threat_intelligence1276 wordsRead on Arc Codex

The business risk of using personal email accounts

The business risk of using personal email accounts When employees move business communications into personal email accounts, organizations lose visibility into where data resides, who can access it, and how to protect, retain, or recover it when something goes wrong. Key takeaways - You can't protect data you can't see. Business information stored in personal email accounts falls outside many corporate security, monitoring, and governance controls. - Personal email increases business risk beyond cybersecurity. It can create legal, compliance, recordkeeping, and continuity challenges in addition to phishing and malware risk. - Secure business communication requires both policy and technology. Organizations should provide secure, approved communication tools and make them easier to use than personal alternatives. "When is it OK to use personal email for business?" We’ve been getting different versions of this question for years. It’s based on the premise that using personal email is sometimes more convenient than logging into a company-controlled account. Multifactor authentication (MFA), location restrictions and other controls can be annoying when someone is traveling or pressed for time. The short answer to this question is ‘never.’ Personal email accounts introduce new pathways for attack into the business. They reside outside the control of corporate security controls, which means the company can’t monitor them for malicious messages, access and retention policies, suspicious sign-ins or account takeover (ATO) attacks. Personal email accounts are subject to credential phishing, malicious messages, tech-support scams, and many other attacks. While personal accounts may offer spam filtering and MFA, they usually don’t have robust capabilities of enterprise email security. Hudson Rock infostealer research on one corporate domain found thousands of employee-associated infections that exposed corporate authentication infrastructure and a myriad of credentials for consumer services like Netflix, Twitter, Dropbox and LinkedIn. This doesn’t reveal a causal relationship, but it does show that personal or mixed-use machines can expose both personal accounts and enterprise access. A single infostealer infection can lead to a massive data breach. What are the financial risks of using a personal account for business? Data is now one of the most valuable assets a company holds: customer records, financial information, intellectual property, operational communications, employee records, and vendor relationships all flow through email every day. When that data lives in systems your IT team doesn't control, you lose the ability to protect it, govern it, audit it, or recover it. IBM's research illustrates how high those stakes have become. In 2024, 70% of breached organizations reported that the breach caused significant or very significant disruption to their operations — and for those that did recover, the process took more than 100 days. Only 12% of breached organizations were able to fully recover at all. That’s only part of the picture. One study found that 65% of consumers lost trust in a company after a data breach, and 27% discontinued their relationship with the business entirely. Another found that breached companies underperform the NASDAQ by an average of 15.6% over the three years following a breach. This kind of research shows us that a breach can damage a company for many years. What are the legal risks of using a personal account for business? Allowing employees to use personal email accounts to conduct business means that your company's business information is being stored on mail servers outside of your control, anywhere in the world. You have no way of knowing all the places where your company data is stored, or where it’s been transmitted. And a personal email account is not covered by your company's security policies. Your employee may have agreed to Gmail’s Terms and Conditions (which allow for email content searches), but your company didn’t. You may have a good data privacy policy in place—but personal email accounts can bypass it with one click of the "Send" button. Understanding the risks and implications of using personal accounts for business is not always apparent until there are Freedom of Information requests, internal investigations, or eDiscovery. In all of these cases, those personal accounts may contain relevant information and as such have to be offered-up for search and retrieval. Even the act of discovery is difficult - Personal emails are not discoverable in standard legal discovery procedures. Google for example prohibits external scanning of users’ emails (several cases are currently under way), meaning the company will have to instruct the user to scan his or her email themselves and runs a big risk of spoliation sanctions. If the issue is regulatory, the company is likely to be found out-of-compliance. If an employee is using personal email accounts to send business related email using a company device, it doesn’t necessarily mean the organization has the right to search those emails. In the case of "Stengart vs. Loving Care," the New Jersey Supreme Court ruled that an employee "could reasonably expect that e-mail communication with (their) lawyer through her personal, password-protected, web-based e-mail account would remain private, and that sending and receiving them using a company laptop did not eliminate the attorney-client privilege that protected them." It could be very difficult to convince a requester or a court that all relevant information was discovered and produced - even if heroic (and expensive) measures were undertaken such as copying the individual’s entire mailbox to a company server for search and retrieval. And few users would agree to a complete copy of their personal email being held on their company’s servers. The solution might be obvious but companies still need to reinforce it First and foremost, setting strict policies against the use of personal email for business is the only course of action but despite all the reasons why company business should only be done through company email, users will still take the path of least resistance and use whatever email is most straightforward for them. The burden falls to the company, then, to make sure that the “path of least resistance” is the right path. Companies can be proactive and ensure that remote or field employees can easily access company email systems using their own devices. Webmail interfaces are easy to set-up, and any compliance capture will see and preserve those mails even when sent from a home pc, laptop, smartphone or tablet. When composing a new email, particularly on mobiles, employees need to be reminded to always choose the company email address, not their personal one. For non-employees such as contractors and consultants, the issue is the same. If the contractor or consultant is doing business on behalf of the company, then it’s a smart step to provide a company email address for them and enforce strict guidelines on using this is part of the arrangement. IT departments should always be able to retain central control and visibility of all emails being sent or received on the company’s behalf to avoid the problems that result from business being conducted from personal email accounts, but it does require some simple policies and an IT organization that is both proactive and persistent. The problem might not go away entirely, but it will be a nominal problem, not a big one. Barracuda offers a number of email and information management solutions to help organizations centralize and control their business data and minimize corporate and legal risk. Find out more about Barracuda security and data protection solutions at our corporate site here. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.