CIO Brief: You Can't Protect Data You Haven't Found
Retrospective: this article looks back at events from August 2017, written in 2026 with the benefit of hindsight.
The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and still true: you cannot protect data you do not know you have.
Why data discovery matters to leadership
Most organizations underestimate how much sensitive data they hold and where. Copies of customer databases end up in test environments; exports sit in storage folders for years; departing projects leave data behind. Every unknown copy is a breach waiting to happen and a liability under privacy law.
The business impact
- Breach cost rises with the amount and sensitivity of data exposed.
- Regulatory obligations require you to know where personal data lives and to honor deletion requests.
- Storage costs grow with data you no longer need.
Questions to ask your team
- Do we have an inventory of where customer and employee data is stored in the cloud?
- Who owns each major data store?
- How much data do we keep that we no longer need?
- Would we know if sensitive data appeared somewhere it shouldn't?
What good looks like
Automated discovery across cloud storage, named data owners, retention rules that delete what is no longer needed, and alerts when sensitive data shows up in unexpected places.
The decision
Fund a one-time data discovery exercise across your main cloud storage, then decide what to protect, move or delete. Deleting unneeded data is one of the few security investments that also reduces cost.
- Amazon Macie Launches (Aug 2017): Machine Learning for Finding Sensitive Data in S3 Platform Changes
- How to Use Amazon Macie to Discover PII in Your S3 Buckets How-To & Hardening
- Amazon Macie Rollout Checklist: Cost Controls and Finding Triage How-To & Hardening