The CDO’s Key Role in Fighting Ransomware

3 min read

How bad is the ransomware problem?

More than one-third of organizations worldwide have suffered a ransomware attack or breach that blocked access to systems or data in the previous 12 months, IDC said in August of last year. FBI statisticsshow that these incidents have been increasing about 20% annually since 2020. That’s pretty bad.

Though the attacks vary in severity and type of organization targeted, they always have one thing in common. When malicious actors infect a computer or server, encrypt its contents to block access, and demand ransom in exchange for the encryption key, they’re holding hostage a company’s most precious resource: its data.

Given how crippling the loss of data can be — for example, the attack on Colonial Pipeline in late April 2021 that led to gasoline shortages on the East Coast — you’d think the chief data officer (CDO) would play a central role in helping protect sensitive data against ransomware attacks and in planning the response if their organization is targeted. But that often is not the case.

First, many organizations still don’t have a CDO (though I think all should). Companies increasingly have added the CDO position to the C-suite in recent years, but many holdouts remain. In fact, less than half of large organizations have a CDO, according to a 2021 Gartnersurvey.

Second, the role is still evolving. Consultancy NewVantage Partnersreports that 65% of companies now have a CDO, up from 12% in 2012, but less than half actually have primary responsibility for data. “Clarity on responsibilities, focus, purview, and reporting relationship remains in flux,” the report said.

Having a CDO benefits a company in several ways. In a time when data is often described as the new oil, an immense and extremely valuable resource, it simply makes sense to have a lead executive for managing and governing data across the organization and creating a data-driven culture that maximizes business results.

The increase in ransomware attacks only amplifies the case for a strong, focused CDO. Even after paying a ransom, the average victim recovers only 65% of their data. All in all, the averagecost for a US company in 2021 — including ransom, downtime, recovery, lost opportunity and data, IT, etc. — was $1.85 million.

Here are four ways a CDO, if given a seat at the table, can help guard against and minimize the impact of ransomware attacks.

As data flows into and across enterprises from all directions — customers, partners, vendors, internal systems such as marketing and HR, etc.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at informationweek.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.