Sony Pixel Power calrec Sony

Why is procurement so critical to minimizing information risk? by Amy Perras

15/09/2016

In today's business environment, no organization can afford to ignore information risk. The consequences of an information related catastrophe, whether it's a malicious attack, a natural disaster or a simple employee error, can be enormous. Six figure fines, loss of reputation, potential lawsuits the costs are frequently counted in millions of dollars. In many cases, businesses never recover. According to the London Chamber of Commerce, 90% of companies that suffer a significant data loss go out of business within two years.

It's not just about IT

While businesses are definitely waking up to the need to develop strategies to minimize their exposure to information risk, there is still a tendency amongst senior managers to think of this as an IT issue in other words something for someone else to take responsibility for. Senior managers are not alone in their complacency. In a 2014 PwC survey of 1,800 businesses, when asked who should have a responsibility for information risk the majority said IT, with a mere 1% in Europe and 3% in North America saying everyone .

Procurement on the front line

The fact is, information risk is something that affects everyone within an organization. We all benefit when it is managed well, and we all stand to suffer if it is ignored or handled poorly. And procurement professionals, in particular, find themselves on the front line of this critical issue.

Why procurement matters so much

One of the biggest challenges companies face in trying to get their records management under control is the unfortunate reality that they have records in too many disparate locations under the control of too many different vendors.

This causes immediate problems that threaten to undermine the best records management strategy. Having multiple storage locations and vendors makes it difficult to operate according to your established methods and processes. Not only that, it forces you to become an expert in all of your vendors' respective systems and practices.

In most cases, this situation has not come about through a deliberate decision-making process. Multiple vendors can creep into an organization's daily business activities in many ways. Some may be a legacy from mergers or acquisitions, whilst others have popped up through local offices or business units simply going off and doing their own thing.

However the situation evolved, the result is records being held by different vendors, in different locations, often under different systems. This is costly, complex and confusing. Moreover, managing multiple vendors is wasteful and makes it difficult, if not impossible, for the company who has all these vendors to be able to find the records it needs. Indeed, a recent report by Iron Mountain found that 83% of organizations were unable to locate hard-copy records when needed.

It's not just you (my supplier), but your suppliers that I am interested in. If they are out of compliance, we are all out of compliance. Ellen, Strategic Sourcing Manager

The consequences of chaotic procurement

Unnecessary expense

Managing multiple vendors increases the costs of records management and gives your organization far less control over deploying and enforcing enterprise-wide policies and processes. It also gives you less leverage than if you are using a single vendor. Furthermore, you are failing to maximize economies of scale and in all likelihood overspending on discovery costs, personnel, training and management.

Poor productivity

Having multiple vendors is not only costly in dollars, it also puts an unnecessary strain on worker productivity. Employees have to go to different places to find records, utilizing different systems for legal holds and different processes for destruction.

Inconsistent policy management

With too many vendors, retention, destruction and legal holds can be subject to multiple and inconsistent policies, along with multiple applications and manual processes. This makes it almost impossible to achieve the records management standards you are seeking. According to research undertaken by Iron Mountain, only 9% of companies say they are able to achieve a best-practice level of consistent, enterprise-wide policy adoption.

Litigation risks

E-discovery costs are not the only major risk in having too many vendors for records management. Your organization may be more susceptible to litigation losses, or even unable to defend itself properly because inconsistent policy application across multiple vendors means information is not there when you need it. It is a poor way to settle a lawsuit when you could have mounted a vigorous defense, simply because you can't find some records.

In our next blog, we look at how organizations can realign their procurement strategy to consolidate their vendors and turn information risk into information opportunity.
LINK: http://blogs.ironmountain.com/2016/service-lines/information-managemen...
See more stories from ironmountain

More from Iron Mountain Entertainment Services

14/06/2017

HIMs in the Driver Seat: Accelerating Data Integrity Efforts by Michelle Urban

Early on in EMR implementation it was all about getting up and running to realize the incentive payments offered by the government. How could legacy information...

14/06/2017

SMB Tax Season: Would Your Business Pass an IRS Audit? by Melissa Cantarow

If you run or work at a small business, you know there are many perks. From the close relationships to the opportunities to take on new skills and roles, there&...

14/06/2017

Are You Looking for Custom Kitting Solutions? Then Look No Further by Leslie Barton

Custom kitting can be viewed as the process by which your business touches pro...

29/03/2017

Leading the way to data quality by Karen Snyder

This year's Healthcare Information and Management Systems Society (HIMSS) Annual Conference had another record-setting year for attendance, with over 40,000...

28/03/2017

Leading the Way to Quality Data by James White

Having worked in Health Information for over 39 years, I recently had an opportunity to speak with Health Information students at Cuyahoga Community College. Th...

09/03/2017

AWS Outage Shows How Little Control Cloud Users Have by Nadine Dias

On Tuesday, February 28th, Amazon Web Services (AWS) had a service disruption that affected its Simple Storage Service (S3) which supports over 150,000 websites...

07/03/2017

Custom Kitting and Booklets: Cut the Clutter and Make a Good Impreion by Leslie Barton

I don't know about you, but I'm just way too busy these days. When I ask...

01/03/2017

What ds Trump s Dodd-Frank Reform mean for Banking and Financial Services? by Shawn A. Brazeau

The Dodd-Frank Act is currently being reviewed by the Trump administration in an...

28/02/2017

Do Your Point of Purchase Displays ATTRACT Customers? by Leslie Barton

In a competitive retail environment, creative use of point of purchase displays can set you apart from the dull roar of conventional installations. Manufacturer...

16/02/2017

Join the ranks of Heal IT profeionals standing up to #makeHITcount every day! by Elia Robins

Imagine a seamlessappointment with your health provider: Even with a last-minut...

14/02/2017

Treating the Old Wounds of Transition to Advance Value-Based Care by Michelle Urban

ARRA. HIPAA. Meaningful Use. Value-based Care. MACRA. And so it goes The only th...

09/02/2017

Meaningful Use and MACRA-Positive Change by James White

As a Healthcare Information management (HIM) professional for the past 40 years, I have experienced the transition of the paper medical record to today's mo...

08/02/2017

IG Solutions - It s A New Day for Records Retention Schedules! by Craig Grimestad

Companies often struggle with numerous issues when developing and administrating...

06/02/2017

Ds Healcare Care About Clinical Quality Improvement? by John Lynn

We face a big challenge in healthcare. A doctor's success is largely not dependent on the quality of care they provide a patient. We won't dive into the...

03/02/2017

Holy MACRA! by Karen Snyder

A lot has been written about the Medicare Access and CHIP Reauthorization Act, better known as MACRA, since it was published in October 2016. The intent of this...

31/01/2017

Destination: Value-Based Care by Nancy Twombly

Despite all predictions on the future of our healthcare delivery system, healthcare is - and will continue to be - one of the key drivers in our economy. While ...

27/01/2017

Data privacy in the IoT Era by Paul Gillin

It's appropriate that this year's Data Privacy Day (January 28) takes place just three weeks after the giant Consumer Electronic Show (CES). CES is an a...

13/01/2017

5 Top IT Predictions for 07: Which Technology Trends will Impact You? by John Boruvka

This is certainly the time of year for predictions, forecasts, and trends, so we...

05/01/2017

Are you using our Escrow Management Center to your Advantage? by Nadine Dias

As an Iron Mountain technology escrow customer, you have access to our online portal in Iron Mountain Connect called the Escrow Management Center. We hope all ...

05/01/2017

Retention Schedules To Purge or Not to Purge and When? by Linda Joshua

When developing a retention schedule and looking at the legal research that supports it, there are laws and regulations that set minimum periods that must be ad...

30/12/2016

What happens when your Source Code is released from Escrow? by Nadine Dias

You may know that technology escrow (also known as software escrow) is a best practice for safeguarding your software source code in case there is ever an issue...

23/12/2016

The Psychology of Records Management: Energize Compliance with Technology by Craig Grimestad

This is the last of a 7 part series on energizing compliance. The last? I though...

29/11/2016

Mergers, Acquisitions & Divestitures: Managing Information and Risk by Mark Emery

Mergers, Acquisitions and Divestures (MA&D) happen for many reasons - to create ...

18/11/2016

Concerned with Busine Continuity? Understand Software Licensing Risks. by John Boruvka

If you're concerned with business continuity in your company, it's impor...

18/11/2016

Evaluating Your Storage Options: Tape or Cloud by John Sharpe

Over the past few years or so, data protection has trended towards the Cloud. But that doesn't mean tape is dead-far from it. Today's forward-thinking o...

04/11/2016

A Millennial s Impreion: My first Gartner Conference by Nadine Dias

I was the oddball millennial at the recent Gartner IT Financial, Procurement & Asset Management Summit in Grapevine, Texas. As one of the few millennials at th...

21/10/2016

Managing Cyber Security reats to Personal Heal Information by John Lynn

One of the challenges that keeps healthcare leaders up at night more than any other is managing cyber security threats to health data management. Unfortunately,...

17/10/2016

The consequences of data hoarding by Paul Gillin

At some point during the past decade, storage costs crossed a threshold that made it cheaper and easier for organizations to keep data than to throw it away. Th...

08/10/2016

Why Hackers Love Small Businees

Typically, when a data breach makes the headlines it involves a well-known brand with deep pockets which might give you a sense that hackers are only interested...

05/10/2016

Records management best practices: In 40 characters or le by Karen Guglielmo

Records management is a complicated job. RIM professional work hard every day to take their company's R and I and M the heck out it. So we took to Twi...

30/09/2016

Building a Framework for the Future of Federal Information Management by Lisa De Luca

The information landscape is constantly changing, especially for government. Fed...

30/09/2016

Care Continuum And the Internet of ings by Simon Morrell

I was once part of the Internet of Things. A sensor on my sneaker linked to a tiny computer on my wrist. When I plugged the computer into my laptop the battery ...

30/09/2016

Is Your Busine Prepared for a Cyberattack? by Eileen Sweeney

September is National Preparedness Month and a good time to think about whether your company is ready. Companies can improve preparedness by being proactive - r...

28/09/2016

The Psychology of Records Management: Energize Compliance with Forcing Functions by Craig Grimestad

With what? Never heard the term Forcing Functions used in Records Management (...

16/09/2016

A Virus Backup Plan: Responding to a Terrible, Horrible, No Good, Very Bad Day by John Sharpe

Extortion. Ransom. International crime syndicates. No, this isn't a descript...

16/09/2016

How can procurement help an organization master information risk? by Amy Perras

There is a tendency for discussions about information risk to focus exclusively on the dangers organizations find themselves exposed to and potential disasters ...

15/09/2016

Why is procurement so critical to minimizing information risk? by Amy Perras

In today's business environment, no organization can afford to ignore information risk. The consequences of an information related catastrophe, whether it&#...

23/08/2016

The 4 Levels of Verification: Verify Your Developer s Compliance by Nadine Dias

Once you have made the decision of whether or not you need technology escrow, ha...

22/08/2016

The Standard is the Standard: ISO 700 & Law Firms by Brianne Aul

This past June, our Pittsburgh ARMA chapter toured Heinz Field, home to the Super Bowl LI Champion (you heard it here first!) Pittsburgh Steelers. Directly out...

18/08/2016

Pre- Vs. Post-Claification For Records Metadata by Juerg Meier

I recently watched a demo of the IBM Watson natural language processing (NLP) tool that showed how it was used by police for criminal investigations at a Record...

15/08/2016

Closing the Gap by Lisa De Luca

Empowering Federal Professionals with Next-Generation Information Management Skills As anybody who has been paying attention to federal headlines or budgets ca...

10/08/2016

Putting information privacy first by John JT Tomovcsik

There is a lot more to protecting customer privacy than locking down facilities and enforcing strong passwords. It's about getting the entire organization a...

09/08/2016

A Licensee s Guide to Technology Escrow [Free eBook] by Nadine Dias

Investing in technology is not a decision that is made lightly. In today's technology-driven world, companies are competing to be the best of the best and t...

05/08/2016

Disposing of IT ts: eBay, You Found What on ose Hard Drives? by Michele Hope

Some organizations dispose of their IT assets by recycling what they can and discarding the rest. For others, this process involves reselling parts that still h...

05/08/2016

How to Reduce Data Storage Costs by John Sharpe

In the age of big data, IT managers are increasingly tasked with taking more comprehensive views of their organizations' data. This requires them to evaluat...

05/08/2016

Uncovering the Hidden Risk wiin Federal Information Management Programs by Lisa De Luca

Identifying and addressing the burgeoning skills gap issue The federal governm...

04/08/2016

My First 6 Mons as an IG Project Coordinator by Jeica Bundy

I recently checked in with Karen, the project coordinator for the Records and Information Governance Group at a large healthcare corporation in Missouri. Karen ...

28/07/2016

Customer Care by Day, Rock Star by Night by Megan OKeefe

Friendliness, patience, and determination are qualities that make for a remarkable customer service agent, and Kim possesses all three. As a member of Iron Mou...

22/07/2016

Top Benefits of Outsourcing Print and Fulfillment by Leslie Barton

You have to spend money to make money, as the old adage goes. But, when it comes to print and fulfillment, most companies would prefer to spend less and make mo...

21/07/2016

6 Bad Habits of Data Management- Part by John Sharpe

In my last blog, 6 Bad Habits of Data Management- Part 1, I covered three bad habits many IT departments across the globe are guilty of committing. Here are 3 m...