World Paper Free Day: ignore this paper thin security scare

happygeek 1 Tallied Votes 435 Views Share

So, today is '' apparently and I'm not sure whether it's appropriate to buy a card in the circumstances. Joking aside, what I am sure of is that such Hallmark days do provide an opportunity for press releases to be thrown in my general direction. And so it was that yesterday one pops into my inbox proclaiming "Paper revealed as the top threat to information security." What rot! Before even reading a word of the release itself I knew that it was going to be rubbish that, if it were on paper, I would screw into a ball and with an athletic flounce chuck into the bin. I was not wrong, and here's why.

"Paper the top threat to information security say two-thirds of UK firms. Iron Mountain/PwC study reveals just 15 per cent have a team focused specifically on paper protection" screams the strap line. "The handling of paper documents is the single greatest threat to the protection of information, according to a recent study by storage and information management company Iron Mountain and PwC launched ahead of World Paper Free Day on November 6th" it continues, before informing me that 66 per cent of mid-sized companies regard the management of information on paper as a serious security risk, and that's more than double the number that fear external threats to digital content such as hacking and malware.

Can you spot the two big problems there? The first is obvious, and that is this bit of news was brought to you by a 'storage and information management' company, so no vested interest there then. The second is the wholly ridiculous claim that handling of paper is 'the single greatest threat' to information protection. Have I said "what rot" already? Yes, I have, good. If this was actually the case, in an increasingly digital world, then all our fears about cyber criminals, malware and data breaches could be solved by concentrating on removing paper from the equation and by so doing eliminating paper. How does that apply to those businesses who are, indeed, pretty much paper-free already? Can they save a small fortune by not bothering about protecting the digital data now then?

Look, I'm not completely stupid; I do understand that paper documents represent a security risk within any organisation that does not have appropriate strategies in place to mitigate risk wherever it occurs in the business. That means ensuring that any legacy archives are properly secured, access properly restricted and disposal properly supervised. All that should go without saying, as should suggesting that paper is the major risk we need to be concentrating on as far as data security is concerned.

I agree with Sue Trombley, Managing Director of Professional Services at Iron Mountain when she says that "organisations need to introduce and monitor effective processes and responsibilities for keeping paper documents safe. While we may never be completely free of paper, we can significantly reduce its associated risk by raising awareness, providing practical processes, and monitoring compliance" and if that was all the press release said I probably wouldn't be writing this news rant right now.

Unfortunately it went further, a lot further, and entered FUD territory by trying to hook a scare story on the back of a Hallmark day with that 'paper top threat to information security' headline...

Dani AI

Generated

is right to call out the headline as PR-driven exaggeration. Paper is a genuine vector for data loss — misfiled contracts, visible pay slips, or poorly controlled archive rooms — but treating it as the “single greatest” threat ignores context: likelihood, impact, and existing controls vary by organisation. Headlines around themed events tend to amplify perception rather than measured risk.

A practical, evidence-first reply is to treat paper the same way as digital: find the data, classify it, and apply controls proportionate to risk. Key steps are straightforward: perform a short inventory to locate where regulated or high-impact information exists on paper and digitally; assign data owners; map simple flows (who touches the document and when); and apply basic controls consistently. Typical controls to consider include locked storage and visitor logs for physical records, supervised shredding or secure destruction, print-release and clear-desk rules, and for electronic data strong authentication, encryption, patching, DLP where appropriate, and centralized logging.

A quick 30–90 day triage works well: within 30 days secure obvious high-risk paper repositories (HR, finance, legal) and enforce shredding/locked storage; enable full-disk encryption and MFA on endpoints; within 90 days formalise retention schedules, assign owners, and run a one-time audit or tabletop to validate procedures. Useful KPIs are simple and measurable: percent of sensitive records with an assigned owner, percent of endpoints encrypted, and number of uncontrolled print queues eliminated.

Surveys and soundbites (and yes, the freebie-themed PR that had joking) are conversation starters — not a substitute for an evidence-based program. Treat vendor claims as prompts to check inventories and controls, and let measured risk, not a headline, drive priorities.

RobertHDD 15 Posting Whiz in Training

I wish there was a worldwide event that people can get free stuff in an hour

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.