---
title: "Why is data strategy a boardroom matter?"
description: "Data strategy decides on investment, accountability and risk. Why it belongs with executive leadership and what NIS2 and DORA expect of management."
canonical: "https://simo-online.com/en/knowledge/business-data-strategy"
---

# Why is data strategy a boardroom matter?

Data strategy decides on investment, accountability and risk. Why it belongs with executive leadership and what NIS2 and DORA expect of management.

Dargestellte Fassung: https://simo-online.com/en/knowledge/business-data-strategy

## Why is data strategy a boardroom matter?

Data strategy is a boardroom matter because it decides on investment, accountability and risk, not on technology. It defines which data supports which business decisions, who is accountable for that data and in what order to invest. Only executive leadership can answer those questions. In regulated sectors there is a further reason: NIS2 and DORA explicitly hold management accountable for information security and ICT risk.

- A data strategy is derived from the corporate strategy, not from IT.
- It links the most important decisions to the data they depend on.
- Governance defines roles such as data owners, rules and decision paths.
- It states benefits as targets that can be checked later.

### A management discipline, not an IT project.

A data strategy belongs with executive leadership, alongside financial and HR strategy. It starts with the decisions the company has to make over the next few years: where to invest, which markets to serve, which risks to take. For each of these decisions it clarifies which data is needed, at what quality and how current it has to be.

- That tells you which data really matters to the business. Not every data source deserves the same attention. A good data strategy sets priorities and is open about what will not be tackled for now. Delegated to IT, it becomes a list of tools. Led by the executive team, it becomes a steering instrument.

### What regulation expects of management.

In companies within the scope of NIS2, the management body approves the cybersecurity risk-management measures and oversees their implementation. In the financial sector, DORA explicitly places responsibility for ICT risk management with the management body. Neither can be demonstrated without clear accountability for data. A data strategy provides that clarity: who is accountable for which data and how decisions about it are made.

- In Germany, Section 38 of the BSI Act (BSIG) has implemented this duty since December 6, 2025: the management of important and particularly important entities implements and oversees the information security measures itself, takes part in regular training and is liable for breaches.

Rules that touch data accountability

- GDPR: accountability for personal data
- NIS2 and Section 38 BSIG: duties of management
- DORA: the management body's responsibility for ICT risk
- EU AI Act: obligations by the risk class of an AI system
- BCBS 239: risk data aggregation at banks

### A few pages that steer.

The outcome of a data strategy is not a thick concept paper but a leadership instrument of a few pages: the strategy itself, a governance model with clear roles such as data owners, and a roadmap with investment areas. The roadmap states the expected benefit as a target that leadership can check later. That keeps the strategy a management tool rather than a document that ends up in a drawer.

- A typical scenario: a financial services provider has to show its supervisor where the data in its risk reports comes from. The data exists, but nobody owns it. Together with leadership, the business-critical data domains are defined, data owners are named and evidence paths are described. The next audit request can be answered with documents that already exist.
- The scenario is typical of our engagements, not a single client case.

### How does a data strategy differ from an IT strategy?

An IT strategy answers which systems and technology a company works with. A data strategy answers which information supports which decisions and who is accountable for it. It comes before the IT strategy and gives it direction.

### Do mid-sized companies need a data strategy too?

Especially there. In a mid-sized company, a few people decide a lot, often under time pressure. A data strategy of a few pages makes sure those decisions rest on reliable numbers rather than on whichever report was finished first.

### Who implements the data strategy?

Your team, with clear roles. The data strategy names data owners and those responsible for data quality. SIMO supports the implementation if you wish, with the goal that your team carries it forward on its own.

Directive (EU) 2022/2555 (NIS2), Article 20

Regulation (EU) 2022/2554 (DORA), Article 5

Regulation (EU) 2016/679 (GDPR), Article 5(2)

Basel Committee on Banking Supervision: BCBS 239, Principles for effective risk data aggregation and risk reporting, 2013

ISO/IEC 38505-1:2017, Governance of data
