Data Leakage: Human Weakness Or System Design | INTERNAL AUDIT DEPARTMENT
» ARTICLE » Data leakage: Human weakness or System design

Data leakage: Human weakness or System design

Article Search and Republishes By  : Audit Dalam UPM Website Committee

 

In recent days, the public has been shocked by an issue involving the misuse of customer information that went viral on social media. As usual, much of the attention has focused on the individual believed to be involved.

However, from a software engineering perspective, a more important question should be asked. Did the incident happen only because of human error, or did it also reveal weaknesses in the system’s design?

 

The reality is that humans are not perfect. Mistakes and misuse can happen, whether intentionally or unintentionally. Therefore, modern digital systems should not be designed with the assumption that every user will always follow the correct procedures.

 

Instead, systems should be designed with the possibility of misuse in mind. They should also be able to prevent harmful actions before customers are affected.

 

In software engineering, there is an important concept known as "security by design".

 

This concept means that security should not be added only after a system has been completed. It should be included in the system from the early stages of development.

 

For example, a building is designed with emergency exits, security cameras and alarm systems before it is opened for use. In the same way, a digital system should have built-in security controls from the beginning.

 

One important practice is the principle of “least privilege”. This means that every user should only be given access to the information needed to perform their duties.

 

For example, if an employee only needs access to customer payment information, the employee should not be able to view the customer’s full profile or unrelated transaction history. The wider the access given, the higher the risk of misuse.

 

Besides limiting access, every activity carried out in the system should also be properly recorded. These records are not only useful for investigations after an incident. They also help organisations monitor and detect suspicious activities.

 

An organisation should be able to identify unusual activities, such as a user accessing hundreds of customer records within a short period or accessing the system outside normal working hours.

 

This is where artificial intelligence, or AI, can play a greater role. Today, AI is not only used to create content or answer questions. It is also widely used in cybersecurity.

 

Through machine learning, a system can learn the normal usage patterns of each user. It can then detect activities that are different from the user’s usual behaviour.

 

When suspicious activity is detected, the system can automatically issue an alert or temporarily block access until further checks are completed.

 

However, technology alone cannot solve every problem. Information security also depends on the organisation’s culture.

 

Employees should receive regular training on data-handling ethics, customer privacy and the legal consequences of misusing information.

 

In today’s digital world, every piece of customer data is a responsibility that must be protected carefully.

 

Organisations also need to change the way they view cybersecurity. Security should not be treated as an additional cost or as the responsibility of the information technology department alone.

Instead, it should be part of the organisation’s overall strategy. It should involve management, system developers, operational staff and everyone who handles customer information.

 

In the digital economy, trust is often more valuable than technology itself.

 

Customers do not choose a service only because of its competitive price or advanced features. They also choose it because they believe their personal information will be kept safe.

 

Once that trust is damaged, rebuilding it can take a long time and cost much more than investing in proper security from the beginning.

 

Therefore, every incident involving data misuse should be treated as an important lesson for all organisations, regardless of their industry.

 

The focus should not only be on identifying who is responsible. Organisations should also examine how their systems can be designed to be safer, smarter and more resilient.

 

In a world that increasingly depends on data, an organisation’s success is no longer measured only by how advanced its technology is. It is also measured by its ability to protect the trust given by every customer.

 

Article Published by: Ts. Dr. Sufri Muhammad, Senior Lecturer, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia

Source: Berita RTM

Date of Input: 27/07/2026 | Updated: 27/07/2026 | faiz_suparman

MEDIA SHARING

INTERNAL AUDIT DEPARTMENT
Universiti Putra Malaysia
43400 UPM Serdang
Selangor Darul Ehsan
03-9769 1346
03-9769 6176
X, (03:25:41pm-03:30:41pm, 28 Jul 2026)   [*LIVETIMESTAMP*]