TL;DR: Ungoverned ROT data is driving breach exposure, compliance risk, AI data leakage, and operational overhead, according to Securiti’s whitepaper, which argues that discovery alone is not enough without policy-driven deletion and lifecycle controls. The real issue is that data governance fails when organisations can find data but cannot defensibly act on it.
NHIMG editorial — based on content published by Securiti: The Cost of Ungoverned Data When Invisible Risk Becomes Unavoidable
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: How should security teams reduce ROT data risk without creating retention chaos?
A: Start by classifying data into retention classes with explicit owners, legal hold rules, and deletion triggers.
Q: Why does shadow IT create risk for both human and non-human identities?
A: Because unmanaged SaaS often contains both employee access and machine-to-machine access inside the same application boundary.
Q: What do teams get wrong about data discovery and minimisation?
A: They often treat discovery as the finish line.
Practitioner guidance
- Define executable retention rules Map each major data class to a retention period, legal hold condition, and deletion trigger so disposition is no longer a manual judgement call.
- Link DSPM findings to remediation Require every sensitive-data discovery to land in a workflow that can restrict, archive, or delete the record with a logged approval trail.
- Stop AI systems from consuming ROT data Block low-value or expired content from vector stores, copilots, and downstream retrieval layers until the data has been minimised and reclassified.
What's in the full article
Securiti's full whitepaper covers the operational detail this post intentionally leaves for the source:
- A cost breakdown for breach exposure, regulatory fines, AI data leakage, and storage overhead tied to ROT data.
- A policy-driven deletion approach for organisations that need defensible minimisation with an audit trail.
- Operational guidance for using Securiti's DSPM capability to classify, contextualise, and remediate ungoverned data.
- Examples of how teams can move from discovery to continuous audit-ready posture.
👉 Read Securiti's whitepaper on the cost of ungoverned data →
ROT data minimization for AI agents: what should teams do now?
Explore further
ROT data creates identity risk because access outlives purpose. When data has no clear owner, retention rule, or disposition path, it becomes available to people, service accounts, and AI systems that no longer need it. That is not just storage waste. It is identity exposure translated into data sprawl. The practitioner implication is that data minimization and access governance now have to be treated as one control surface.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Another finding from LLMjacking: How Attackers Hijack AI Using Compromised NHIs shows attackers can attempt access within 17 minutes of public AWS credential exposure.
A question worth separating out:
Q: Who should own accountability for AI data access risk?
A: Accountability should sit with the teams that own identity, data governance, and security operations together. If AI can access enterprise data, then ownership must cover entitlement design, monitoring, and incident response across the full workflow. The governance gap is not just technical, because without a named owner, no one can prove who approved or contained the access.
👉 Read our full editorial: ROT data minimization is now core to safe enterprise AI governance