A USB drive shows up where it does not belong. The break room table. The parking lot. A shipping envelope with no return address. Sometimes it has a label that makes it interesting: payroll, layoffs, bonus schedule. Somebody picks it up, and the very human next thought is “I should find out whose this is.”
That is the whole trick. It is decades old and it still works, not because your people are careless but because they are curious and helpful, the same traits that make them good at their jobs. Here is the thing though. The found drive is the dramatic version of this risk, not the version most likely to cost you money. The everyday one is your own team moving company files onto personal drives that nobody tracks and nothing encrypts. This post covers both and spends most of its time on what to do about them.
Why This Old Trick Still Works on Good People
Security training frames this as a failure of judgment. It is not. It is a predictable response to a small mystery. A stray drive creates an itch, and plugging it in is the fastest way to scratch it. The impulse gets stronger when the label suggests something sensitive, because now the finder feels responsible for handling it properly.
CISA describes negligence, the kind that comes from ignoring a policy rather than intending harm, as one of the unintentional insider threats organizations face, and names losing portable storage devices as an example. That framing puts the emphasis where it belongs. This is a habits problem, not a character problem, and you fix it with a rule that is easy to follow and an alternative that beats the risky option.
What an Unknown Drive Can Do to a Machine
Two things are worth understanding, and neither requires technical depth.
First, files on a drive are still files. If one is harmful and someone opens it, you have the same problem as a bad email attachment. That part is familiar.
Second, and less familiar: a USB device is not necessarily storage. When you plug something in, the device tells the computer what kind of device it is, and the computer generally believes it. Something shaped like a flash drive can announce itself as a completely different class of hardware, and the operating system treats it accordingly. That is why “I only looked, I did not open anything” is not the reassurance people think. The practical consequence: an unknown device connected to a company machine is an incident, not a curiosity.
The Everyday Risk That Costs More
Now the unglamorous part, which is where most actual damage happens.
Your estimator copies drawings onto a drive from a conference tote bag so he can work from home. Your bookkeeper moves a year of statements onto a personal drive because the file was too big to email. Somebody leaving takes a copy of the customer list, not maliciously, just because they built it. None of them think they are doing anything wrong.
Three things make this expensive. The drive is almost never encrypted, so losing it hands the data to whoever finds it. Nobody knows the copy exists, so if it walks out you cannot say what was on it, which is exactly what a client, insurer, or regulator will ask. And it never gets deleted, so it is still in a desk drawer three years later. Same pattern as unapproved cloud accounts, which we covered in our post on shadow IT.
A Policy People Will Actually Follow
Banning USB drives outright feels decisive and usually fails, because people still need to move large files and will find a way. A workable policy has four parts.
- Provide approved encrypted drives. Buy a handful of hardware encrypted drives, keep them somewhere known, and make them the only ones allowed to carry company data. NIST’s small business guidance points businesses toward encryption as the core protection for data on portable devices.
- Write one sentence about unknown media. Do not plug in any drive or cable you did not get from the company. Bring it to IT. That is the entire rule, and it fits on a sticker.
- Make the sanctioned path easier than the risky one. This decides whether the policy survives. If your file sharing platform makes sending a two gigabyte file to a client genuinely simple, nobody reaches for a thumb drive. If it does not, the policy loses. Fix the tool, then write the rule.
- Control the ports where it matters. Most business device management platforms can block or restrict removable storage on specific machines. Do it on the machines holding the data you would least like to lose.
Add one habit at the back end. When a drive is retired or reassigned, the data on it has to be dealt with. NIST published Revision 2 of its Guidelines for Media Sanitization in September 2025, defining sanitization as “a process that renders access to the target data on media infeasible for a given level of effort” and encouraging a defined program rather than case by case decisions. For a small business that means one written rule covering old drives, phones, and laptops, not a binder.
Someone Already Plugged One In
It happens. The response matters more than the mistake, and the most important part is that the person tells you quickly. If your culture punishes the report, you find out weeks later from something worse.
- Disconnect the machine from the network. Unplug the cable or turn off the wireless. Do not delete things or run cleanup tools, and avoid powering it off, because useful evidence lives in memory.
- Keep the drive. Set it aside, do not plug it into a second computer to investigate. That is how one affected machine becomes two.
- Call your IT provider immediately. Tell them what was plugged in, where it came from, what was opened, and how long ago. All four matter.
- Change passwords for that user from a different device. Especially email, banking, and anything with saved payment access.
- Thank the person who reported it. Out loud, in front of others if you can. You are buying every future report with how you handle this one.
The Bottom Line
The parking lot drive is a good story and a real risk, but the boring version is what drains value from most small businesses: company data walking around on unencrypted personal drives nobody is tracking. Both have the same answer. Give people a safe, easy, approved way to move files, state one clear rule about unknown media, and make reporting a mistake feel safe. Curiosity is not going away, and you do not want it to. The instinct that reaches for a mystery drive is the same one that questions a strange email, which is half the battle in why phishing keeps getting through.
If you want help setting up encrypted drives, sane file transfer, or device controls that will not make your team miserable, that is a short conversation. We work with small and mid-sized businesses across Denton County and would rather do this before an incident than after. Contact us today.
Sources:
Comments are closed