
Whoever can say no to keeping something. In practice retention fails when it is owned by a team that can write a policy but cannot delete anything, which produces an accurate document describing a state of affairs that has never existed.
What is the cheapest improvement available here?
Writing down, for each significant data store, why it exists and what would have to be true to delete it. The exercise is unglamorous and it routinely finds stores nobody can justify, which are the ones that can go immediately at no cost and no risk.