How 'we need a data strategy' almost always means three different things to three different executives—and the technical strategist who doesn't force that disagreement into the open before writing a plan ends up authoring a document that satisfies no one

Three executives asked me for a data strategy in the same month, and for a while I believed they had asked me the same question.

The CFO wanted the data platform bill to stop growing faster than the business. Snowflake credits, Databricks units, hundreds of pipelines nobody has audited in two years. Flexera's 2025 survey found 84% of cloud professionals rank managing spend as their top challenge, third year running.

The Chief Product Officer wanted more experiments per quarter and models out of notebooks and into the product. To her, a data strategy meant fewer approval gates and more copies of the data, close to the teams doing the work.

The CISO wanted lineage, classification, and access control, partly because of EU AI Act obligations landing this August, and partly because IBM's 2024 breach report found about a third of breaches involved shadow data, costing roughly 16% more and taking about a quarter longer to find.

Write one document for all three and the conflict shows up immediately. The copies the CPO needs are the copies the CFO is trying to kill and the copies the CISO cannot see. Every good thing one of them wants takes something from another. DalleMule and Davenport called this offense and defense in 2017, and their sharpest line is the one people skip: it is unwise to default to a 50/50 split. Somebody has to choose.

I went looking for the statistic everyone repeats, that most enterprise data strategies are abandoned inside eighteen months. There is no primary source I could find, so I am not passing it along. What I found instead is more useful. Gartner predicts 80% of data and analytics governance initiatives will fail by 2027, for want of a real or manufactured crisis, which is a polite way of saying nobody agreed on the problem. MIT Sloan studied 124 organizations and found only 28% of the executives responsible for executing strategy could name three of their company's strategic priorities, while the senior teams above them were sure they were aligned. The Project Management Institute puts 47% of unsuccessful projects on inaccurate requirements. And average CDO tenure is about two and a half years, so a restart every couple of years is close to structural.

So before I open a single diagram, I do something boring. I ask each executive to write one sentence, alone, without seeing the others: what problem should this strategy solve. Then I read the three sentences out loud in the same room. Usually I get "cut our cloud spend," "ship models faster," and "survive the audit," and everyone laughs nervously, because they had assumed they were working on the same thing.

That disagreement is the deliverable. The rest of the meeting is spent making each person say what they will give up, out loud, with a number attached.

I can draw a lovely architecture. I have never seen a lovely architecture rescue a plan that three people quietly disagreed with.

"We Need a Data Strategy" — Research Overview: The Three-Executive Collision

Raw research material for a LinkedIn post. Objective overview with sources, provenance notes, and verified-vs-zombie flags. Current as of July 2026.

TL;DR

  • When executives say "we need a data strategy," a CFO typically means cost rationalization (rein in the Snowflake/Databricks bill, kill duplicate pipelines, monetize dark data), a CPO means faster experimentation and ML velocity (self-serve analytics, models in production, shorter time-to-insight), and a CISO/CDO means governance, lineage, and control (compliance, breach risk, auditability). These three agendas actively trade off against one another, and the strategist who doesn't surface the disagreement first will write a document that satisfies none of them.
  • The failure numbers are large and real, but several famous ones are "zombie statistics": the "85% of big data projects fail" line traces to a since-deleted tweet, "87% of data science projects never reach production" traces to an un-sourced opinion piece, and no primary Gartner source exists for the claim that "X% of data strategies are abandoned within 18 months." The soundly-sourced evidence points to problem definition and executive alignment — not architecture — as the dominant failure mode.
  • Independent research converges on the thesis: only 28% of executives can name their own company's strategic priorities (MIT Sloan), 47% of failed projects fail on inaccurate requirements (PMI), and Gartner's own diagnosis of why governance programs fail is "a lack of a real or manufactured crisis" — i.e., no agreed-upon problem to solve.

Key Findings

1. The three-executive collision is real, and there's an authoritative framework for it

The best framework-level articulation is Leandro DalleMule & Thomas H. Davenport, "What's Your Data Strategy?" (Harvard Business Review, Vol. 95, No. 3, May–June 2017, pp. 112–121). They split data strategy into two orientations:

  • Defense — "ensuring data security, privacy, integrity, quality, regulatory compliance, and governance"; data-management orientation = control; enabling architecture = a single source of truth (SSOT). (This is the CISO/CDO agenda.) [1]
  • Offense — "improve competitive position and profitability" through analytics, modeling, visualization, transformation and enrichment; orientation = flexibility; enabling architecture = multiple versions of the truth (MVOTs). (This is the CPO agenda.) [1]

Their central, quotable claim: "Devoting equal attention to offense and defense is sometimes optimal, but in general it's unwise to default to a 50/50 split." Firms must make an explicit trade-off based on their industry, competitive position, and regulatory exposure. The article also supplies two memorable supporting stats: "less than half of an organization's structured data is actively used in making decisions—and less than 1% of its unstructured data is analyzed or used at all," and "more than 70% of employees have access to data they should not." The framework was built on DalleMule's experience as CDO of insurer AIG plus study of roughly a half-dozen other large firms. [2][1]

2. Failure statistics: verified vs. zombie (provenance matters here)

This is the section the requester specifically asked to be careful about. Findings:

StatisticVerdictActual provenance
"85% of big data projects fail"Zombie / weakly sourcedGartner analystNick Heudeckersaid Gartner's earlier 60% estimate was "too conservative" and the real rate was "closer to 85%" — in asince-deleted tweet (2017), quoted in TechRepublic. Not a formal Gartner study. Frequently mutates into "85% of AI projects fail" or "85% of data science projects fail," which are further-degraded versions.
"87% of data science projects never make it into production"ZombieTraces to aVentureBeat article (2019)about a Transform 2019 panel where IBM's Deborah Leff cited a2017 CIO Dive opinion piece("a mere 13% … reach completion") that provided no source or research.
"Through 2022, only 20% of analytic insights will deliver business outcomes"Verified (Gartner)Gartner "Top Data and Analytics Predicts for 2019," analystAndrew White, published Jan 3, 2019 (Gartner analyst blog / "Predicts 2019" research — legitimate, but a notch below a formal press release).
"80% of D&A governance initiatives will fail by 2027"Verified (Gartner)Gartner press release,Feb 28, 2024, VP AnalystSaul Judah: failures due to "a lack of a real or manufactured crisis." "A D&A governance program that does not enable prioritized business outcomes fails."
"X% of data strategies abandoned / restarted within 18 months"No primary source found — treat as apocryphalAppears to be a conflation of the Gartner governance-2027 stat above with Gartner's Feb 2025 prediction (Roxane Edjlali) that "through 2026, organizations will abandon 60% of AI projects unsupported by AI-ready data." Donotattribute an "18-month data-strategy abandonment" figure to Gartner.

Digital-transformation "70% fail" caveat: the ubiquitous "70% of digital transformations fail" line is itself contested. McKinsey never measured a 70% failure rate; BCG's 2020 "Flipping the Odds of Digital Transformation Success" found 70% fall short of objectives — but broke down as 30% fully succeeded, 44% created some value but missed targets, and only 26% created little or nothing, scored via executive self-assessment across ~70 companies. BCG separately reports only ~35% of digital transformations reach their goals (analysis of 850+ companies). Use with the nuance intact.

3. Executive misalignment / problem definition as the real root cause

This is the empirical backbone of the thesis:

  • MIT Sloan Management Review — Donald Sull, Charles Sull & James Yoder, "No One Knows Your Strategy — Not Even Your Top Leaders" (2018): "Our analysis of 124 organizations revealed that only 28% of executives and middle managers responsible for executing strategy could list three of their company's strategic priorities." The same research documents that top teams systematically overestimate their own alignment. In one example company ("Generex"), 97% of senior leaders claimed clear understanding of priorities — yet the objective alignment test failed. [3][4]
  • PMI, Pulse of the Profession: Requirements Management (May 2014, survey of 2,000+ practitioners): "nearly half (47 percent) of unsuccessful projects fail to meet goals due to inaccurate requirements management." (An earlier PMI figure was 37% in 2013/2014 as the "primary cause"; the 47% figure is the share of unsuccessful projects whose failure is attributed to requirements.) PMI also reports organizations waste ~US$122M for every US$1B invested due to poor project performance (2016). [5]
  • Gartner's governance diagnosis is itself a problem-definition argument: Judah's prescription is to stop the "center-out, command-and-control approach" and "rescope … governance to target tangible business outcomes." A governance program without an agreed business problem fails — which is exactly the report's thesis in Gartner's own words. [6][6]
  • Supporting alignment stats (lower-tier / secondary sources, use with care): only ~10% of managers believe all their org's strategic priorities have the funding, people and support to succeed (MIT Sloan); LSA Global claims aligned organizations grow revenue 58% faster (study of 410 companies).

Details

CFO lens — cost rationalization of data infrastructure
  • FinOps for data has gone mainstream and is now dominated by AI/data-cloud spend. The FinOps Foundation's State of FinOps 2026 found 98% of practitioners now manage AI spend, up from 31% two years earlier, and formally expanded the FinOps framework to add "data cloud" scopes covering Snowflake and Databricks.
  • Cloud cost is the No. 1 pain point. Per the Flexera 2025 State of the Cloud Report (published March 19, 2025; survey of more than 750 cloud professionals), 84% of respondents rank managing cloud spend as their top cloud challenge — the No. 1 spot for a third consecutive year. [7][8]
  • Consumption pricing is structurally hard to govern. Snowflake bills in "credits," Databricks in "DBUs," BigQuery in "slots" — abstractions that sit between technical activity and financial outcomes. The FinOps Foundation's Data Cloud Platforms Working Group warns that warehouse-level cost visibility "rarely explains actual spend," and Flexera notes idle-resource governance can prevent "10x cost overruns" before any advanced optimization. Finance wants predictable budgets; engineering wants fast queries — the same offense/defense tension in dollar terms.
  • Dark data = wasted spend + risk. Gartner has long compared dark data to "dark matter," estimating that on average more than 50% of a company's data is dark (industry range 40–90%). A Splunk-cited figure puts organizational dark data at ~55%. The Veritas Global Databerg Report (press release March 15, 2016; survey of 2,550+ IT pros across 22 countries) found that 52% of all information stored by organizations worldwide is "dark" data of unknown value, with a further 33% classified as redundant, obsolete or trivial (ROT) — meaning only ~15% was identified as business-critical. Seagate's "Rethink Data" report separately estimated only 32% of available enterprise data is put to work. [9]
  • Tool/pipeline sprawl (directional, vendor-sourced): the Fivetran 2026 Enterprise Data Infrastructure Benchmark (survey of 500+ senior data/tech leaders at orgs >5,000 employees) reports enterprises manage an average of 328 data pipelines (400+ at the largest orgs), breaking an average of 4.7 times per month. The oft-repeated "13 copies of every dataset" claim is a zombie stat (VAST Data itself hedges it as "reportedly") — avoid citing as fact. Note that Gartner does publish authoritative D&A-share-of-IT-budget benchmarks (IT Key Metrics Data; D&A Budget & Efficiency Benchmark), but the specific percentages sit behind Gartner's paywall. [10]
CPO lens — experimentation velocity, self-serve analytics, ML in production
  • Being "data-driven" remains rare and has even declined. NewVantage Partners (now a Wavestone company) has run the benchmark survey of Fortune 1000 data executives since 2012. Self-identification as "data-driven" fell three years running early on — 37.1% (2017) → 32.4% (2018) → 31.0% (2019) — and the 2021/2023 readings put those "created a data-driven organization" at ~24% and "developed a data culture" at ~21%. Consistently, ~92% of executives attribute the principal barrier to people, business process, and culture, and only ~8% to technology. Only ~30% reported having a well-articulated data strategy (NewVantage, via Forbes). [11]
  • Insight rarely converts to outcomes. Gartner (Andrew White, 2019): "Through 2022, only 20% of analytic insights will deliver business outcomes." [12]
  • Governance-vs-velocity is the live battleground. Multiple practitioner sources (Acceldata, Qlik, Atlan, Promethium) describe the same failure loop: heavy centralized approvals slow AI experimentation → teams build shadow pipelines and duplicate data marts to move faster → complexity and risk increase. The recommended resolution — a "thin" governance layer, separating easy exploration from controlled publishing — is itself an argument for defining which problem (speed or control) the strategy is optimizing for. Forrester frames the upside of getting this right: "insights-driven businesses" were projected to grow ~27–30%+ annually (vs ~3.5% global GDP), reaching ~$1.2T by 2020; advanced insights-driven firms are "nearly three times more likely" than beginners to report double-digit growth. [13]
CISO/CDO lens — governance, lineage, controls, regulatory pressure
  • Breach economics tie directly to poor data governance / shadow data. IBM Cost of a Data Breach 2024 (19th edition; Ponemon research across 604 organizations; released July 30, 2024): global average breach cost hit a record US$4.88M, up 10% YoY. 35% of breaches (1 in 3) involved shadow data (data in unmanaged sources); those breaches "correlate to a 16% greater cost" and took 26.2% longer to identify and 20.2% longer to contain. 40% of breaches spanned multiple environments (avg >US$5M). Healthcare remained costliest at US$9.77M; the US remained highest by country at US$9.36M. [14]
  • Regulation is a forcing function. DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) reached full applicability January 17, 2025, mandating ICT risk frameworks, asset inventories, and 24-hour incident notification, with fines up to 2% of worldwide turnover and personal fines for senior managers. The EU AI Act (Regulation 2024/1689) phases in obligations: prohibited practices since Feb 2, 2025; GPAI obligations since Aug 2, 2025; high-risk system obligations (including explicit Article 10 data-governance requirements on training/validation/test data) from Aug 2, 2026 (a Digital Omnibus proposal may push Annex III high-risk to Dec 2, 2027). Max fines €35M or 7% of turnover — higher than GDPR. GDPR remains the baseline. All three push the CISO/CDO toward lineage, classification, and access control.
  • Gartner's governance prediction: "By 2027, 80% of data and analytics governance initiatives will fail due to a lack of a real or manufactured crisis" (Saul Judah, Feb 28, 2024). A companion Gartner prediction: by 2027, 60% of organizations that fail to address the cultural challenges of data governance will fail to govern AI successfully. [6]
The CDO tenure problem — why strategies churn
  • Thomas Davenport & Randy Bean, HBR, Aug 18, 2021 ("Why Do Chief Data Officers Have Such Short Tenures?"): "the average tenure of a CDO is just 2 1/2 years. This compares to nearly seven years for the typical chief executive officer and just over 4 1/2 years for the average chief financial officer or chief information officer." MIT Sloan cites ~30 months. [15][16]
  • The consistently-cited cause is role ambiguity — "many companies don't seem to know exactly what they want" from the CDO, and success is "often defined by ambiguous, unrealistic goals." That short, ambiguity-driven tenure clock is itself a structural engine of strategy restarts: a new CDO every ~2.5 years, each often re-litigating the problem definition. (Adoption of the role is now near-universal in large firms: ~83% of Fortune 1000 have a CDO/CDAO, up from 12% in 2012.) [17]
Frameworks distinguishing what "data strategy" means
  • DalleMule & Davenport (HBR 2017): defense vs. offense; SSOT vs. MVOTs (above).
  • Gartner definition: "a highly dynamic process employed to support the acquisition, organization, analysis, and delivery of data in support of business objectives" — explicitly a business strategy, not a data-team artifact. Gartner press release (Mike Rollings, VP, Oct 23, 2019): "fewer than 50% of documented corporate strategies mention data and analytics as key components for delivering enterprise value" — and Gartner urges elevating data & analytics strategy "to the enterprise level" rather than keeping "a strategy specific to the data and analytics team." [18]
  • Data mesh / centralization debate (Zhamak Dehghani, Martin Fowler): data mesh pushes domain ownership and decentralized data products but requires "federated computational governance" — the explicit balancing act between local autonomy and global standards. This is the same offense/defense/cost tension expressed as an org-design question: decentralize for speed (CPO), centralize for control and cost efficiency (CISO/CFO). Practitioners note the risk is decentralizing without guardrails; most working implementations are federated, not truly decentralized.

Recommendations (for the strategist, staged)

  1. Before writing anything, run a one-line problem statement exercise. Have the CFO, CPO, and CISO/CDO each independently write the single problem they want the "data strategy" to solve. If you get "cut our cloud spend," "ship models faster," and "pass the DORA/AI-Act audit," you've just proved the thesis — and found the real work. This directly attacks the 28%-alignment gap (MIT Sloan) and the 47%-requirements failure mode (PMI).
  2. Use defense/offense as a facilitation tool, not a slide. Force an explicit, quantified trade-off (per DalleMule & Davenport's "don't default to 50/50"). Make each executive commit to what they'll give up: the CPO accepts guardrails, the CISO accepts a "thin" fast lane, the CFO funds the platform that both require.
  3. Anchor governance to a named business crisis or outcome. Gartner's data is explicit: governance without "a real or manufactured crisis" fails 80% of the time. Tie lineage/controls to a concrete regulatory deadline (EU AI Act Aug 2026, DORA now live) or a revenue/experimentation outcome, not to abstract "data quality."
  4. Sequence for a visible win inside the CDO tenure clock (~2.5 years). Because the leader who commissioned the strategy statistically may not be there in 30 months, deliver one measurable business outcome in the first 12–18 months rather than a multi-year platform rebuild.
  5. Benchmarks that should change the plan: if data-cloud spend is growing faster than the workloads it serves → lead with the CFO framing. If models are stuck in notebooks / time-to-insight is measured in weeks → lead with the CPO framing. If there's an imminent regulatory deadline or shadow-data exposure → lead with the CISO framing. The point is that whichever problem is most acute defines the strategy — and that should be decided openly, not defaulted to whoever writes the doc.

Caveats

  • Zombie-stat risk is high in this topic. The "85% of big data projects fail" and "87% never reach production" figures are widely repeated but poorly sourced (deleted tweet; un-sourced opinion piece). The "18-month data strategy abandonment" figure has no traceable primary Gartner origin and should not be attributed to Gartner. Flag these if used.
  • Vendor and consultancy surveys are self-interested. FinOps Foundation, Flexera, Splunk, Veritas, Fivetran, Forrester's insights-driven work, and most governance-tool blogs have commercial motives. Treat their numbers as directional, and prefer the peer-reviewed / primary-analyst figures (IBM/Ponemon, MIT Sloan, PMI, Gartner press releases, HBR) where precision matters.
  • The three-persona framing is an analytical device. Real organizations blur these roles (a CDO may own cost and governance; product may own its own platform spend). The value of the framing is diagnostic, not literal.
  • Some Gartner figures are predictions, not measured outcomes (the "80% by 2027" governance stat and the "20% of insights through 2022" stat are forward-looking analyst forecasts). Present them as Gartner predictions, not established fact.
  • Survey samples are small and skew large-enterprise. NewVantage/Wavestone (~85–120 Fortune 1000 executives/year) and BCG's transformation self-assessments are not representative of mid-market or SMB firms.
  1. Slideshare — https://www.slideshare.net/slideshow/whats-your-data-strategy-leandro-dallemule-thomas-h-davendocx/253568582
  2. Westcliff — https://ir.westcliff.edu/wp-content/uploads/2018/12/hbr-whats-your-data-strategy.pdf
  3. MIT Sloan Management Review — https://sloanreview.mit.edu/article/no-one-knows-your-strategy-not-even-your-top-leaders/
  4. O'Reilly — https://www.oreilly.com/library/view/the-strategic-agility/53863MIT60465/chapter003.html
  5. PMI + 2 — https://www.pmi.org/learning/thought-leadership/pulse/core-competency-project-program-success
  6. Gartner — https://www.gartner.com/en/newsroom/press-releases/2024-02-28-gartner-predicts-80-percent-of-data-and-analytics-governance-initiatives-will-fail-by-2027-due-to-a-lack-of-a-real-or-manufactured-crisis-
  7. Flexera — https://www.flexera.com/about-us/press-center/new-flexera-report-finds-84-percent-of-organizations-struggle-to-manage-cloud-spend
  8. Scribd — https://www.scribd.com/document/847968383/Flexera-State-of-the-Cloud-Report-2025
  9. Medium + 2 — https://orlandpomares.medium.com/shedding-light-on-dark-data-b98bf7bb5e9e
  10. Substack + 3 — https://metricasoftware.substack.com/p/the-real-cost-of-fragile-etl-pipelines
  11. MIT Sloan Management Review + 2 — https://sloanreview.mit.edu/article/action-and-inaction-on-data-analytics-and-ai/
  12. CIO — https://www.cio.com/article/193943/transforming-analytics-into-business-impact.html
  13. forrester — https://www.forrester.com/press-newsroom/forrester-data-strategy-insights-2022-agenda
  14. ibm + 4 — https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs?utm_
  15. MIT Sloan — https://mitsloan.mit.edu/ideas-made-to-matter/chief-data-officers-dont-stay-their-roles-long-heres-why
  16. GDS Group — https://gdsgroup.com/insights/article/maligned-and-misunderstood-why-chief-data-officers-dont-last-long-in-the-job/
  17. Harvard Business Review + 2 — https://hbr.org/2021/08/why-do-chief-data-officers-have-such-short-tenures
  18. Gartner + 2 — https://www.gartner.com/en/information-technology/glossary/data-strategy

Commissioned from our research desk. Subject to final editorial discretion.

How 'we need a data strategy' almost always means three different things to three different executives—and the technical strategist who doesn't force that disagreement into the open before writing a plan ends up authoring a document that satisfies no one. Break down the common collision between the CFO wanting cost rationalization of data infrastructure, the CPO wanting faster experimentation with analytics and ML, and the CISO wanting governance and lineage controls. Research Gartner or Forrester data on how many enterprise data strategies are abandoned or restarted within 18 months. The reader should recognize that alignment on the problem definition matters more than the elegance of the architecture.