ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The dangers of ROT

Manuel Sanchez at iManage argues that hoarding ROT-ting data is a cyber-security nightmare waiting to happen

 

Organisations are drowning in virtual mountains of redundant, obsolete, and trivial (ROT) data. Stored across numerous digital systems, this data serves no business purpose while dramatically increasing the potential attack surface for bad actors. The migration to cloud platforms has added a new wrinkle by layering escalating storage costs on top of this ever-deepening potential security risk.

 

Despite the obvious downsides of hoarding too much unnecessary information, users consistently resist data disposal, clinging to information long past its useful life. If business leaders hope to successfully tackle this problem, they will need a robust data governance effort; only then can they tackle “the rot” at its source and prevent its spread.

 

The unseen forces behind digital clutter

So, how does ROT build up in the first place? There are several psychological and operational barriers that drive organisational reluctance to dispose of ROT data.

 

Take the legal profession as an example: when a lawyer wraps up a case, they often leave behind a trail of documents, templates, and notes. Even after the matter is closed, there’s a strong impulse to retain those materials, not out of necessity, but out of convenience. The idea is simple: “I might need this again.” After all, no one wants to reinvent the wheel or duplicate effort if they don’t have to.

 

This instinct isn’t unique to lawyers; it’s a universal tendency. We all hang onto files, drafts, or data that might prove useful someday (the operative word there being might). But when that behaviour scales across an enterprise of 50, 100, or 1000 employees, the cumulative effect is significant. What begins as a harmless habit can greatly complicate data governance and compliance, especially if this redundant data holds sensitive information.

 

It can also become a strain on the IT infrastructure and storage costs. Historically, organisations had to keep a close eye on storage levels, because running out of storage meant users complaining that they couldn’t work, requiring the IT department to physically install more storage to their main server or nudging users to delete files they didn’t need.

 

The transition from this largely on-prem IT infrastructure to the cloud brought a general perception among end users that these limitations were a thing of the past: “the cloud” was a limitless storage locker.

 

It’s not that simple, of course: while the storage itself might be scalable, it isn’t free, with the result that enterprises might wind up paying x pounds/Euros/dollars per gigabyte of storage each month, possibly for information from decades before that is no longer relevant or useful. 

 

That’s to say nothing of the fact that they’ve created a bigger, juicier target for bad actors looking to get their hands on sensitive data. Look no further than last decade’s Panama Papers scandal for a prime example of the security risks of hanging onto data much longer than you should.

 

A smarter approach to retention and disposition

To nip these problems in the bud, enterprises need to ensure that they have very clear retention policies in place. What constitutes useful information, and how long should that information be kept for? When does that information become redundant or obsolete, and when should it be disposed of?

 

These policies shouldn’t just be buried with other posts in the company intranet: they should be unambiguously communicated to all users within the organisation, so that everyone is on the same page about what official policy actually is.

 

Keep in mind that some users – when confronted with a policy telling them, for instance, that any irrelevant material older than a decade needs to be purged – might become paralysed at the prospect of having to sift through all the files and emails they’ve been hanging onto all these years to see what needs to be scrapped.

 

Fortunately, AI can lend a hand here. AI can help to identify and classify files. If an organisation has documents stored within a centralised location like a document management system (DMS), AI can analyse those files and produce an audit report of sorts, identifying documents that are over 10 years old.

 

More importantly, the AI can distinguish what type of document the file is. Is it a share purchase agreement? Is it a real estate lease? Is it a vendor contract? Is it a will that a law firm drew up for an individual? That’s a critical distinction, because wills, for instance, are a special category and need to be retained for at least 99 years.

 

Likewise, AI can identify if the file contains personal information and should have been deleted in accordance with GDPR, FINRA, or some other regulation that has emerged while someone was stockpiling files. Understanding what type of information is actually in your possession is the first step towards figuring out what you can keep and what you should dispose of.

 

Keep ROT in check

While there will always be a tendency for ROT to accumulate within an organisation, enterprises can effectively manage it and protect themselves from the associated downsides by embracing strategic data lifecycle management as a core business imperative. 

 

Implementing clear retention policies, clarifying them for all users within the organisation, and leveraging technology to automate retention and disposition will significantly contribute to preventing ROT from becoming a nightmare waiting to happen. 

 


 

Manuel Sanchez is an Information Security and Compliance Specialist at iManage

 

Main image courtesy of iStockPhoto.com and Nikada


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543