Marketing goes Big Data: Time bomb for data protection or brave new world?
Marketing seems practically tailor-made for data analysis. But is security being taken into account in the process? An opinion piece by Hans-Günter Börgmann, Managing Director of Iron Mountain Germany.
60 percent of small and medium-sized businesses believe that data analysis is best handled by the marketing department. This was the finding of a recent study¹ conducted by Iron Mountain and PwC. However, another study commissioned by Iron Mountain among marketing directors² paints a different picture: the teams in question are less confident about the success of targeted data analysis.
The following studies paint a similar picture: One Survey According to the Economist Intelligence Unit, one-third of executives believe that the ability to analyze data is the most important skill for marketing professionals in the age of big data. On the other hand, just under half admit that their own teams lack this ability. This is also confirmed by a IBM Study, according to which 82 percent of marketing executives are not sufficiently prepared for the flood of data, and only 59 percent of respondents say they can analyze customer behavior across all channels—for example, for e-commerce or social media. And despite this obvious skills gap, according to IDC Only one in five marketing professionals has received training in data analysis.
Is customer data in safe hands?
In short, there is a high probability that many companies entrust certain teams with important data, even though those teams are ill-equipped or ill-trained to analyze it. According to the Iron Mountain study mentioned at the beginning, marketing teams are increasingly being granted access to sensitive customer data for analysis, but without being held accountable for data security.
The study also found that less than one percent of small and medium-sized companies in Europe believe that responsibility for data security should be assigned to the marketing department. More than half of European companies (48 percent) simply assign responsibility for information risks to the IT security manager.
More Risks Due to Flexibility
Given that marketing departments, in particular, are increasingly adopting flexible work arrangements that allow employees to work from home or while on the go, the issue of data protection and the accountability of marketing staff takes on added significance.
On average, European marketing professionals work from home two to four times a week—more than any other position surveyed in the study. Last year’s Iron Mountain study² also shows that one-third of the marketing employees surveyed take confidential work documents with them to work on them while on the go; one in four throws their documents into the nearest trash can; nearly half send and receive work documents via their personal email accounts, sometimes even over an unsecured Wi-Fi connection (12 percent). However, only one in three employees has access to a secure remote connection or appropriate security guidelines—for example, to handle sensitive data securely while working from home.
All in all, this is a ticking time bomb for data breaches that could go off at any moment.
Good for business intelligence, bad for data protection
Customer information is too valuable to be handled carelessly. The capabilities companies have today for collecting, analyzing, and using information would have been unthinkable just a few years ago: online customer registration, digital communication, social media, and geo- and online tracking now provide companies with unprecedented insights to better understand customers and their needs.
Making such data available company-wide is essential for analyzing it as part of business intelligence and for building long-term customer loyalty in the age of e-commerce and social media. However, employees who handle this data must also know how to protect it. And even more importantly, they must be supported in this effort—for example, through training programs, information campaigns, and the provision of secure mobile work environments (VPN access).
Information management is everyone's business
The days when information management, data protection, and data storage were still handled in the back office by the IT department or the records management team are long gone. Today, this is a business-critical process whose success rests on the shoulders of every employee. That makes it all the more important to close any potential gaps in data security and to make it clear to employees that data breaches can have devastating consequences for the company’s competitiveness, revenue, and reputation. There is only a slight difference between the terms “disclosure” and “leakage”—yet the consequences for data protection could not be more different.
¹ On behalf of Iron Mountain, PwC surveyed senior executives at 600 European and 600 North American companies with 250 to 2,500 employees, as well as 600 companies on both continents with up to 100,000 employees in the following industries: law, finance, pharmaceuticals, insurance, energy, manufacturing, and mechanical engineering. Media release; Abstract; Infographic.
² Opinion Matters for Iron Mountain. The survey was conducted between April 15, 2013, and May 1, 2013. Sample: 5,021 working adults in Germany, the United Kingdom, France, Spain, and the Netherlands. Of these, 1,002 were from Germany.
About Iron Mountain Germany
Iron Mountain is a leading provider of information storage and management services. Its network of high-security archives spans an area of six million square meters, with more than 1,000 facilities in 36 countries, enabling the company to serve customers quickly and reliably. Iron Mountain’s archiving solutions cover both physical documents and digital data, addressing the entire lifecycle—from secure storage to destruction—to help companies store their documents in compliance with regulations, reduce their storage costs, and mitigate risks. Founded in 1951, Iron Mountain stores and secures billions of pieces of corporate information, including business documents, backup tapes, electronic records, and medical data.
