Crown-jewel data protection

What is crown-jewel data — and how should you protect it?

Crown-jewel data is the information whose loss, theft, exposure or destruction could materially harm a company, an organisation or an individual.

What is crown-jewel data?

The small percentage of your information whose loss, theft, exposure or destruction would cause material harm — financially, legally, competitively or personally.

How do you identify it?

Ask one question of each data set: if this appeared publicly tomorrow, or vanished, what would it cost us? Anything with a serious answer is a crown jewel.

Where should it live?

Not in the same place as everyday work. Crown-jewel data belongs in a vault with narrow access and protection applied to the data itself.

The usual crown jewels.

Intellectual property and designs. M&A and deal material. Board minutes and papers. Source code and build secrets. Credentials and private keys, including bitcoin and other digital asset keys. Financial records and forecasts. Legal files and privileged correspondence. AI models and proprietary training data. Customer and patient information. Executive and family records.

Most organisations find the list is surprisingly short — a few hundred files that carry most of the risk.

A three-step programme.

First, inventory: name the files and the owner of each. Second, separate: move them out of collaboration platforms into a vault where nothing is shared by default. Third, verify: confirm retrieval works and integrity is proven, then review the inventory each quarter.

This is a project measured in days, not quarters, and it removes more risk than most multi-year initiatives.

A crown-jewel inventory checklist

  • Intellectual property, designs and research
  • Board papers, minutes and strategic plans
  • M&A, valuation and deal documents
  • Source code, build secrets and infrastructure credentials
  • Private keys, wallet backups and recovery phrases
  • Financial records, forecasts and audit files
  • Legal matters and privileged correspondence
  • AI models, weights and proprietary training data
  • Customer, patient and employee records

Questions people ask

How much crown-jewel data does a typical organisation have?
Usually a tiny fraction of total storage. That is what makes separating it practical.
Should private keys really be stored in the cloud?
Key material should never sit in an ordinary shared drive. A vault with no sharing surface and no single readable copy is a far better home than a folder in a collaboration platform.
Who should own the inventory?
Usually the CISO or general counsel, with named owners per category and a quarterly review.

Keep reading

Citadel by Secured2

Protect what matters most.

Citadel is accepted by a limited number of organisations each quarter. See the plans and start with the data you cannot afford to lose.

See pricing