Join our Newsletter — 33% off our NHI Course

What are the signs that public folders and PSTs are becoming a governance problem?

Common warning signs include unclear ownership, unrestricted growth, orphaned content, and users creating PSTs outside policy. If teams cannot quickly explain who owns the data, who can access it, and why it still exists, governance has already degraded. Those conditions make migration harder and increase the chance that sensitive information is left exposed or forgotten.

What warning signs show public folders and PSTs are turning into a governance issue?

Public folders and PSTs become a governance problem when they stop behaving like controlled records repositories and start acting like informal data dumps. The early signs are usually visible in ownership, access, growth, retention, and policy drift. Once those controls are unclear, the problem is no longer just storage hygiene, it is a data governance and information risk issue.

When ownership and access stop being explainable

The most reliable sign is ambiguity: nobody can quickly say who owns the content, who is allowed to use it, or which business process still depends on it. That is especially concerning when public folders have accumulated over years, because inherited access often outlives the team that created it. A folder that is still shared but no longer actively governed is already operating on assumption rather than control.

Another warning sign is when access decisions are driven by convenience instead of policy. If users rely on broad shared permissions to avoid asking for access, the folder becomes a bypass around normal records handling. The same pattern shows up with PSTs when users keep exporting mail locally because it is easier than using a managed archive or retention process.

What growth, duplication, and off-policy use reveal

Unrestricted growth is more than a capacity issue. It often means content is being retained without review, duplicated into multiple places, or copied into PSTs to escape mailbox limits. When the volume grows but the business purpose is unclear, governance has lost its ability to distinguish active content from abandoned content.

Users creating PSTs outside policy is a strong signal that the official process is not meeting operational needs. In practice, that usually means one of three things: the policy is too restrictive, the approved tooling is hard to use, or teams do not trust the managed archive to meet their workflow. Whatever the cause, the result is the same, content moves into a less visible and less controllable state.

How to tell the issue is becoming a records, retention, and exposure problem

Governance is failing when old folders or PSTs remain in circulation long after the data should have been reviewed, archived, or disposed of. Orphaned content, stale permissions, and unclear retention status mean the environment is accumulating risk faster than it is being curated. That is the point where migration becomes harder, because the organisation is no longer moving a known set of records, it is trying to untangle years of unmanaged sprawl.

Exposure risk also rises when sensitive information can be found in places nobody monitors closely. Even if the data is not actively misused, forgotten PSTs and dormant public folders can still contain messages, attachments, or records that should have been restricted or removed. For readers looking for the broader data governance context, the NIST Privacy Framework is useful because it frames classification, retention, and governance as ongoing controls rather than one-time decisions.

Risk and Threat Considerations

The governance risk is not just administrative drift, it is that uncontrolled folders and PSTs expand the attack surface and the blast radius of a mistake. Once content is copied into unmanaged locations, access review, retention enforcement, and incident response all become harder, especially when the copy is disconnected from central monitoring or backup discipline.

Failure mechanism: Content moves into unmanaged or poorly owned stores, permissions age without review, and retention or deletion rules stop being enforced consistently.

Impact: Sensitive information can remain exposed, be duplicated across endpoints, or survive long after it should have been removed, which increases legal, operational, and incident-response burden.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Public folders and PSTs need clear ownership and business purpose.
GV.RM-01 — Risk Management Strategy Uncontrolled mail stores create retention, exposure, and migration risk.
Recommendation — Define ownership, purpose, and dependency for legacy shared stores before deciding retention or migration. Assess public folders and PSTs as governed data-risk assets, not just storage artifacts.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Broad legacy sharing is a common governance failure in public folders.
AU-11 — Audit Record Retention Legacy content needs defensible retention and disposition controls.
Recommendation — Restrict access to the minimum set of users and groups that still need the content. Retain only the records needed to meet policy, legal, and operational requirements.
ISO/IEC 27001:2022 A.5.12 — Classification of information Public folders and PSTs become risky when content cannot be classified consistently.
Recommendation — Classify legacy mail content so handling, access, and retention rules can be applied consistently.
CIS Controls v8 CIS-5 — Account Management Unclear ownership and stale access are central warning signs in shared content repositories.
Recommendation — Review and remove stale access paths to public folders and associated content stores.

Practitioner Guidance

What to verify: Confirm that every public folder and PST has a named owner, a documented purpose, a retention rule, and an access model that can be explained in one sentence. If any of those four items is missing, treat the item as uncontrolled until proven otherwise.

What to prioritise: Start with the highest-risk content, not the largest mailbox. Focus first on folders and PSTs that contain sensitive, business-critical, or long-retained material, because those are the ones most likely to create remediation blockers during migration.

Common mistake: Treating PST cleanup as a storage project. The real issue is governance, because without ownership and disposition rules, the same behaviours will reappear after the cleanup is finished.

Practitioner takeaway: If you cannot prove who owns the content, why it still exists, and who can access it, the folder or PST should be treated as a governance exception rather than a harmless legacy artifact.