Information Governance Risk: Breach vs Access Loss
Most people hear “information governance risk” and think immediately of a data breach. In this lightning round, Lee Karas and Maura Dunn argue that the breach is only one risk on the list, and often not the one that costs you most. They work through the risk of not being able to reach your own information, using the New England PBS stations whose seventy years of program archives went dark when their cloud provider failed; the risk of ransomware, where nobody wants your data and simply locking you out of it is enough to stop the business; and the risk of the single hard drive or the single box of paper. From there they get practical about scaling risk to the organization: the one-person mechanic shop with three record types that matter (employment, hazardous materials disposal, and financial records supporting the tax return) against the charter school carrying accreditation, curriculum, teacher credentialing, facilities, and student transcripts that graduates ask for fifty years later. They then take on age as its own risk factor, since a company that has kept everything has both a volume problem and an exposure problem: underwriting records written under rules that changed decades ago, or environmental records from an era when the answer was to dump it in the ground. The through line is that a risk assessment is not an academic exercise. It is the input to the retention schedule you build, the repositories you pick, the providers you trust with fiduciary-level responsibility, and whether you are ready to put an AI system on top of any of it.
Episode chapters
00:00 Cold open: the lightning round
00:14 Welcome to What Counts
00:29 What is information governance risk?
00:48 The breach answer: financial records and PII
01:53 A second definition: you cannot find it when you need it
02:55 The PBS archive that disappeared inside a cloud provider
03:53 Why inaccessibility goes straight to the bottom line
04:24 Sizing breach risk: are you actually a target?
05:34 Ransomware and being locked out of your own data
06:06 One hard drive, one box: single points of failure
06:20 The mechanic who keeps everything in paper
07:53 Three record types a one-person shop still has to manage
08:42 The charter school: accreditation, curriculum, and student records
11:27 Company age as a risk factor: volume and obsolete rules
12:11 Underwriting and environmental records that come back to bite
14:02 No program, no proof: auditors, regulators, and courts
15:56 Fiduciary duty and vendor due diligence
16:37 Deploying AI without an IG program underneath it
17:40 Turning the assessment into retention and repository decisions
18:46 Wrap-up
19:07 Closing credits
Sponsor block
This episode is brought to you by TrailBlazer Tracker.
The contract you cannot find is also the contract that auto-renews without you. Tracker reads your PDFs, Word files, and scanned paper, pulls out renewal, cancellation, notice, and payment dates, and puts them on your calendar with lead-time alarms. Every date shows the exact source line it came from, so you can prove where it came from. Track your first document free, forever. Available on the App Store, Google Play, and the Microsoft Store. Details at trailblazer.us.com/tracker.
Closing
What Counts is produced by TrailBlazer Consulting, LLC and hosted by Lee Karas and Maura Dunn. Learn more or reach out directly at info@trailblazer.us.com. Explore compliance-ready corporate training programs at the TrailBlazer Learning Academy. Read more from Maura at Maura’s Substack. Music by Jason Blake. Full disclaimer.


