By Shawn Diehl, VP Information Services & Support, Bunch CareSolutions, A Xerox Company and StrataCare, A Xerox Company
Business thought leaders who wave high the banner for big data tend to focus almost exclusively on the targeted outcomes for exploiting data and analytic capabilities. There is no question that the power of large data sets, when mined correctly, can be a game changer. Among the many benefits are accelerated and more intelligent decision-making, improved service delivery, and new revenue streams as the result of new product or service offerings or expanded sales opportunities.
Often overlooked are the custodial obligations and associated risks in the white water world of big data, including: infrastructure and information security costs for managing the various replicated data assets; costs of staying ahead of the fluid regulatory environments and the growing number of associated audits; accommodating increasing (and divergent) customer contract requirements related to big data protection and overall data retention; the risks and obligations that come from utilizing third-party value providers; and finally, the cost and effort of compliance with eDiscovery mandates.
In this two-part series focused on balancing the discussion around big data initiatives, we will look at the cost and risk continuum associated with managing large sets of customer data assets. Our first installment examines the technology and information security side of managing data assets, while our second one focuses on the regulatory and policy realities of data custodianship.
Infrastructure and Information Security Costs
The enormous amount of data being captured to fuel big data applications has obviously increased storage costs. Many standard data sets now include five or more replications of data that must be protected. Accompanying each of these data replications is the need to create and maintain technical and procedural approaches for managing, protecting and perpetuating them.

Figure 1: 5x Replication of Big Data
Beyond where the data is housed and managed internally, separate— equally stringent— technical and procedural approaches are needed. When managing data transmissions among multiple vendor partners, all elements of the service provider ecosystem must be considered. It is critical to remember that your value chain is as strong as its weakest link.
Growing Focus on Information Security and Privacy
Based on the increasing levels of financial and brand-related risks associated with managing large data sets that contain sensitive, customer-centric information, executives are becoming more risk averse, and understandably so. Standards of what constitutes acceptable risk for sensitive data and its protection are changing rapidly. Owners of these data assets are continually re-examining their data security standards and related programs, thereby placing ever increasing demands for data protection on their vendors. Consequently, there has been a clear shift from innovation to risk reduction in IT budgets.
Other signs of the times include:
- Increased demand (and cost) for experienced information security staff has made hiring and retaining professionals with this skill set increasingly more difficult.
- Increased targeting of standard management frameworks, such as ISO 27001:2, for data hosting and security programs aimed at data protection for audit credibility for, and acceptance by, customers and third-party value chains.
- Increased investment in data masking and obfuscation as a foundation for any data custodianship platform to provide protection for both testing activities and leveraging third-party (onshore/offshore) resources.
But the key challenge for a data custodian remains establishing a comprehensive data security program that can robustly address “al la carte” data security requests from customers.
When evaluating opportunities connected to big data analytics, it is essential to include a complete view of the related life cycle technology and the procedural costs associated with it. Likewise, it is prudent to assess whether your existing information risk management processes and support functions can keep pace—or will require augmenting to remain viable.
About Shawn Diehl
Shawn Diehl serves as the vice president of information services and support for Bunch CareSolutions, A Xerox Company, and StrataCare, A Xerox Company. He is responsible for the design, deployment and maintenance of infrastructure and information systems. He also leads the technology teams that are responsible for SaaS client implementations, application support and information security. Diehl has 20 years of experience within the IT industry and has earned the industry-respected ITIL, C|CISO, and CISSP certifications. He received his Bachelor of Science in business administration.
About StrataCare
StrataCare, A Xerox Company, offers comprehensive Internet-based national bill review software, workflow and outsourcing solutions to the workers’ compensation payer community. Based in Irvine, California, StrataCare’s innovative software and service saves billions of dollars annually for some of the industry’s top insurance companies, third-party administrators, managed care companies and self-insured employers.
About Bunch CareSolutions
Bunch CareSolutions, A Xerox Company, is a national medical management company based in Lakeland, Florida. The company operates exclusively in the workers’ compensation industry as a full service, managed care firm. Since its founding in 1988, Bunch CareSolutions has consistently grown in size, scope of services and standards of excellence. It has done so without compromising its clinical focus or mission of “making the world a better place—one life at time.”