Retention drift: the breach multiplier nobody decided on: Retained data accumulating into exposure that multiplies the impact of a breach.Retention drift: the breach multiplier nobody decided on: Retained data accumulating into exposure that multiplies the impact of a breach.
S10 Group Newsletter · Identity & Containment Series

Retention drift:
the breach multiplier nobody decided on

Why the blast radius is often built
long before the incident begins.
Newsletter #5
Published: 15 July 2026
Last updated: 9 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert

The data that never quite went away

The previous newsletter issues looked at what happens when trust fails, when a critical vendor becomes unsafe, when the first hour is still waiting for permission and when detection does not become action quickly enough.

This final issue moves one layer earlier. It asks a more uncomfortable question:

how much of the eventual consequence was quietly built before the incident began?

That is the difficult part of retention drift. Nobody usually decides to create a future breach multiplier. Nobody sits in a meeting and says: let us keep old data, broad access and forgotten identity paths alive so the next incident becomes larger.

It happens in smaller, more reasonable moments. A data copy stays because migration is not finished. A dataset is kept because someone may need it. A service account survives because nobody owns it. An export lands in a reporting environment and becomes normal. A temporary exception becomes part of how the business runs.

When an incident breaks, the initial hours are not defined by technical resolution, but by absolute operational uncertainty. Which records were reachable? Which copies still existed? Which systems held data the business assumed had become irrelevant? Which trusted paths still connected to old data stores, exports, archives or exceptions that nobody had revisited for years? And if those old exceptions are still reachable, they can become exactly the material an attacker wants most: data with leverage, access with consequence, and pathways that still work because nobody had been forced to close them before pressure arrived.

The attacker did not create all of that in the moment. The attacker found it.

Most impact is accumulated, not attacked.
Retention, access scope, and identity pathways often determine the blast radius before the incident begins.

When “temporary” becomes permanent

European data-protection guidance is clear on the basic principle: personal data should not be kept longer than necessary, and organisations should define when data is erased or reviewed. That sounds simple until pressure reveals how many exceptions have quietly become the operating model.

The Odido reporting made that pattern concrete and close to home. Public reporting in February 2026 said Odido needed more time to understand why some customer data appeared to have been retained beyond its stated period. That is why the Odido reporting matters here. The investigation into retention periods is not the main story of the breach. It is the side effect that makes the deeper point visible: when data remains reachable beyond its useful life, a security incident can turn yesterday’s unresolved governance into today’s exposure, tomorrow’s regulatory question and a longer trust problem for people who thought the relationship had already ended.

In March, further reporting found data relating to at least 44,000 former customers in the leaked dataset whose relationship with the company had ended more than two years earlier. Dutch regulators later opened an investigation into the retention of customer data after the hack.

That does not prove motive. It does not require us to make a legal conclusion. It does something more useful for leaders: it shows how a breach becomes heavier when old data remains reachable after the business purpose has faded.

The uncomfortable lesson is not only that a retention rule may have failed. It is that retention discipline becomes operational resilience when trust breaks.

Because once an attacker is inside, the question is no longer only what data exists. It is what data still exists, who can still reach it and which trusted routes still connect to it.

That is why over-retention is not mainly a paperwork problem. It is a governance problem that waits patiently until the incident turns it into a public, operational and human one.
Retained is not the same as reachable
On 26 March 2026, Dutch regulators separated two questions that are often treated as one. The Autoriteit Persoonsgegevens opened a specific investigation into the retention periods applied to current and former customer data, while the Rijksinspectie Digitale Infrastructuur examined the security of Odido’s customer system. A July update stated that the ACM would assess the provider’s statutory duty of care together with the RDI, while the AP would focus fully on data-retention periods. No final regulatory conclusion has yet been published.

That distinction matters for leadership. Some records may need to be retained for legitimate contractual, fiscal or legal reasons, but the fact that a record must still exist does not determine whether it should remain reachable through the same live system, identity path or operational account.

Retention, accessibility and deletion are separate control decisions. The resilience question is whether each remains proportionate to the purpose the data still serves—and whether unnecessary operational reach can be removed before an incident turns retained information into exposed information.

The data that never quite went away
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details
What sensitive data still exists in your environment that no longer serves an operational purpose but would still matter if exposed?

The blast radius is built before the attack

A breach is rarely shaped by data volume alone. It is shaped by three quiet multipliers that often exist long before the first public statement is written.

Retention is what still exists. Access scope is what can still be reached. Identity pathways are the trusted routes that still connect people, services, suppliers, integrations and automated processes to that data.

That triad is what makes retention drift more dangerous than storage waste. Old data only becomes a live problem when trust paths still lead to it.

That matters now because attackers increasingly operate through what organisations already trust. Microsoft describes persistent access, identity-driven intrusion and preventable exposure across critical infrastructure.

ReliaQuest described a recent reporting period in which “trust” itself was the key attack surface, with attackers exploiting trusted tools, identities and user behaviour. In healthcare, Vectra describes long reconnaissance periods in which attackers map networks, identify critical systems and look for leverage before impact becomes visible.

Detection still matters. But detection cannot easily clean up years of accumulation once the incident is already moving. Kudelski describes a narrow detection window in some ransomware cases, with attackers moving from initial access to full domain control within hours. By then, old data, forgotten access and trusted pathways may already have defined how wide the incident can become.

That is the real multiplier. Not only what the attacker does. What the environment still allows the attacker to reach.

What Control Changes
When accumulated exposure becomes live risk, control depends on what the organisation can still narrow, isolate, and protect in practice.

Strategic levers

  1. Force the uncomfortable data question.
    Name one sensitive data category the business assumes is “under control”: former-customer records, archived claims, inactive patient files, historical identity data, old exports, legacy backup sets. Then ask whether that data still serves an operational purpose today, or whether it simply still exists because removing it became too hard.
  2. Force the reachability question.
    For that same data category, identify who or what can still reach it now: people, service accounts, suppliers, integrations, automation, reporting tools, AI copilots, backup processes and emergency accounts. Not who once needed access. Who can still reach it today.
  3. Force the control question.
    Prove what can be narrowed in minutes without breaking legitimate operations. Which path can be closed? Which privilege can be removed? Which copy can be restricted? Which identity route can be segmented? Which data store can be isolated without creating a second outage?


The point is not to prove that a retention policy exists. The point is to discover whether the organisation can still reduce exposure when old data, broad access and trusted identity paths become a live control problem.

A useful pressure-test is simple: take one sensitive data category and trace it from policy to reality. Where does it live? Where was it copied? Who can reach it? Which identity path still connects to it? What would break if that path was narrowed? And if the answer is “we do not know”, the blast radius is already larger than leadership thinks.

What Retention Changes
Retention discipline does more than reduce compliance risk.
It reduces how much of the environment becomes consequential when trust breaks.

From accumulated exposure to control

I would not describe retention drift as a legal tail-end issue. It is part of operational resilience because a security breach cannot always be prevented.

When trust breaks, old exposure does not remain old. It becomes current.

Former-customer data becomes customer impact. Dormant access becomes attacker reach. A forgotten export becomes a disclosure problem. A trusted identity path becomes a way to turn yesterday’s exception into tomorrow’s headline.

Retention drift does not create the incident. It can enlarge what the security incident is able to touch.

Control decides whether that exposure becomes theft, encryption, spread or operational collapse once the attacker is inside.

The Odido reporting makes that point visible. The investigation into retention periods is not the core cyber incident, but it shows how old records can create a second layer of consequence once attackers gain access: data exposure, regulatory scrutiny and a longer trust problem for people who believed the relationship had already ended.

But retention discipline is only one part of the answer; it merely reduces what happens to be stored there. It does not, by itself, stop an attacker who has already successfully entered the environment.

That is where operational control becomes decisive. Our platform is built for the exact moment prevention has been bypassed and the organisation must still maintain control. It detects lateral movement, prevents data theft, protects virtual environments, halts ransomware encryption, and interrupts malicious behaviour before a single compromised path escalates into a wider operational crisis.

Consequently, the practical leadership question becomes far sharper than retention alone:

If an attacker reaches your data tomorrow, can you detect the movement and stop the data theft before exposure becomes wider consequence?

If that would be relevant for your team, feel free to contact me:

The problem is rarely only that attackers got in.
It is that too much old exposure was still there when they did.

New series: The Governable Organisation

With this fifth issue, we close the first arc of this newsletter: identity, dependency, first-hour authority, detection delay and retention drift. Together, they point to the same uncomfortable lesson. Modern incidents do not become difficult only because attackers get in. They become difficult because access, data, dependencies, decision rights and operational assumptions have already shaped how much control remains when pressure arrives.

That is why the next phase of Control Under Pressure will widen the lens.
From next month, the newsletter moves into a new editorial theme:

The Governable Organisation

The question is no longer only how to contain a specific incident. It is how to build an organisation that can still make decisions, narrow exposure, preserve operations and explain its actions when prevention has already been bypassed. This next phase connects three S10 content streams:

The Resilience Briefings
Why resilience has changed — and why continuity now depends on control, not only recovery.

CISO & Leadership Dynamics

Why cyber leadership has changed — and why technical reality now has to be translated into governance, authority, budget and accountability.

When Attacks Move

How control is actually lost — through lateral movement, trusted paths, identity misuse, supplier exposure, data reachability and operational delay.

The first multi-series release starts in September 2026.

Thank you for reading this first arc. The next one moves from incident containment to a larger question:

What makes an organisation governable when pressure arrives?

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.

No noise. No automated campaign stream. Just a simple signal when there is something worth reading.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Further readings

Previous S10 Group newsletter arc

17 March 2026 - #01: The Odido lesson:
The Odido Lesson →
Return to the identity-trust lesson: access may continue to work even after the organisation can no longer trust what that access represents.
08 April 2026 - #02:
When the Vendor Is Non-Negotiable →
Explore how dependency on critical suppliers can reduce room to manoeuvre when trust becomes uncertain.
14 May 2026 - #03:
The First Hour: Who Is Allowed to Act? →
Revisit the decision-rights question that determines whether the first hour produces action or delay.
17 June 2026 - #04:
Detection Is Not Control →
Understand why detection only matters when the organisation can safely turn signals into action.

Context & discovery

The public sources listed here serve as a reading path for context and inspiration, rather than a formal academic bibliography. These external materials are independent of the official S10 publication track.
Optional further reading / inspiration only
Cloud Security Alliance - Understanding the blast radius