Definition
Data loss is any situation in which data becomes inaccessible, corrupted or destroyed, either temporarily or permanently. It can result from a cyberattack, particularly ransomware, hardware failure, human error, malicious deletion or a physical disaster.
Main causes
- Ransomware and cyberattacks: encryption or destruction of data, including backups. In Sophos's 2024 report, 94% of attacks involved an attempt to compromise backups.
- Hardware failure: failure of a disk, storage array or server.
- Human error: accidental deletion or incorrect handling.
- Physical disaster: fire, flooding or theft.
Consequences
- Operational downtime: every hour of disruption has direct and indirect costs.
- Recovery costs: rebuilding, staff time and sometimes ransom demands.
- Regulatory exposure: notification duties under the GDPR and continuity requirements under NIS2 or DORA, with possible sanctions.
- Damage to reputation and trust among customers and partners.
Design for recovery
Risk cannot be eliminated completely. Recovery planning should therefore include disconnected backups, fast and tested recovery, and coverage of critical workloads. The 3-2-1-1 rule structures those copies, including one that is offline or protected from rewriting.
