www.kiteworks.com
www.kiteworks.com
Executive Summary
Kiteworks’ 2022 Sensitive Content Communications Privacy and Compliance Report is based on findings from a
detailed survey of IT, security, privacy, and compliance leaders representing 15 different countries.
1
The objective
of the survey was to identify key challenges and trends when it comes to how organizations govern and secure
sensitive content communications.
The report comes at a time when the average cost of a data breach now exceeds $4 million, according to IBM
and Ponemon Institute.
2
Regulatory bodies and government entities recognize the risk breached data poses to
organizations, and we have seen significant growth in compliance standards in recent years. Depending on their
industry and the geographical scope of operations, organizations must demonstrate their technology tools are
compliant with those standards as well as produce audit trails that demonstrate adherence to governance tracking
and controls around who accesses sensitive content, with whom it is shared, when was it updated and shared, on
what devices it was shared, and where it is stored.
One of the foremost takeaways from the report is that a majority of organizations are inadequately protected against
third-party security and compliance risks related to sensitive content communications. There are numerous reasons
behind this issue.
Complexity, Silos, and Inefficiencies
Most organizations share sensitive content with a long list of third-party entities. Two-thirds of organizations do so
with more than 1,000 third parties, while one-third have over 2,500. The complexity of governing and securing these
sensitive content communications is heightened due to all organizations in the survey admitting to using numerous
communication channels, including email, file sharing, web forms, file transfer and automation protocols, and
application programming interfaces (APIs). Email and file sharing are most used, though other communication
protocols were frequently cited as well.
2022 Sensitive Content Communications Privacy
and Compliance Report
67%
use 4+ different systems to
track, control, and secure content
communications
60%
ask the sender to send an unencrypted
file to a shared drive link if an email
cannot be decrypted
30+
Almost half spend 30+ staff hours
monthly dealing with incoming
emails that cannot be decrypted