AWSCIO BriefingsRetrospectives

CIO Brief: You Can't Protect Data You Haven't Found

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2017, written in 2026 with the benefit of hindsight.

The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and still true: you cannot protect data you do not know you have.

Why data discovery matters to leadership

Most organizations underestimate how much sensitive data they hold and where. Copies of customer databases end up in test environments; exports sit in storage folders for years; departing projects leave data behind. Every unknown copy is a breach waiting to happen and a liability under privacy law.

The business impact

  • Breach cost rises with the amount and sensitivity of data exposed.
  • Regulatory obligations require you to know where personal data lives and to honor deletion requests.
  • Storage costs grow with data you no longer need.

Questions to ask your team

  • Do we have an inventory of where customer and employee data is stored in the cloud?
  • Who owns each major data store?
  • How much data do we keep that we no longer need?
  • Would we know if sensitive data appeared somewhere it shouldn't?

What good looks like

Automated discovery across cloud storage, named data owners, retention rules that delete what is no longer needed, and alerts when sensitive data shows up in unexpected places.

The decision

Fund a one-time data discovery exercise across your main cloud storage, then decide what to protect, move or delete. Deleting unneeded data is one of the few security investments that also reduces cost.

amazon macie impactAmazon Macie2017

More on this story