We're blaming the user for our mistake. That's like blaming the cow for leaving the pasture because one of us forgot to lock the gate.
The simple fact is that this user should have never been able to be in a position for this to happen.
Where were the IT security policies and procedures? Why was mission critical data on someone's c: drive? When (if ever) was the last audit?
We curse enterprise IT departments because they are so slow at getting things done, but they are really, really good at putting in place the things that would never allow this to happen. I have customers with strict policies regarding the protection of mission critical data, and I bet that none of it is as important as what was routinely put onto this laptop and paraded around town.
Public companies are responsible to their shareholders and the SEC. Private companies are responsible to their investors and creditors. Why weren't the same protections put in place to the trustees and taxpayers in this case?
Every nanosecond this researcher has to worry about performing routine IT overhead is a nanosecond not spent on critical research. The technological solutions to problems like this have been around for years. Why weren't they in place?
It's about time for IT to stop blaming the user and fix the problem.