IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
iStorage warns firms to secure data beyond networks

iStorage warns firms to secure data beyond networks

Tue, 1st Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

iStorage has urged organisations to pay more attention to protecting data outside their networks, as breaches in the UK public sector and education system continue to draw scrutiny.

Andrew Willdig, Group Chief Executive Officer of iStorage, said many organisations still treat network defence as the main line of protection, while paying too little attention to what happens when sensitive information is downloaded, copied or shared beyond the corporate environment.

His comments follow a reported breach affecting the Department for Education that exposed more than 600,000 records relating to government officials, school leaders and education organisations. He said the wider lesson extends beyond perimeter security.

"This breach is a reminder that no organisation is immune to data breaches. Protecting sensitive information requires more than just securing your network.

Organisations also need to invest in employee awareness, strong identity security and robust processes for managing third-party access, as human behaviour remains one of the biggest security challenges.

At the same time, sensitive data should remain protected wherever it goes. If it falls into the wrong hands, it should remain unreadable and unusable," said Andrew Willdig, Group Chief Executive Officer of iStorage.

The argument reflects a broader concern in cybersecurity: data often becomes more vulnerable once it leaves central systems. Files may be moved to laptops, removable storage devices or shared with external partners, creating risks that network controls alone do not address.

Education focus

Government survey data points to sustained pressure on schools and colleges. According to the education findings in the UK Government's Cyber Security Breaches Survey, 73% of secondary schools identified a cyber-attack or data breach in the past 12 months, up from 60% a year earlier.

That rise has reinforced education's position as one of the country's most frequently targeted sectors. Public bodies and education institutions often hold large volumes of personal information, making them attractive targets for criminals and leaving them exposed to disruption when systems or records are compromised.

Willdig said a key weakness lies in the assumption that protected networks automatically mean protected data. He argued that security planning must also account for staff behaviour, social engineering and third-party access.

"One of the biggest misconceptions is that once you've secured your network, your data is secure. But that's only part of the story.

Information is constantly being downloaded, copied and shared across laptops, portable storage devices and other removable media. Organisations also need to recognise that technology alone isn't enough.

Regular staff training, raising awareness of social engineering tactics and secure third-party access all play an important role in reducing risk.

Data needs to be protected wherever it goes, and unfortunately many organisations are leaving a significant gap in their data security strategy," Willdig said.

Planning gaps

Preparedness remains another concern. The latest UK Government Cyber Security Breaches Survey found that only 25% of businesses have a formal incident response plan, suggesting many still lack a defined process for dealing with cyber incidents.

For the 43% of businesses that experienced a cyber breach or attack in the past year, that gap may leave management teams responding under pressure without an agreed framework. In practice, incident response plans can determine how quickly systems are contained, which stakeholders are informed and how evidence is preserved.

The figures also suggest some organisations may be underestimating the operational side of cybersecurity. Technical controls may reduce exposure, but breach response also depends on governance, staff training and clarity over who makes decisions when an attack or data leak is identified.

Willdig said organisations should work on the basis that some sensitive data will move beyond their immediate control. In his view, the key question is whether that information remains protected when it does.

"I don't think it's always about a lack of investment. In many cases, organisations simply don't realise where their biggest risks are.

They spend a lot of time securing the network, which is important, but data breaches can happen in many different ways, whether through human error, social engineering or weaknesses in third-party access.

Forward planning is critical. Businesses need to combine technical safeguards with employee training, strong identity security and a clear incident response plan so that, if the worst does happen, their sensitive data remains protected," Willdig said.