Crisam Logo
  • CRISAM®
    CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Continuing education
    • Events
    • Customers
    • Webinars
  • Areas of application
    Areas of application
    • Information Security Management
    • Integrated Risk Management
    • Data Protection Management
    • Internal Control System & Audit Management
    • Business Continuity Management
    • Project Risk Management
    • CRISAM® Legal Hold Software
    • CRISAM® Compliance powered by Deloitte
    • ESG
    • DORA
    • Compliance Management
    • Tax Compliance Management System
    • Global Internal Audit Standards
    • SAT legal cadastre module
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
  • Industries
    Industries
    • Automotive
    • Energy
    • Health
    • Manufacturing
    • Finance
    • Trade
    • Real Estate & Construction Industry
    • Broadcasting & Telecommunications
    • Technology
    • Transport & Logistics
  • More
    More
    • Download Center
    • News
    • CRISAM® Partner
    • CRISAM® Academy
    • Jobs
    • Contact
  • en
    • de
Request
  • Sprache
    • de
  • CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Continuing education
    • Events
    • Customers
    • Webinars
  • Areas of application
    • Information Security Management
    • Integrated Risk Management
    • Data Protection Management
    • Internal Control System & Audit Management
    • Business Continuity Management
    • Project Risk Management
    • CRISAM® Legal Hold Software
    • CRISAM® Compliance powered by Deloitte
    • ESG
    • DORA
    • Compliance Management
    • Tax Compliance Management System
    • Global Internal Audit Standards
    • SAT legal cadastre module
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
  • Industries
    • Automotive
    • Energy
    • Health
    • Manufacturing
    • Finance
    • Trade
    • Real Estate & Construction Industry
    • Broadcasting & Telecommunications
    • Technology
    • Transport & Logistics
  • More
    • Download Center
    • News
    • CRISAM® Partner
    • CRISAM® Academy
    • Jobs
    • Contact
  • Request
Ilustration Cloud Computing

There’s a fire – how well protected is your data?

The fire at Europe’s largest data center OVH in Strasbourg on March 10, 2021 showed us all that the cloud also has its limits in terms of availability.

Natural disasters, fires or human error can never be completely prevented, but it is possible to take appropriate measures in good time to prevent a complete loss of data such as that suffered by some customers of the French cloud provider OVH. First, a brief review due to current events.

 

What is known about the incident on 10.03.2021 at cloud provider OVH?
  • According to the company, the fire completely destroyed one of the four data centers and partially destroyed another.
  • Data from 12,000 to 16,000 customers is affected (plus that of their customers).
  • On the morning of the fire, 3.6 million websites from 464,000 domain names were temporarily taken offline (according to the British data collector Netcraft).
  • On its website, OHV advises its customers to activate the Disaster Recovery Plan.

 

What impact can a complete loss of data have on a company?
  • In the event of irretrievable data loss (no backup available) or an impairment of availability, there is an acute need for action from a data protection perspective.
  • Notification of a data breach to the authority and, if applicable, the data subjects is necessary.
  • This results in unforeseeable damage to the company’s image, which may lead to a loss of sales and tie up resources in troubleshooting.
  • Depending on which data is affected, there can be a significant loss of knowledge and documentation in the company, which in turn can have legal and financial consequences.

Our aim is to inform our customers and suggest solutions on how they can approach the issue of data security in general and in particular when outsourcing to a cloud provider.

From our perspective as risk management experts, the most important rule is:

Understand the company and its risk acceptance
Our recommendation

We recommend that every company take a close look at this issue, because the consequences can be painful and an investment saved at one end in the area of information security can be expensive at the other. It is therefore worth taking a closer look at a few points in good time.

How can you answer the question of an effectively implemented risk management system for yourself? How can you answer the question of an effectively implemented risk management system for yourself? Do you know which information and IT systems could cause the greatest damage to the company in the event of a loss of confidentiality, integrity or availability? How much damage can the company cope with?

If you do not yet have any or only insufficient answers to these questions, we strongly recommend that you address these issues as part of a Business Impact Analysis (BIA). This creates the basis for a backup and restore strategy that is tailored to your company’s needs and allows you to take care of the design of the technical and organizational measures in the next step.

Regardless of this, it is ALWAYS advisable to have a data backup in a different location than just on a cloud server. A different location also means that the data is not located in the room/house next door, but that there is a geographical separation between the servers used. This should at least apply to the company’s most critical data.

With the CRISAM® risk management software, the relevant questions on risk assessments are already stored in the system. The advantage is that with CRISAM® you have an integrated risk management system that combines various disciplines and methods and allows you to check against the state of the art. This makes it easier for users to control the process and, above all, to evaluate and consolidate risks.

Do you need advice or have questions on this topic? We are here for you!

Sources:

OHVcloud
Heise
FAZ
Dataprotect

About the author

Over the past 15 years, Markus Müller has successfully set up risk and compliance management projects internationally and in practically all industries. Starting out as a consultant and now managing director of one of the leading software manufacturers (CALPANA business consulting GmbH) for integrated risk management solutions (CRISAM®), Markus Müller knows every problem that an organization can face when introducing an ISMS.

Geschäftsführer Markus Müller

No risk - let's just stay in touch!

Telefonsymbol in grün für Kontaktaufnahme.
Phone

+43 (0)732 601 216-0

Umschlag-Icon in grün, das den Versand von E-Mails symbolisiert.
E-Mail

office@crisam.net

Papierflieger in grün, der die Versandoption für E-Mails symbolisiert.
Newsletter

Register now

CRISAM GRC Software
Darstellung eines Trends im Risikomanagement

CALPANA business consulting GmbH

Blumauerstr. 43

4020 Linz, Austria

+43 (0)732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net

CALPANA business consulting GmbH

Blumauerstr. 43

4020 Linz, Austria

+43 (0)732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net
CRISAM®
  • What is CRISAM?
  • CRISAM® Method
  • CRISAM® Content
  • Events
  • Continuing education
Operational area
  • Information Security Management
  • Data Protection Management
  • Integrated Risk Management
  • Internal Control System & Audit Management
  • Business Continuity Management
  • Project Risk Management
Industries
  • Automotive
  • Energy
  • Health
More
  • Download Center
  • CRISAM® Partner
  • News
  • Contact

© 2023 CALPANA business consulting GmbH. All rights reserved.

  • Imprint
  • Privacy
linkedin
xing