Security teams map their data thoroughly. Customer records, financial systems, source code repositories, HR files: all identified, classified and controlled. Then there is the marketing team's shared drive containing forty thousand images, video files, product photographs and campaign material, accessed by two agencies, six freelancers and everyone who has ever worked in the department.
It rarely appears on a data inventory, it almost never features in an access review, and it is treated as though media were somehow not data at all.
The reason is largely historical. Marketing assets were traditionally low-sensitivity, and the tooling used to manage them grew up outside IT's remit, purchased on a departmental card and adopted because it was convenient. That inheritance persists even as the material has become more sensitive. Product imagery ahead of a launch is commercially confidential. Photographs taken inside facilities disclose layout, equipment and physical security arrangements.
Video from internal events captures employees who never consented to external use. Frameworks set out in a Cloudinary DAM resource and similar overviews describe how these systems handle permissions, versioning and audit trails, which is precisely the vocabulary a security function needs when the conversation with marketing turns from what a platform can do creatively to who can retrieve what from it.
Media libraries accumulate external access more readily than almost any other repository, because sharing is the point. Agencies need assets. Freelance designers need working files. Print suppliers need originals.
Each of those relationships generates credentials or share links, and very few organisations remove them when a project finishes. The characteristic failure is not a breach but an accumulation: a library where nobody can say with confidence who currently has access, and where a link generated for a supplier three years ago still resolves.
The National Cyber Security Centre is consistent on this point in its guidance, treating regular review of accounts and permissions, and prompt removal of access that is no longer needed, as a basic control rather than an advanced one. Applying that review to media platforms as rigorously as to core systems closes a gap most organisations do not know they have.
Even a well-controlled library loses its value if the same assets exist in a dozen other places. Files get downloaded to laptops, forwarded as email attachments, dropped into personal cloud accounts because a deadline was tight, and shared through messaging apps that were never approved for anything. Once an asset leaves the managed system, no permission model applies to it.
This is why usability matters as a security property rather than a nicety: a library that is slow, confusing or restrictive guarantees that people will work around it, and every workaround creates an uncontrolled copy. The organisations that keep media under control are generally the ones where retrieving an asset properly is easier than emailing it. The same reasoning applies to how external parties are given material.
A time-limited link tied to a named recipient is both easier for an agency than a credential and far easier for the organisation to revoke, and choosing that route by default removes a large share of the sprawl before it accumulates.
Beyond confidentiality, media files come with commitments attached that expire. Stock imagery is licensed for defined uses and periods. Photographs of employees and customers are personal data with retention limits and consent conditions. Material from a partner may be usable only while the partnership lasts.
A library with no record of these constraints will eventually use something it no longer has the right to use, which is a legal and reputational problem rather than a technical one. Recording rights and expiry alongside each asset, and enforcing them systematically, is the only approach that holds once a collection passes a few thousand items.
The practical steps are unremarkable and rarely taken. Add media repositories to the data inventory and classify their contents rather than assuming everything in them is public. Run periodic access reviews covering external parties as well as staff. Ensure offboarding covers these platforms, since departing employees and finished contracts are the most common source of stale access.
Record licensing and consent alongside the assets themselves. And involve the marketing team as owners rather than subjects, because they understand the material and will route around any control imposed without their input. Media is data. It simply arrived through a door the security function was not watching.
Incident response planning deserves the same attention, since a compromise of a media platform raises questions most playbooks do not answer: what was in there, who could reach it, whether unreleased material has been taken, and which third parties need to be told.
Working that through in advance is considerably easier than improvising it during an incident, and it usually surfaces the access and inventory gaps described above before an attacker does.