Security policy has a reputation problem. It reads like paperwork, it shows up once a year in required training, and it rarely feels connected to the work actually in front of you.
But most rules exist because something went wrong somewhere first. Someone sent a spreadsheet to the wrong address. Someone stored sensitive records in a personal account because it was faster. Someone pasted internal material into a tool nobody had reviewed. The rule came afterward, written by people trying to keep it from happening again.
The value of knowing the rules is that you are not deciding in the moment. When a request arrives and you are already behind, the answer is either something you know or something you improvise.
The Mistakes That Repeat
The 2026 Verizon Data Breach Investigations Report examined more than 22,000 confirmed breaches across 145 countries. In the education sector, Miscellaneous Errors ranked among the three most common breach patterns, accounting for 16 percent of breaches.
Misdelivery, meaning information sent to the wrong recipient, remains the leading error type in education and in nearly every other sector. Across the public sector broadly, misdelivery accounted for 88 percent of all errors. The second most common error type came in at 4 percent. It is not close.
The cause is not complicated. In public sector breaches, 91 percent of errors traced back to plain carelessness rather than to bad processes or bad technology. That finding is discouraging on one level and encouraging on another, because carelessness is the failure mode most responsive to a small change in habit.
Convenient Workarounds Carry Real Risk
Where misuse was involved in public sector breaches, 82 percent came down to data mishandling. That category is broad, and it covers exactly the shortcuts that feel harmless in the moment. Sending information through an unauthorized channel counts. So does using a workaround that puts data somewhere it was never supposed to live, or storing records in a way that does not meet policy.
None of that requires bad intent. It requires being busy and choosing the path with the least friction. The rules exist to mark where that path leads somewhere you would not have gone on purpose.
The Newest Rule Most People Have Not Read
Generative AI has moved faster than most policy has. The DBIR found that 45 percent of employees are now regular users of AI tools on corporate devices, up from 15 percent the previous year. Among users reaching AI services from corporate devices, 67 percent did so through non-corporate accounts.
Unauthorized AI use is now the third most common non-malicious insider action detected in the DBIR’s data loss prevention dataset, with its share increasing fourfold from the previous year. The most common data type submitted to external AI models was source code, followed by images and other structured data. In 3.2 percent of policy violations, research and technical documentation was uploaded to systems that had never been reviewed.
Anything pasted into an unapproved tool may leave university-controlled systems and be handled under terms and protections the university has not reviewed. Before using an AI service for university work, confirm the tool is approved and confirm what kinds of information are allowed to go into it.
Habits That Keep You Inside the Rules
- Learn how your data is classified and what each level permits before you need to move any of it.
- Keep university work on university systems and university accounts.
- Read the recipient line before you send, especially on anything containing personal or sensitive information.
- Resist routing work data through personal email, personal cloud storage, or personal devices for convenience.
- Confirm that an AI tool is approved before putting institutional information into it, and check which categories of data are permitted.
- Ask when a process seems to require a workaround, rather than inventing one. The workaround is usually the part that later shows up in an incident report.
- Ask before you act when you are unsure what a rule requires, because asking afterward is a different and harder conversation.
If Something Goes Wrong
If you sent information to the wrong recipient, stored something in a place it should not be, or put data into a tool you are not certain was approved, report it. Early reporting keeps a small mistake small. Waiting is what turns it into an incident.
For questions about a policy, a request, or a tool, the Office of Information Security would rather hear from you early than late. For account or device issues, contact your campus help desk. A full list of campus contacts is available on the Universities of Wisconsin IT Help Desks page.