Re-Air: Implementing Robust Data Protection Measures - Hans Vargas - Guardians of the Data - Ep #35

What is the first step in building an effective data security and data governance strategy?

In this re-aired episode, we revisit a powerful conversation with Hans Vargas, Enterprise Data Protection Lead at Marathon Petroleum Corporation.

Hans shares timeless insights on one of the most persistent challenges in data security: understanding what data actually matters and how to protect it effectively. From the importance of data discovery and classification to the realities of working with business stakeholders, this episode is a practical look at what it takes to build a strong data protection foundation.

As organizations continue to navigate cloud adoption, AI, and increasingly distributed environments, Hans’s perspective is just as relevant today as when this episode first aired.

Takeaways:
  • Know What You Need to Protect: Start with data discovery and identify what data you have, where it is, and what is sensitive. You can't protect what you don't know exists.
  • Engage Data Owners Directly: Build relationships with data owners, not just stakeholders. Have open conversations to understand what is truly sensitive and important to the business.
  • Communicate the Value of Data Protection: Clearly explain to business units why data protection matters, using relatable analogies if needed (e.g., moving houses, hoarding).
  • Establish and Strengthen Data Governance: Ensure your organization has clear data governance policies covering the entire data lifecycle from creation to disposition.
  • Collaborate Across Teams: Work closely with data governance, legal, and business units. Data security is a two-way street; share discoveries and insights to improve overall protection.
  • Don’t Rely Solely on Tools: Deploying a tool is not enough. Make sure processes and responsibilities are in place before or alongside technology adoption.
  • Consider the Full CIA Triad: Don’t focus only on confidentiality. Ensure data integrity and availability are also prioritized to keep the business running smoothly.

Quote of the Show:
  • “I argue that the conversation about the architecture of how to protect data should be one of the first things.” - Hans Vargas

Links:

Ways to Tune In:
Re-Air: Implementing Robust Data Protection Measures - Hans Vargas - Guardians of the Data - Ep #35
Broadcast by