internal management file
aka Excel spreadsheet
The UK government's corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of dozens of officials publicly accessible for around 40 hours. The breach, first reported by The Guardian, was disclosed in UK Government Investments' (UKGI) annual report, which says …
a member of staff "did not follow established information security policies."
There are a host of questions in that weaselese.
In this context what is meant exactly by established which in no way means codified, promulgated or published.
Unless staff a regularly inducted, refreshed and tested on current policy - security or otherwise - it is entirely disingenuous to claim any failure on their part is entirely their fault.
Inadequate systems, inadequate support and incompetent (oh, and also inadequate) leadership are invariably the root causes of these systemic failures. That is not going to change soon - or ever - so these failures will recur but those responsible will likely become better at concealment.