drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

The Value Of Data

While much has been written about the cost of downtime, IT and business professionals find little useful guidance on how to compute the value of their data, or more correctly, to determine the financial impact of data loss. And yet data loss remains a significant risk to organizations. A better understanding of data value and the impact of data loss will guide better decision making when selecting data protection solutions. The goal of this article is to help organizations estimate how much money they will lose if they lose data. The article outlines the major components of data value and the major factors that increase or limit the financial risk from data loss. After reviewing these components and factors, every organization should be able to define for themselves the value of their data and estimate the financial and human impact of data loss.

Four Components to Financial Risk and Data Value

In order to calculate the financial risk of data loss, four major components must be evaluated. These are:

  1. the financial impact of downtime caused by data loss

  2. the cost of reconstructing lost data

  3. the value represented by data that can’t be reconstructed

  4. the impact of a data loss on an organization’s reputation

Downtime

The first component of risk and data value is the lost data’s impact on downtime. Almost anytime there is a disaster and a failover, there is downtime, and when there is also data loss, the downtime can be significantly prolonged. The excessive downtime occurs because when data is lost, additional repair operations may have to take place including, in some extreme cases, restoring data from tapes. Fortunately, even if it is prolonged, the cost of downtime from data loss is relatively simple to calculate after the disaster occurs.

For sales applications, the cost of the downtime is the value of the sales that didn’t occur because the application was down. If the application takes two hours to restore, then the organization will lose two hours of potential sales. Some of those sales might simply be deferred, assuming a customer is willing to return at a later time, but many will not, and the sales will be lost forever.

For other applications, the cost of downtime can be measured in lost productivity. If the application supports design, development, manufacturing or operations, for example, then the cost of the downtime associated with data loss can be calculated by multiplying the hourly cost of the labor times the number of hours the application was down. To this, risk managers should also add the value of sales that didn’t occur because the organization could not design, develop, or make the product or deliver the service to fulfill an order. This risk is particularly high when customers have options as to what or where they buy and where customers have requirements that are time-dependent or must be satisfied quickly.

The financial risk associated with data-loss downtime varies widely from industry to industry and application to application. And while financial impact does vary, there are limits on the magnitude of the loss.

Data Reconstruction

The second component of financial risk in data loss is the expense incurred to recreate the work product contained in the lost data. For sales transactions, this may mean the cost of researching and re-entering lost orders. If there is any locally-stored paper trail, this may be relatively straight-forward. But in today’s mostly electronic world, reconstructing from a paper trail may not be an option.

In the case of data loss associated with design or development applications, the cost of the data loss would include the amount of labor associated with the recreation of the lost data. For example, if an organization has 20 engineers developing a software application, and they lose the last hour’s work, then the cost of data reconstruction is 20 engineers for one hour.

Data Representation

The third component of financial risk in data loss is the value of unrecoverable data. Without synchronous replication some data will be lost and unrecoverable. In these situations, organizations need to evaluate the value of what the data represented. This is most important in financial transactions.

In sales applications, organizations can make a reasonable estimate of the financial impact of data loss by knowing their average revenue per transaction and their average transactions per hour. This can be further refined and made more precise, if the organizations have some knowledge regarding how transaction value and volume fluctuate by time of day, day of week, day of month, and day of year.

Reputation

The final component of financial risk in data loss is the loss of reputation. In particular, if an organization suffers a negative impact to their reputation due to data loss, they may lose a customer for life. In this case, then, the financial impact of data loss includes the life-time value of every customer that stops conducting business with the organization, plus the life-time value of every potential customer that the organization fails to win, because the organization’s reputation has been damaged.

This risk to reputation need not always be associated with the customer’s money. A professional money manager who fails to arrive on time for an appointment because he lost calendar data may have as much reputation risk as an organization that lost a few minutes of sales transactions. A lawyer that loses a document may appear incapable of performing their fiduciary responsibilities. A financial institution that loses security and log-in information may create frustrated clients when they can’t log into online banking applications, even if no banking transactions were lost.

The bigger the disaster and the more broadly the disaster is experienced across organizations, then the more likely the customers will forgive the data loss as an unavoidable event. Most data losses, however, occur from localized events, not from major natural disasters. If the data loss is, in fact, localized to a single organization, then the risk to the organization’s reputation is greater. Localized data losses make organizations appear slipshod in their operational processes.

Within an organization, if the data loss is associated with a single customer’s data, then the impact may be relatively small. However, the more data an organization loses, the more likely the loss will impact multiple customers. Social media can create a negative multiplier effect on an organization’s reputation, particularly when losses affect many customers.

Five Factors Influencing Value

Beyond the components of risk identified above, there are several factors that magnify or minimize the impact of the risk components. Some will vary by industry, while others are factors found in every modern IT operation.

Time Dependency

There is a class of data the value of which is entirely time-dependent. This data has no value after a disaster. Dispatch systems are one good example. Imagine a taxi dispatch system that goes down and loses 5 minutes of data and takes 30 minutes to restore the applications and data. The taxi company will lose revenue from the downtime, but from the point of view of the people waiting for taxis or for the company dispatching taxis, there is absolutely no value knowing who was waiting for a taxi or where taxis were 30 minutes ago. By the time the application is restarted and the historical data restored, the individuals will have made other arrangements, and the taxis will have moved.

Another example is that of a newspaper. If a newspaper production system fails at the wrong time and data is lost, the result will be no newspaper the next day. There will be tremendous losses from the downtime, mainly due to lost advertisement revenue. However, the data for the newspaper articles will have no value, if it is recovered the next day. It will be yesterday’s news.

Range of Values and Frequency of Transactions

In transaction systems, the financial risks associated with data loss are dramatically impacted by the range of potential values and the frequency of transactions. At the low-end of value are applications that maintain cell phone call detail records. In the aggregate, they are valuable, but the range in values of an individual call is not significant. A carrier might thus be more than willing to lose a few 1000 transactions, because the value of each individual call is very low, and few customers are likely to complain that they weren’t charged enough.

Retail organizations have a broader range of transaction values and transaction volume and may be less willing to suffer the impact of lost data. As an example, an electronics retailer knows that the day after Thanksgiving both transaction value and transaction volume increase dramatically. Five minutes of data loss on the day after Thanksgiving would have much more impact than five minutes of data loss on Jan. 15. And lost data would make it difficult, if not impossible, to process returns, thus leading to customer dissatisfaction.

In other industries, transaction values and volume can have an even greater range of potential values than retail and may have a less predictable cycle. In commodity and stock exchanges, transactions can be valued at a few thousand dollars or multiple millions. And high transaction volume and high-value transactions can occur any day that the exchange is open. A single lost transaction could be sufficient to bankrupt a smaller organization. And five minutes of lost data on the wrong day could bankrupt many mid-sized financial institutions.

Completeness

In some applications, the need for data completeness increases the data-loss cost component of data reconstruction. Remember that the cost of data reconstruction is the amount of labor required to recreate lost data.

Inventory and financial accounting applications often require that data be exact. A manufacturer that doesn’t have an accurate inventory may shut down a factory if they fail to reorder necessary parts or materials. When an organization loses inventory data, they aren’t losing the inventory of a single known item. They don’t know what they’ve lost, so they have to check everything by completing a physical inventory of the entire warehouse. This exercise in data recreation will be far more costly than the time originally spent to enter the inventory transactions.

Application Consistency

Some data, while not inherently valuable, is absolutely necessary in order for applications to operate. Virtualized environments are particularly vulnerable. A prime example is a VMware environment supporting application servers, where the application servers talk to each other. These servers have to have access control, which is kept in an access control database. If a disaster happens at the same time as the access control system is being updated, then the correct access control data will not be in the remote site, and the applications at the remote site will not be operational.

Other operational information needed at a recovery site includes server and network configuration data, authentication server and router information. If everything is synchronized then recovery should be straightforward. But if credentials change before the data is replicated, and then a disaster occurs, suddenly at the remote site you may bring up systems and not be able support such things as passwords and configurations.

Data that Impacts Life

There is one special category of data for which the cost of data loss is not measured in dollars, but rather in lives. Those who operate in these industries know the applications, the value of the data, and the potential impact on life. In medicine, these include medical records that list life-threatening allergies, radiological images needed for surgeries, and records of prescribed medications in order to avoid dangerous drug interactions or overdoses. In security and defense applications, these include databases of known felons and suspected terrorists. In these applications, the loss of a single bit of data may result in the loss of life. Of course, there will also be a financial impact from this type of data loss. It may be seen in the form of legal costs and settlements, in higher insurance premiums, and most certainly in the impact on the organization’s reputation.

Conclusion

Recent research has shown that organizations significantly underestimate the time needed to recover applications and data in the event of a disaster. This may be due, in large part, to a misunderstanding of how complex the recovery process can be when data is incomplete or has to be reconstructed. No matter how rigorous the analysis, because of the nature of disasters and the fact that disasters don’t typically happen in isolation, the true value of data and the true cost to recover will only be known after the disaster.

One thing is certain. However, synchronous replication provides faster, more predictable application recovery time and eliminates the risk of data loss. Organizations can only determine whether an investment in synchronous replication is justified by understanding all of the risk factors and costs associated with data loss.

Dr. Alex Winokur is the CTO and co-founder of Axxana, and a recognized innovator in data management, data protection, and storage. He spent 11 years in the IBM research division, achieving the prestigious IBM master inventor title and authoring or co-authoring more than 15 patents in storage, network management, and telecommunication areas. Dr. Winokur has a rich systems engineering background and a proven record of developing high-performance, high-availability storage subsystems. He is a strong leader with an established record of building research and development organizations. Prior to co-founding Axxana, Dr. Winokur was the CTO of XIV Information Systems (acquired by IBM) and the founder of Sepaton (Formerly SANgate), a successful startup company in the area of Storage Area Networks (SAN).

Dr. Winokur holds B.Sc. and M.Sc from the Technion, Israel’s Institute of Technology and a Ph.D. from Penn State University.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.