Data Leakage
Stop sensitive data from leaving your org.
What Is Data Leakage?
Most data leaves an organization by accident, not by attack. This exercise walks the ordinary mistakes: autocomplete putting a confidential report in the wrong inbox, a Word file carrying tracked changes and author names into an external share, a file share left open to everyone. It also covers the quieter channels, including personal cloud storage, screen sharing on a call, and uploads to third-party AI tools. You will practice least-privilege sharing, recipient checks, and scrubbing metadata before anything goes out.
What You'll Learn in Data Leakage
- Identify the most common accidental data leakage channels including misdirected emails, unsecured file shares, and exposed document metadata
- Scrub hidden metadata from documents, presentations, and spreadsheets before sharing files outside your organization
- Apply the principle of least privilege when configuring file share permissions and cloud storage access controls
- Classify information by sensitivity level and apply appropriate handling procedures for each classification tier
- Recognize less obvious leakage vectors including screen sharing exposure, AI tool uploads, and personal cloud storage transfers
Data Leakage — Training Steps
-
Introduction
Today, you will learn about data leakage risks and how sensitive information can be accidentally exposed through everyday business activities.
-
Preparing for Client Meeting
Alice is preparing for an important client call about Tolvanne Freight's new software product. She needs to access the client database using her account credentials. As she prepares, Alice writes down her account password on the whiteboard because it's been updated recently and she's not used to her new password yet. The password is now clearly visible on the whiteboard behind her desk, but Alice is not aware of that.
-
Accessing Client Database
Alice needs to access the company's client database to prepare for the presentation. She uses the web browser to open Tolvanne Freight's internal client database portal and signs into her account using the password she wrote on the whiteboard. This database contains sensitive client information that will be referenced during the upcoming meeting.
-
Receiving Meeting Invitation
Alice receives a meeting notification for the client presentation with Brisvane Solutions, a prospective client. She's been preparing all morning and is eager to make a good impression.
-
Joining the Video Call
Alice joins the video meeting with Brisvane Solutions. She positions herself at her desk, not realizing that the whiteboard with her password is clearly visible behind her. The meeting begins and everything seems to go smoothly.
-
Successful Meeting Conclusion
The meeting concludes with what appears to be positive results. One of the participants, Bob Stevens, asks unusually specific questions about how client data is stored. Alice finds the questions slightly unusual but confirms they have a secure database. Overall, she believes the meeting went well.
-
Bob's Corporate Espionage
What Alice doesn't know is that Bob Stevens was never from Brisvane Solutions: he's a corporate spy working for CompetitorCorp. During the video call, Bob noticed Alice's password on the whiteboard behind her. He now uses it to access Tolvanne Freight's client database and downloads everything.
-
Devastating Contract Loss
The next day, Alice receives a shocking email from Brisvane Solutions informing her that they have awarded their contract to CompetitorCorp instead. The competitor somehow offered terms and pricing that exactly matched Brisvane's specific requirements.
-
Security Breach Discovery
Later that day, Alice receives an urgent email from Tolvanne Freight's CEO and IT security team. They have discovered during a routine security audit that the company's client database has been compromised.
-
Devastating Realization
Alice suddenly turns around and looks at her whiteboard, realizing with horror that she caused the security breach. Her password was visible behind her during the entire video call, allowing Bob to access the client database using her credentials.
Security Framework Coverage
CWE
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CIS Controls
- CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind