The past five years have shown us an incredible increase in the amount of data being generated. We have seen the Internet of Things combine with fast communications and cheap storage. The result is a deluge of data that has to be protected; with new challenges come new solutions.

Today we sat down with a veteran in data protection, Aaron Lewis. He shares with listeners lessons learned from decades of his involvement in data protection. He focuses on three ideas that involve data: classification, mapping, and recovery.

He starts with you understanding the data itself. The adage, “If you protect everything you protect nothing” applies here. A system administrator must be able to separate sensitive, classified, and top-secret information. Effort should be placed on the most valuable data.

Data mapping sounds like a simple task. Well, at one time it was. Today a system may be attacked when data is residing in many locations. Aaron reminds us that in a modern enterprise, you may see data on the wrong network. It could be in a chat tool, like Slack. If you just protect data that sits in your network, you will be vulnerable.

Mike Tyson famously said that everyone has a plan until they are hit in the face. However, Aaron points out that many federal leaders may not even have a plan. If they do, it is sitting on a shelf. Some have called this “shelfware.”

To be able to effectively defend data, one should have a current plan that is living. Aarons says that a plan is not a plan unless it has been tested. He recommends a disaster recovery plan that responsible parties rehearse.