Business impact across your data sources

Compare your data sources by usage, employee access, data sensitivity and cyber posture to spot risky, unnecessary or well-managed systems.

Not every system in your inventory carries the same risk. A tool that many employees can access but rarely use, or a vendor with weak security handling sensitive data, deserves more attention than a well-secured system used daily by a small team. The Business impact view compares your data sources across four dimensions, so you can quickly see which systems to review, restrict or retire.

Open the business impact view

In the left navigation, under Governance, select Risks, then select the Business impact tab.

How to read the view

Each comparison has three parts:

  • The matrix plots your data sources on two dimensions. Red areas indicate the highest potential impact, yellow areas need a closer look, and green areas indicate good usage.
  • Highlights count how many data sources fall into each impact category, with a short explanation of what it means.
  • The table lists each data source with its values for both dimensions and its estimated impact.

Above the matrix, you'll see how many data sources are shown, and how many aren't showing due to missing data.

Comparisons

Under Compare, choose one of four comparisons:

ComparisonWhat it helps you find
Usage vs. employeesSystems that many employees can access but rarely use, which increases the risk of accidental disclosure, and systems few people use that you may not need at all
Employees vs. data sensitivitySystems where many employees can access highly sensitive data
Employees vs. cyber postureSystems with weak security that many employees use
Cyber posture vs. data sensitivityVendors with weak security that hold sensitive data [confirm highlight categories]

Impact categories

CategoryWhat it means
Risk for accidental disclosureMore people can access the data than need to, or sensitive data is exposed to a wider group, which increases the chance of a data leak
Misconduct of sensitive dataMany employees can access highly sensitive data. Review the vendor's data protection practices and who has access
Questionable necessityOnly a few employees access the system, and rarely. Consider whether you still need it
Actively used, good usage or good cyber postureThe system is well matched to how it's used, with no immediate concern

Where the data comes from

DimensionSource
Usage and employeesDiscovery, which detects how many employees access each system and how often [confirm: email and SSO discovery]
Data sensitivityThe data types assigned to each data source [confirm]
Cyber postureThe vendor's cyber posture rating [confirm]

Data sources missing a value for either dimension of a comparison aren't shown in it. To include them, complete their details in your inventory: for example, set up discovery or add data types. See Navigate Your Inventory.

Act on the results

If you seeConsider
Risk for accidental disclosureLimiting access to the employees who need it, or reviewing whether the data needs to be in that system
Misconduct of sensitive dataRunning a privacy or security assessment on the vendor, and reviewing its data protection practices
Questionable necessityConfirming with the business owner whether the system is still needed, and marking it as unused if not
Weak cyber postureRunning a vendor security assessment and flagging the risk in your risk registry

Reducing the number of systems and people with access to personal data is a core principle of privacy and security frameworks worldwide, and these comparisons help you act on it.

Related articles


Did this page help you?