Date: 30 July 2026
Shadow Copies Undermine Everything Else
Even a well-controlled library loses its value if the same assets exist in a dozen other places. Files get downloaded to laptops, forwarded as email attachments, dropped into personal cloud accounts because a deadline was tight, and shared through messaging apps that were never approved for anything. Once an asset leaves the managed system, no permission model applies to it.
This is why usability matters as a security property rather than a nicety: a library that is slow, confusing or restrictive guarantees that people will work around it, and every workaround creates an uncontrolled copy. The organisations that keep media under control are generally the ones where retrieving an asset properly is easier than emailing it. The same reasoning applies to how external parties are given material.
A time-limited link tied to a named recipient is both easier for an agency than a credential and far easier for the organisation to revoke, and choosing that route by default removes a large share of the sprawl before it accumulates.
Assets Carry Obligations, Not Just Content
Beyond confidentiality, media files come with commitments attached that expire. Stock imagery is licensed for defined uses and periods. Photographs of employees and customers are personal data with retention limits and consent conditions. Material from a partner may be usable only while the partnership lasts.
A library with no record of these constraints will eventually use something it no longer has the right to use, which is a legal and reputational problem rather than a technical one. Recording rights and expiry alongside each asset, and enforcing them systematically, is the only approach that holds once a collection passes a few thousand items.
Bring It Into the Programme
The practical steps are unremarkable and rarely taken. Add media repositories to the data inventory and classify their contents rather than assuming everything in them is public. Run periodic access reviews covering external parties as well as staff. Ensure offboarding covers these platforms, since departing employees and finished contracts are the most common source of stale access.
Record licensing and consent alongside the assets themselves. And involve the marketing team as owners rather than subjects, because they understand the material and will route around any control imposed without their input. Media is data. It simply arrived through a door the security function was not watching.
Incident response planning deserves the same attention, since a compromise of a media platform raises questions most playbooks do not answer: what was in there, who could reach it, whether unreleased material has been taken, and which third parties need to be told.
Working that through in advance is considerably easier than improvising it during an incident, and it usually surfaces the access and inventory gaps described above before an attacker does.



