Security is a leadership responsibility
Data breaches make headlines, but the daily reality of security is less dramatic and more important. It's about policies, practices, and choices that protect your organization and the people you serve.
For leaders in human services, healthcare, and education, this isn't optional. You're holding sensitive data about vulnerable populations. The stakes are real.
Four things every leader should understand
1. Know where your data lives
Can you name every system that holds client data? Every spreadsheet, every cloud tool, every legacy database? If not, you have a visibility problem. You can't protect what you can't see.
Start by cataloging every system that touches sensitive data. This inventory is the foundation of any security practice.
2. Access should be the minimum necessary
The principle of least privilege means people should only have access to the data they need for their role. Not everyone needs admin access. Not every staff member needs to see every client's record.
Review access permissions at least annually. When someone changes roles or leaves, update their access immediately.
3. Backups aren't optional
If your primary system fails — server crash, ransomware, accidental deletion — can you recover? Backups need to be automatic, regular, and tested. An untested backup is the same as no backup.
Ask your team: when was the last time we tested a restore? If the answer is "never" or "I don't know," fix that this week.
4. Compliance is the floor, not the ceiling
Meeting regulatory requirements — PIPEDA, PHIPA, HIPAA, whatever applies to your jurisdiction — is the minimum standard. Good security practices go beyond compliance checkboxes.
Compliance tells you what you must do. A security-conscious culture tells you what you should do.
The conversation to have with your team
Ask three questions: What's our biggest security risk right now? When was our last access review? What's our recovery plan if a critical system goes down?
The answers will tell you where to focus your attention and investment.
The takeaway
Security doesn't require technical expertise to lead effectively. It requires awareness, discipline, and the willingness to prioritize protection alongside productivity. Make it a regular topic, not an afterthought.
