
Manuel Sanchez at iManage argues that hoarding ROT-ting data is a cyber-security nightmare waiting to happen
Organisations are drowning in virtual mountains of redundant, obsolete, and trivial (ROT) data. Stored across numerous digital systems, this data serves no business purpose while dramatically increasing the potential attack surface for bad actors. The migration to cloud platforms has added a new wrinkle by layering escalating storage costs on top of this ever-deepening potential security risk.
Despite the obvious downsides of hoarding too much unnecessary information, users consistently resist data disposal, clinging to information long past its useful life. If business leaders hope to successfully tackle this problem, they will need a robust data governance effort; only then can they tackle “the rot” at its source and prevent its spread.
So, how does ROT build up in the first place? There are several psychological and operational barriers that drive organisational reluctance to dispose of ROT data.
Take the legal profession as an example: when a lawyer wraps up a case, they often leave behind a trail of documents, templates, and notes. Even after the matter is closed, there’s a strong impulse to retain those materials, not out of necessity, but out of convenience. The idea is simple: “I might need this again.” After all, no one wants to reinvent the wheel or duplicate effort if they don’t have to.
This instinct isn’t unique to lawyers; it’s a universal tendency. We all hang onto files, drafts, or data that might prove useful someday (the operative word there being might). But when that behaviour scales across an enterprise of 50, 100, or 1000 employees, the cumulative effect is significant. What begins as a harmless habit can greatly complicate data governance and compliance, especially if this redundant data holds sensitive information.
It can also become a strain on the IT infrastructure and storage costs. Historically, organisations had to keep a close eye on storage levels, because running out of storage meant users complaining that they couldn’t work, requiring the IT department to physically install more storage to their main server or nudging users to delete files they didn’t need.
The transition from this largely on-prem IT infrastructure to the cloud brought a general perception among end users that these limitations were a thing of the past: “the cloud” was a limitless storage locker.
It’s not that simple, of course: while the storage itself might be scalable, it isn’t free, with the result that enterprises might wind up paying x pounds/Euros/dollars per gigabyte of storage each month, possibly for information from decades before that is no longer relevant or useful.
That’s to say nothing of the fact that they’ve created a bigger, juicier target for bad actors looking to get their hands on sensitive data. Look no further than last decade’s Panama Papers scandal for a prime example of the security risks of hanging onto data much longer than you should.
To nip these problems in the bud, enterprises need to ensure that they have very clear retention policies in place. What constitutes useful information, and how long should that information be kept for? When does that information become redundant or obsolete, and when should it be disposed of?
These policies shouldn’t just be buried with other posts in the company intranet: they should be unambiguously communicated to all users within the organisation, so that everyone is on the same page about what official policy actually is.
Keep in mind that some users – when confronted with a policy telling them, for instance, that any irrelevant material older than a decade needs to be purged – might become paralysed at the prospect of having to sift through all the files and emails they’ve been hanging onto all these years to see what needs to be scrapped.
Fortunately, AI can lend a hand here. AI can help to identify and classify files. If an organisation has documents stored within a centralised location like a document management system (DMS), AI can analyse those files and produce an audit report of sorts, identifying documents that are over 10 years old.
More importantly, the AI can distinguish what type of document the file is. Is it a share purchase agreement? Is it a real estate lease? Is it a vendor contract? Is it a will that a law firm drew up for an individual? That’s a critical distinction, because wills, for instance, are a special category and need to be retained for at least 99 years.
Likewise, AI can identify if the file contains personal information and should have been deleted in accordance with GDPR, FINRA, or some other regulation that has emerged while someone was stockpiling files. Understanding what type of information is actually in your possession is the first step towards figuring out what you can keep and what you should dispose of.
While there will always be a tendency for ROT to accumulate within an organisation, enterprises can effectively manage it and protect themselves from the associated downsides by embracing strategic data lifecycle management as a core business imperative.
Implementing clear retention policies, clarifying them for all users within the organisation, and leveraging technology to automate retention and disposition will significantly contribute to preventing ROT from becoming a nightmare waiting to happen.
Manuel Sanchez is an Information Security and Compliance Specialist at iManage
Main image courtesy of iStockPhoto.com and Nikada
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543