A balancing act: How companies can achieve their data governance goals
When the pandemic first struck, it seemed like businesses were all scrambling to take themselves online. From humble food eateries to massive government agencies, organizations realized that digitalization was now the name of the game.
But while cloud technologies and other digitalization tools might have provided a way forward for businesses amid the global health crisis, they also brought new risks for companies’ data governance and management efforts.
Amid a flurry of rapid IT changes, some businesses were unable to keep up, specifically with their IT security needs. In fact, cyberattacks have become 81% more common since the pandemic started. To make matters worse, attacks are now more severe, with each incident amounting to roughly US$4.2 million in lost business costs.
It might be easy to pin most of the blame on malicious actors, but companies need to note that risks in data governance can come from within too.
Preventing unintentional risks
One hazard is the phenomenon known as “shadow IT.” This refers to when employees use external, unauthorized software, which a company’s IT department has little to no control over. According to Dux Raymond Sy, chief brand officer at SaaS platform AvePoint, examples of these include the use of tools such as WhatsApp or Dropbox to collaborate or carry out day-to-day work.
While these software can be convenient for employees to use, this is precisely their downfall.
“That’s the trade-off. The easier it is, the less likely it is to be secure or have guardrails in place,” Sy explains. “I believe people aren’t malicious, but there are things that non-IT folks don’t think about.”

Dux Raymond Sy, chief brand officer at AvePoint / Photo credit: AvePoint
Although giving up security for convenience in our personal lives might be OK for some, the ramifications are huge if bad things happen in a corporate setting. “That’s why it’s critical for businesses to make it easy for people to do the right thing. It’s like putting up bumpers in a bowling alley,” shares Sy.
Insight Global, a staffing company that was contracted by the Pennsylvania Department of Health to provide Covid-19 contact tracing services, found this out the hard way last year. According to the firm, several employees used Google accounts to share contact tracing records, which led to a data breach once links to those documents were leaked online.
The breach resulted in roughly 70,000 individuals having their personal health information exposed, and Insight Global’s US$23 million contract with the Pennsylvania Department of Health was later nullified.
Another data governance risk that companies encounter occurs when they mismanage their data and run afoul of data protection laws.
“Unfortunately, we don’t get rid of stuff [on our databases] and just keep massive amounts of data,” Sy points out.
According to a study by Seagate, companies hold around 1 petabyte of data across various repositories and locations, with that figure projected to double this year. A separate study by digital security firm Gemalto showed that 46% of executives believe their company doesn’t even know where the sensitive and private portions of their data are stored.
As such, this leaves companies at risk of flouting regulations such as the General Data Protection Regulation (GDPR) in the European Union. For instance, GDPR guidelines state that personal data should not be kept longer than necessary, meaning that unless companies have a legally defensible reason to hold on to former employees’ data, leaving such information in their databases could open them up to heavy regulatory punishment.
That’s why, apart from making sure that employees can properly handle data, companies also need the right policies to constantly be aware of how to manage the information in their possession and whether they should retain it.
Backfiring policies
However, trying to manually implement data governance policies can sometimes exacerbate the very problem companies are trying to solve. According to Sy, some organizations get so strict about data governance that the policies end up working against them.
“On one hand, you can put all these policies and be very strict around data. The problem is, if it requires a ton of effort from employees or stifles and prevents people from getting their work done, they’re going to go around [these procedures] for sure,” he says. This, in turn, could lead to shadow IT problems getting even worse.
Indeed, a survey by the Harvard Business Review found that out of 330 respondents, 85% said that the top three reasons they knowingly circumvent their company’s cybersecurity policies were “to better accomplish tasks for my job,” “to get something I needed,” and “to help others get their work done.”
Instead, a better way for companies to govern their data is by using automated governance solutions. In doing so, companies can be assured that their data is well-protected without feeling the need to go overboard in their data governance policies. Sy calls this the “middle ground of empowered governance.”
Automated tools make it easier for employees to adhere to policies as well, as they would bar the use of shadow IT from the get-go.
“Let’s say you’re in finance and you decide to share an Excel file with somebody outside the company. The [automated] system won’t let you do it because based on governance policies, an Excel file with financial data can’t be shared externally,” Sy explains.
With automation, it also means that adhering to various data protection laws should be a breeze, as companies won’t need to spend time figuring out the many details of different regulations around the world.
AvePoint’s Cloud Governance solution, for instance, automatically archives or deletes Microsoft Teams groups after a certain period of time, depending on the relevant regulations in certain geographies.
“Empowering employees to automatically do what’s best for the organization is what’s key here,” he emphasizes.
Dealing with the deluge of data
With more data being generated every year, Sy notes that moving forward, companies will have to be cognizant of the way information is contextualized.
“Let’s say we’re an organization of 2,000 people in 14 countries. I may come across specific pieces of information or data in one part of the business or from another country that I may take out of context,” he says. “If I don’t have the right context, I may not be able to take advantage of [the data] correctly or I may interpret it in a different way.”
In this regard, Sy believes that advancements in governance technology – such as AI and machine learning-enabled solutions – can act as a positive force in the coming years.
By using these new technologies, companies can gain further insights into their data, helping them “connect the dots” and improve the way they contextualize the information they hold.
AvePoint helps companies secure collaboration data, sustain the connections between people, and ensure business continuity. More than 8 million cloud users today rely on AvePoint’s Confidence platform, an advanced SaaS and data management solution to optimize SaaS operations and secure collaboration.
To find out more about AvePoint, visit its website.
This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
Recommended reads
Indonesian AI startup goes global
Forrest Li on scaling Sea, building smarter bots, and founder grit
An AI assistant that joins sales calls and scores team skills
SGX’s CEO says it doesn’t need a unicorn to win
SMEs want AI too, but not the kind Big Tech is selling
Oatside’s alt-milk rise hits a profitable gear
Alibaba’s financial health in 12 charts
Asia’s telcos bundle AI into mobile plans. Will it pay off?
M-Daq chases bigger clients as revenue falls, losses grow
VC tracker: Accel raises US$3.5b, including US$550m for India
Editing by Nathaniel Fetalvero and Jaclyn Tiu
(And yes, we’re serious about ethics and transparency. More information here.)




