No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Preventing “The Great Spreadsheet Escape:” Lessons from BlackRock’s Data Leak

It Could Have Been Worse. It Also Could Have Been Prevented.

by Diane Robinette
March 20, 2019
in Data Privacy, Featured
illustration of leaky faucet in blue

In January, BlackRock accidentally leaked confidential sales data by posting spreadsheets unsecurely online – certainly not the first time we’ve seen sensitive information “escape” an organization. Incisive CEO Diane Robinette provides guidance companies can follow to minimize spreadsheet risk.

Several weeks ago, the world’s largest asset manager, BlackRock, accidentally posted a link to spreadsheets containing confidential information about thousands of the firm’s financial advisor clients. As reported by Bloomberg News, the link was inadvertently posted on the company’s web pages dedicated to BlackRock’s iShares exchange-traded funds. Included in these spreadsheets was a categorized list of advisors broken into groups identified as “dabblers” and “power users.”

While BlackRock was lucky in the fact that there was no financial information included on these spreadsheets, they are still left to deal with reputational damage. For the rest of us, this breach brings an important issue — spreadsheet risk management — back into the spotlight.

Despite years of rumors predicting the demise of spreadsheets, they are still widely used by businesses of every size. And why shouldn’t they be? Beyond providing an easy way to categorize clients and business partners, spreadsheets continue to meet the analytical needs of finance and business executives. They are especially useful for analyzing and providing evidentiary support for decision-making and for complex calculations where data is continuously changing. Yet, as we’ve seen time and time again, spreadsheets represent continued exposure to risk.

Accidentally clicking on the wrong spreadsheet is an easy mistake to make, especially when all documents are stored and treated equally. For example, it may seem obvious that a confidential spreadsheet should not sit alongside a football or Oscars pool spreadsheet, yet sometimes they do. When this happens, in a rush, it’s easy to click on the wrong spreadsheet and hit “send” or “post” before realizing the error. Putting policies in place that dictate such things as where confidential spreadsheets are stored is a good start. However, policies and procedures alone are simply not enough. Technology that enforces these policies and limits spreadsheet access to only authorized users is critical to stopping spreadsheets from escaping.

In an effort to gain control over spreadsheet risks, it’s not uncommon for companies to focus on change management. And while there is great value in the ability to track who changed what, when they changed it, etc., change management alone is also not enough.

It’s essential to put controls around spreadsheets that allow policies to be set and enforced and to dictate such things as who can access a spreadsheet or whether a spreadsheet can be saved outside the system. Spreadsheet risk management technology cannot entirely prevent scenarios like the BlackRock one from happening (yet). However, the ability to house critical spreadsheets in a controlled environment, along with policies and procedures, can limit these situations from happening.

Human error is always a liability. And while technology alone isn’t the answer, the right technology will provide the visibility and transparency to ensure you’re doing the right things. Implementing controls to manage the risks associated with business-critical spreadsheets will help keep companies from becoming the subject of embarrassing or devastating headlines.

Tags: Data GovernanceReputation Risk
Previous Post

Proposed Privacy Legislation Grows at the State Level

Next Post

Deloitte Report: 94 Percent of Boards Surveyed Aim to Increase Diversity, Industry-Specific Experience Tops Board Recruitment Priorities

Diane Robinette

Diane Robinette

Diane Robinette is president and CEO of Incisive Software, a provider of innovative risk intelligence spreadsheet management solutions. She has more than 20 years of experience in strategic planning, marketing, product management, business operations and management. Diane has worked in companies from startups to large enterprises in various industries including high-tech, aerospace and defense, telecommunications, financial services and transportation.

Related Posts

EU flags in sun

European Data Act: Balancing IP & Privacy

by Peter Lando and Stefica Milor
August 24, 2026

Companies that delay meeting the act’s requirements may find themselves challenged by enforcement and outpaced by competitors

capitol building

So You’ve Been Subpoenaed by Congress? How to Prepare for Lawmakers’ Grilling

by Robert S. Hoff and Julie A. Edelstein
August 18, 2026

A congressional investigation is a high-stakes event where the response matters as much as the underlying facts

ways and means meeting room

As Midterms Approach, Specter of Transcribed Interviews Rises for Non-Governmental Actors

by Jason McCullough, Diana Shaw and Peter Rechter
August 18, 2026

TIs are informal, but records are kept and they are increasingly being videotaped

user data privacy notice in app

What Companies Need to Know About the Evolving Youth Privacy Landscape

by Greg Szewczyk and Madison Etherington
August 10, 2026

With numerous state youth data laws passed and more in the works, count on a patchwork adding to compliance requirements

Next Post
racially diverse hands raised on yellow background

Deloitte Report: 94 Percent of Boards Surveyed Aim to Increase Diversity, Industry-Specific Experience Tops Board Recruitment Priorities

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights