Skip to content

Information Management - Document Release Guidance

  • Knowledge Level: All Levels
  • Protection Stage: All Stages
  • Time to read:

This short document illustrates a ‘4 Step Publication Approach’ aimed at helping those preparing documents for electronic publication to a wide community, including publicly accessible websites and document servers

Last Updated: 21 September 2026
Share this article:

Publishing documents without compromising information security

Most documents published by organisations are re-leased electronically, even on those occasions where a printed version is also produced. However, a number of examples have been identified where these elec-tronically published documents contain unintentionally included sensitive data. While this was not immediately visible to the drafter or the eventual readers, this data was discoverable by commonly used search engines and by individuals motivated to take a deeper look.

Work undertaken to understand how these incidents occurred found two common characteristics:

  • documents are being prepared close to a deadline; and
  • there is a desire for the document to be compelling and therefore it is rich in diagrams and other imagery.

These two factors can be a recipe for incorporating material that may be more detailed than needed or could inadvertently contain embedded information that isn’t immediately apparent. If this information is sensitive it could be commercially or operationally damaging or in extreme circumstances, compromise national security. Even in circumstances where there is no di-rect financial or security loss – there can be personal or corporate reputational loss to the author and publishing organisation. It is important therefore to consider adopting a mindset that a ‘publication’ of a document is a ‘release’ of information which requires a guiding process.

This short document illustrates a ‘4 Step Publication Approach’ aimed at helping those preparing documents for electronic publication to a wide community, including publicly accessible websites and document servers.

Example 1

On transferring charts, as graphics, from a spreadsheet, a lot of commercially sen-sitive data was transferred with them.  It became embedded in a high-profile pub-lished document in a manner that wasn’t visible to the reader. However, it was indexed by search engines and the origi-nal technical information was recoverable from the published document. 

Develop and implement a document preparation and release process

A document preparation and release process should be developed and implemented alongside the necessary mechanisms that will make it easy for people to imple-ment. The process should include each of the 4 steps set out on the right. These light-touch elements enable any risks that may relate to specific documents to be identified and addressed.

4-Step Publication Approach

  1. Consider the information risk
  2. Prepare documents defensively
  3. Check before publication
  4. Respond to incidents 

Step 1: Consider the information risks

The information and material that will be contained in the publication should be established and then assessed to determine whether any aspects of it are sensitive and therefore could constitute a risk to the organisation, its assets, services, or clients or to individuals or communities.

Sensitive information includes that which can:

  • adversely affect the privacy, welfare or safety of an individual or individuals;
  • compromise intellectual property or trade secrets of an organisation;
  • used to significantly compromise the integrity, safety, security and/or resilience of an asset, product or service, or its ability to function;
  • cause commercial or economic harm to an organisa-tion or country; and/or
  • jeopardise the security, internal and foreign affairs of a nation.

It also encompasses:

  • licensed data not authorised for release;
  • information system and cyber-security measures that shouldn’t be disclosed in the document (e.g. internal network URIs, file server information, file paths, inter-nal document identifiers, etc); and
  • data introduced by the editing and publishing process and tool(s).

Some risks may warrant specific action, such as seeking authorisation to release specific material or involving rel-evant parties in the document release process. The need for, and occurrence of these actions should be noted and retained as part of the publication process.

This is the right time to consider if exposing details, or making use of source data that may contain a lot of detail, is necessary. While it can be tempting to include details to increase impact or to reinforce a general point, such information may be useful to others such as those motivated to conduct investigations (such as online re-connaissance) that amplifies some of the listed risks.

Example 2

Proprietary technical information about a major part of the UK’s transport in-frastructure was imported into a doc-ument along with some images. This data wasn’t visible to the reader but was found by search engines and provided seed material for further compromising online research.

Step 2: Prepare documents defensively

The ease with which rich media, containing more than intended, can be imported has led to several security breach incidents. In addition, metadata (data about data) which includes user and organisational information, and information such as internal file paths and URLs, that may also present risk, have been found in several electronically published documents.

The aim of preparing a publication defensively is to reduce the risk of transferring sensitive data from the source text, graphics and imagery to the final document. This can be done by avoiding copying and pasting source media directly. Instead, the source media should first be transformed into a format that doesn’t contain the types of information which are not immediately apparent to the author or reader, but which can lead to the risks and potential impacts described.

The ability to convert copied sections of source files before inserting them into a destination document is generally offered in most applications.

Source Material

Basic Conversion

Import to final document

Transform extracts to safer format:

  • Plain text

  • Basic images with appropriate resolution

  • Clean tables

  • Check before next step 

For many documents this is simply a matter of pasting the selected extracts from source material as an image or as plain text. It can be useful to do this in an intermediate, clean document before subsequently copying into the final document. Maintaining a copy of theses transformed items can minimise the temptation to revert to the source material for updates or when images and tables need to be reused.

A quick check of the transformed material can be done easily before being imported to the final document. An additional benefit of this approach is that it can signifi-cantly reduce the file size of the final document.

The defensive approach also assists in the production of documents that have redacted elements, by avoiding reliance on an application’s redaction features alone if the integrity of the redaction is paramount.

Example 3

In January 2021 a high profile document was shared publicly by the European Commission during the tense period of early Covid-19 vaccine introduction. While it was heavily redacted for contrac-tual reasons, it wasn’t long before many of the redacted sections were revealed in the document. The error was subse-quently admitted by the EU but generat-ed significant, unwanted, press coverage.

Step 3: Check before publication

The document should be checked by someone other than author to confirm that it necessary risk mitigation and defensive actions have been taken. This check should establish whether any sensitive data has been introduced by the tools used to create the final document.

The occurrence of these checks and their findings should be documented and retained.

Step 4: Respond to incidents

If it is discovered that data that poses a risk has been released unintentionally, is better to act responsibly - don’t assume that it won’t get noticed by others if it hasn’t already been. Once a vulnerability is identified in one document, experience shows that a hostile party is likely to investigate other potential sources of information, for example from other published documents, and if success-ful, begin to aggregate them. This can lead to discovery of other information weaknesses and result in cyber-security compromise or other malicious action.

In some circumstances, addressing an incident may involve notifying parties that may have been affected in addition to taking remedial action on the documents themselves. Risk-based decisions may be required to manage the existence of copies of documents under the control of third parties that are easily accessible.

Software-specific advice

The following table lists some application-specific guid-ance. They do not replace the process and advice in this document, but they may help users find out practical meas-ures to mitigate some of the risks identified. They may be subject to change and are not endorsed as being effective against all risks. Acting defensively comes before rely-ing on tool-specific mitigations. Examples 1 and 2 above would not have been addressed by following the advice in these links alone.

Did you find this page useful?
helpfulness rating