
Organizations in heavily regulated industries such as healthcare and financial services will often prioritize data protection over uptime due to potential regulatory penalties or loss of customer trust. “If you’re a bank, you’d rather be down for a day, or even two days, and not have a data loss than be back up in 40 minutes and have a data loss, because your brand damage suffers,” Cardwell says.
The equation flips for companies that don’t hold especially sensitive data. Amazon, she notes, tokenizes credit card numbers, so a breach would expose only a customer’s name, address, and email — not financial or health information. “It depends on where you are on that spectrum of sensitive data … where your resilience meter is,” she says. “If you’re Amazon, you want to be up fast, because every minute is millions of dollars.”
Cardwell argues CISOs need to set explicit tolerances for data loss — what kind of data and how much of it — they are prepared to risk, not just how quickly systems come back online.
