10 tips to prevent email errors It’s confession time. I recently copied the wrong person on an email. Same first name, different surname. Thankfully, it was easily resolved. But for someone in my line of work? Shameful. It’s like a chef putting ketchup on a pasta dish. Nonetheless, I decided to try my best to learn from the experience. Which got me thinking about two issues in particular: a) Email errors are not just one of the major causes of personal data breaches, but also downright awkward even where there’s no personal data risk. They can lead to sharing commercially sensitive information, or opinions. They can breach client trust. b) What are the best ways of reducing instances of human error? I know I’m not alone. Other data protection folk have admitted making the occasional mistake too. A good friend of mine once accidentally sent an email to a client – not a data breach but she did lose the client. I’ll also never forget receiving an email and finding myself reading a fellow colleague’s rather disparaging views about my team. Of course, there are the frequent data breaches – often small, sometimes big, caused by matters like emailing the wrong recipient, or using the CC field for multiple recipients. Yet, for many, it’s ‘just one of those things.’ Oops! Then the embarrassment fades… until next time. So is it really enough to keep reminding people to double check before sending? Won’t there always be times when we’re overworked, dashing to go on holiday, or distracted by personal issues? Is it good enough to rely on recall features? Probably not, when in practice they’re often completely ineffective. People will continue to make mistakes. To err is human. What else can we do? 10 email tips Here are a few suggestions for reducing the risk. 1. Disable or restrict auto-fill Yes auto-fill is a handy way to quickly go through our address book and predict who we want to email. Nonetheless, it sometimes chooses the wrong person… and we don’t notice. This is what got me. I’ve disabled this feature, and shouldn’t have had it enabled in the first place. I am now very content to spend a couple of seconds finding the correct email address. 2. Avoid email altogether Encourage (or insist) that staff who need to share attachments, personal data or any other sensitive information use links to protected SharePoint folders/files rather than using email. 3. Attachments Use software to prevent or restrict any email containing an attachment. 4. Detect personal data If 3. is a a step too far, look at using software which can automatically detect personal data in attachments or email content and prevents it being sent – or prompts people to check they really want to send. 5. External recipients Implement user prompts for external email recipients – ‘are you sure you want to send this externally?’ 6. Multiple recipients Use controls to alert users if they’re emailing multiple recipients using the CC field – prompting them to use BCC. Alternatively for teams who routinely send emails using BCC, use a bulk mail solution. 7. Delay on send How often do you spot an error just after you’ve sent an email? Setting up a delay on send for your staff, gives people a chance to correct their mistakes. 8. ‘Reply to All’ Set an alert if people are about to reply to all, prompting them to check whether this is appropriate. 9. Revoke access after sending Some more advanced email security solutions give you the ability to recall or revoke access to an email and its attachments, even after it hits the recipient’s inbox. 10. Email review Where teams are responsible for routinely sending sensitive information by email, and there’s no alternative, have a review process so someone else checks before sending. It’s worth checking what controls are available on your email system or looking at additional software solutions. Some of the prompts mentioned above are available using Outlook’s MailTips. Of course training, continually raising awareness and clear rules all play their part. Making sure your people know how you expect them to behave is crucial. It also needs to be clear what action people should take when they’ve made a mistake. Are staff permitted to try and rectify this themselves, or does it always need to be immediately reported? The steps you expect your staff to take need to be easily understood and reinforced in training and culture. This also means supervisors should lead by example. I’m a fan of quick reference guides supporting more detailed policies and procedures. In this case, a ‘golden rules for emails’ on one page, in plain English. with the rules and clear steps for what to do when things go wrong. Laminate it, turn it into posters – do whatever works to get the message home. Ultimately, mistakes are inevitable. What isn’t inevitable, though, is the impact mistakes have once the ‘send’ button’s been hit. Every little step taken to mitigate email errors lessens the impact when one inevitably slips through the net. Most of us, after all, recognise the occasional mistake will occur. The problem is if they happen too often, it can undermine confidence in your people, your organisation and your brand.
Access controls: Protecting your systems and data Is your data properly protected? Do existing staff or former employees have access to personal data they shouldn’t have access to? Keeping your business’ IT estate and personal data safe and secure is vital. One of the key ways to achieve this is by having robust access controls. Failure to make sure you have appropriate measures and controls to protect your network and the personal data on it could lead to a data breach. This could have very serious consequences for your customers and staff, and the business’ reputation and finances. How things can go wrong Recently a former management trainee at a car rental company was found guilty and fined for illegally obtaining customer records. Accessing this data fell outside his role at the time. In 2023 a former 111 call centre advisor was found guilty and fined for illegally accessing the medical records of a child and his family. In 2022 a former staff advisor for an NHS Foundation was recently found guilty of accessing patient records without a valid reason. Anecdotally, we know of cases of former employees being found to be using their previous employer’s personal data once they have moved onto a new role. The ability to access and either deliberately or accidentally misuse data is a common risk for all organisations. Add to this the risk of more employees and contractors working remotely, and it’s clear we need to take control of who has access to what. High-level check list 1. Apply the ‘Principle of Least Privilege’ There’s a useful security principle, known as ‘the principle of least privilege’ (PoLP). This sets a rule that employees should have only the minimum access rights needed to perform their job functions. Think of it in the same way as the ‘minimisation’ principle within GDPR. You grant the minimum access necessary for each user to meet the specific set of tasks their role requires, with the specific datasets they need. By adopting this principle, you can prevent the risk of employees gaining more access rights over time. You’ll need to periodically check to make sure they still need the existing access rights they have. For example, when someone changes role, their access needs may also change. If your access controls haven’t been reviewed for a long time, adopting PoLP can give you great start point to tighten up security. 2. Identity and Access Management IAM is a broad term for the policy, processes and technology you use to administer employee access to your IT resources. IAM technology can join it all up – a single place where your business users can be authenticated when they sign into the network and be granted specific access to the selected IT resources, datasets and functions they need for their role. One IAM example you may have heard of is Microsoft’s Active Directory. 3. Role-based access Your business might have several departments and various levels of responsibility within them. Most employees won’t need access to all areas. Many businesses adopt a framework in which employees can be identified by their job role and level, so they can be given access rights which meets the needs of the type of job they do. 4. Security layers Striking the right balance between usability and security is not easy. It’s important to consider the sensitivity of different data and the risks if that data was breached. You can take a proportionate approach to setting your security controls. For example personal data, financial data, special category or other sensitive personal data, commercially sensitive data (and so on) will need a greater level of security than most other data. Technologies can help you apply proportionate levels of security. Implementing security technologies at the appropriate levels can give greater protection to certain systems & data which demand a high level of security (i.e. strictly-controlled access), while allowing non-confidential or non-sensitive information to be accessed quickly by a wider audience. 5. Using biometrics How do you access your laptop or phone? Many of us use our fingerprint or facial recognition which give a high level of security, using our own biometrics data. But some say, for all their convenience benefits, they are not as secure as a complex password! But then, how many of us really use complex passwords? Perhaps you use an app to generate and store complex passwords for you. Sadly lots of people use words, names or memorable dates within their passwords. Security is only going to be as good as your weakest link. 6. Multi-factor authentication (MFA) Multi-factor authentication has become a business standard in many situations, to prevent fraudulent use of stolen passwords or PINs. But do make sure it’s set up effectively. I’ve seen some examples where MFA has to be activated by the user themselves. So if they fail to activate it, there’s little point having it. I’ve heard about data breaches happening following ineffective implementation of MFA, so do be vigilant. There are an array of measures which can be adopted. This is just a taster, which I hope you found useful – stay safe and secure!