Things we’ve seen before

TJ’s Stories

Small decisions. Large consequences. Practical stories about the controls that protect information, people, and continuity. This is guidance, not legal advice.

A note from TJ

I’ve spent years seeing how ordinary technology decisions play out in real businesses. In these stories, the shortcuts were taken by management trying to save a buck—without considering the larger ramifications for the business. I’m sharing the patterns, warning signs, and practical controls so directors and teams can recognise the risk before it becomes their incident.

TJ’s Story #001

“Just Use Your Own Laptop”

Unmanaged BYOD and VPN access

The company needed someone to work from home, so a personal laptop was approved in five minutes. It had no central management, no confirmed encryption, and no reliable patch record. The employee connected through the VPN, copied client files locally, and later lost the laptop in a café. The VPN had been protected; the device and the data on it had not. When the employee was terminated, the company disabled the VPN account—but could not prove whether client files, cached email, browser downloads, or synchronised folders had been removed from the personal laptop. An RMM agent or remote-wipe tool was not an answer: the laptop contained the employee’s private information, and the employee was not expected to let a third party control it.

Question for the Directors

If a personal device is used to reach company systems, who verifies that it is secure before access is granted—and how will the organisation verify deletion when the person leaves?

Potential Legal & Regulatory Implications

PDPA 2024 may be relevant where personal data is accessed or stored. Under the Companies Act 2016, directors should be able to explain how material operational and information risks were considered. The issue is not that BYOD is automatically unlawful; it is whether the organisation has defined, proportionate safeguards and can demonstrate them.

ISO/IEC 27001 best-practice controls

  • Asset and access inventory with an assigned device owner
  • MFA and least-privilege VPN or zero-trust access
  • Company-controlled storage with no local synchronisation or downloads where possible
  • Immediate termination checklist: revoke accounts, tokens, sessions, certificates, and shared links
  • Clear BYOD prohibition or tightly limited exception that respects the employee’s private data and does not rely on RMM control
  • Offboarding attestation and documented residual-risk decision where the device cannot be inspected

What should a reasonable director have done?

Prefer managed company devices, or keep company data in systems that can be revoked centrally without controlling the employee’s personal laptop. At termination, disable every access path, remove company-side access and shared links, recover any company equipment, request deletion of any agreed local copies without inspecting private data, and record what cannot be verified. If the organisation cannot prove that data is absent, it should not have placed that data on the personal device.

TJ’s Story #002

“Give Him Administrator Rights”

Privilege without accountability

An end user needed to install a printer driver, so management gave him administrator rights “just for now.” The exception stayed in place. In some cases, every end user in the business was given administrator access before we stepped in. A malicious attachment could then run with far more authority than the user needed, turning a convenience decision into a company-wide blast-radius decision.

Question for the Directors

Why does this end user need this level of access, and when will it be removed?

Potential Legal & Regulatory Implications

PDPA 2024 may be engaged if excessive privilege contributes to unauthorised access to personal data. The Companies Act 2016 does not make every access mistake automatically illegal, but it reinforces the need for directors to exercise informed oversight of material business risks. Copyright Act 1987 can also matter when software is installed or copied without a valid licence.

ISO/IEC 27001 best-practice controls

  • Role-based access and least privilege
  • Separate standard and administrative accounts
  • Privileged-access approval and time limits
  • Access reviews and audit logs
  • Licensed software and controlled change management

What should a reasonable director have done?

Keep end users on standard accounts, provide a controlled way to install approved software, remove blanket administrator access, and review any exceptional access with an expiry date.

TJ’s Story #003

“We're Only 20 Staff”

No policies because the business is small

There were only twenty people, so the company kept security in the founders’ heads. Everyone knew the Wi-Fi password. Nobody knew who should report a suspicious email, who could approve a new user, or what happened when an employee left. Small teams move quickly; without a few written decisions, they also spread mistakes quickly.

Question for the Directors

Could a new employee, manager, or adviser understand how information is handled without asking one person?

Potential Legal & Regulatory Implications

PDPA 2024 applies based on the handling of personal data, not on whether an organisation feels large. The Companies Act 2016 may make governance and oversight relevant to directors’ duties, but a missing policy is not automatically a statutory breach. Copyright Act 1987 may be relevant to unlicensed software, images, documents, or training material used by the business.

ISO/IEC 27001 best-practice controls

  • Information-security and acceptable-use policy
  • Joiner, mover, and leaver process
  • Incident and breach reporting route
  • Backup, retention, and recovery responsibilities
  • Security awareness and periodic review

What should a reasonable director have done?

Write the small set of rules the business actually needs, assign owners, train staff, and review the rules after changes or incidents.

TJ’s Story #004

“The Printer Went Back”

A leased multifunction printer with a built-in hard drive

The office returned its leased multifunction printer at the end of the contract. Everyone remembered the paper trays and the meter reading. Nobody asked about the hard drive. Over the years, the machine had stored scanned identity documents, contracts, invoices, and copies of correspondence. The device left the building with a great deal of confidential information still inside it.

Question for the Directors

When a leased device leaves the organisation, can we prove what happened to the data it retained?

Potential Legal & Regulatory Implications

PDPA 2024 may be relevant where personal data remains on a device returned to a principal or supplier. The Companies Act 2016 makes it sensible for directors to oversee the custody and disposal of material business records; return of a device is not automatically a breach, but unmanaged data retention creates a foreseeable risk. Copyright Act 1987 may also be relevant to stored or copied third-party material. Contract terms, processor responsibilities, and evidence of sanitisation should be checked.

ISO/IEC 27001 best-practice controls

  • Inventory printers and confirm whether they contain HDDs, SSDs, fax memory, or removable media
  • Define retention, export, and secure deletion before lease return
  • Obtain a written certificate of sanitisation, destruction, or retained-disk custody
  • Restrict service access and review vendor or principal data-processing terms
  • Record chain of custody, return date, serial number, and responsible approver

What should a reasonable director have done?

Ask about storage at purchase or renewal, export only what must be retained, require a documented wipe or disk-removal process, and keep evidence before the machine leaves the premises.

TJ’s Story #005

“I’m Not IT Savvy, I Didn’t Know”

Directors do not need to be technical specialists—but they do need oversight

When the incident was discussed, the director said, “I’m not IT savvy. I didn’t know.” No one expected the director to understand every firewall rule, endpoint alert, or backup log. But directors routinely ask accountants about cash flow, tax exposure, controls, and unusual transactions. If those questions are serious enough for the accounts, why should the systems holding the company’s records, money, and personal data receive less attention? The business had approved technology spending, accepted risk, appointed suppliers, and received warnings that were never recorded or followed up. Not knowing the technical detail was understandable; not asking whether the important risks were controlled was avoidable.

Question for the Directors

If directors ask detailed questions about accounting because financial controls matter, what equivalent questions are they asking about IT, security, privacy, and recovery?

Potential Legal & Regulatory Implications

PDPA 2024 may be relevant where personal data is processed without appropriate safeguards or where a breach is not handled as required. The Companies Act 2016 does not require directors to become IT engineers, but directors should exercise informed oversight, make reasonable enquiries, and retain evidence of material risk decisions. These facts do not automatically establish liability; responsibility depends on the circumstances, duties, and conduct involved.

ISO/IEC 27001 best-practice controls

  • Defined information-security responsibilities and reporting lines
  • A risk register with owners, deadlines, and accepted residual risks
  • Regular management reporting in plain business language
  • Independent review or specialist advice where internal expertise is limited
  • Recorded decisions, exceptions, budgets, and follow-up actions
  • Incident escalation and board-level review of material events

What should a reasonable director have done?

Ask IT the same kind of control questions asked of finance: what could go wrong, how likely and damaging it would be, which controls reduce the risk, how they are tested, and who owns the next action. Directors can rely on specialists, but should challenge unclear answers, document decisions, and verify that agreed actions were completed.

TJ’s Story #006

“The Security Budget Could Wait”

Layered security is a business control

The business had thirty staff, so management approved only a small NAS, inexpensive consumer laptops running Windows 10 Home Edition, and Microsoft Office Personal. To minimize costs, one Microsoft Office Personal subscription—usable on up to five devices—was shared across the workforce. No budget was approved for email security, endpoint detection and response, MFA, monitoring, awareness training, or incident response. The laptops became obsolete while the NAS quietly collected company files. Months later, a convincing invoice attachment launched malware. Nobody noticed the attacker exploring the network until files were encrypted. A firewall can reduce network exposure; it cannot by itself stop a user from being phished.

Question for the Directors

If the business approves only a NAS, Windows 10 Home laptops, and shared Microsoft Office Personal subscriptions, what protects thirty staff from phishing, credential theft, ransomware, and loss of the NAS itself?

Potential Legal & Regulatory Implications

PDPA 2024 may require an organisation to consider reasonable security measures when personal data is at risk. Directors under the Companies Act 2016 should be prepared to explain how material cyber risk and resilience were assessed. Neither law makes one product mandatory in every organisation; the defensible question is whether safeguards were proportionate to the risk and actually operated.

ISO/IEC 27001 best-practice controls

  • Email security and phishing protection
  • Endpoint Detection and Response (EDR) mandatory for managed endpoints
  • Supported operating systems and centrally managed endpoint updates
  • MFA and least-privilege access
  • Business-appropriate identity and licensing rather than shared personal subscriptions
  • Central monitoring, logging, and alert response
  • Security awareness training, incident response, and tested backups separate from the NAS

What should a reasonable director have done?

Treat the NAS and laptops as only part of the environment. Fund a layered control set, replace unsupported endpoints, use business-appropriate licensing and identities, assign monitoring and response ownership, and test recovery from a failure or ransomware event before relying on the equipment.

Next step