Which assets are a drug-discovery startup's crown jewels, and how do you defend that ranking?
answer
- which loss you never recover from
- volume is not value
- irreplaceable beats large
- what does losing it invalidate elsewhere
- force a budgeted ordering, not tiers
basics
~20 sThe crown jewels are the molecule-screening model weights and the accumulated wet-lab result set: losing either hands a competitor the company's entire scientific lead. The sales CRM holds more records but the company survives losing it. Rank by which loss is unrecoverable.
solid answer
~40 sCrown jewels are the small set of assets whose compromise you do not recover from, so rank by consequence, not by volume. At a seed-stage drug-discovery startup the trained screening model and the wet-lab results effectively **are** the company: a competitor who copies them gets years of spend and failed experiments for free, and the fundraising story goes with it. The CRM holds far more records and more personal data, and losing it is painful and reportable, but the business continues the next morning. Defend the ranking with a one-sentence loss statement per asset rather than with record counts. The ranking then changes the model: with insider-reachable research artifacts on top, the threats that survive triage are bulk export, copies onto personal devices, and access that outlives someone's notice period.
go deeper
Know the term: crown jewels are the few assets whose loss you do not recover from, and their job is to set the order in which everything else gets looked at.
Be ready to compare two assets on consequence rather than size, and to explain why a large customer database can rank below a small set of trade-secret artifacts.
Demonstrate the ranking doing work: name the threats that survive once an insider-reachable artifact is top, and defend each ranking with a one-sentence loss statement.
Expect to arbitrate when every owner claims criticality. Produce a forced, budgeted ordering the business will actually stand behind, plus a rule for when it gets revisited.
## What crown jewels means "Crown jewels" names the handful of assets whose compromise is **not survivable or not recoverable**. It is a prioritisation device, not a completeness device: the point is to fix the order in which threats get attention when — always — there is more model than there is sprint. The discipline is to rank by **loss**, and specifically by loss you cannot undo. Note this is not formal asset valuation or a corporate risk register with quantified expected loss; that is a separate enterprise discipline. Here you need only enough ordering to drive triage in a design session. ## Working the example Three candidate assets at a seed-stage drug-discovery startup: | Asset | Loss if compromised | Recoverable? | |---|---|---| | Screening model weights | A competitor gets the scientific lead the company was built to sell | No | | Wet-lab result set | Years of experiments, including the expensive negative results, handed over | No | | Sales CRM | Painful, reportable, damaging to relationships | Yes | The CRM is bigger, holds personal data, and is what most people's instinct reaches for, because "customer data breach" is the default story. But it is replaceable. The research artifacts are not: the wet-lab set includes which molecules **failed**, which is precisely the knowledge a competitor cannot buy and would otherwise have to pay years to reproduce. If those leave, the differentiator is gone and the next funding round is a different conversation. That is the shape of the defence. Not "the model is our IP" but "if this leaves, the company no longer has anything to sell." ## The criteria that do the work - **Irreplaceability.** Can it be regenerated? Backups restore availability, never exclusivity — a copied secret stays copied. - **Recoverability of the loss.** Distinguish an expensive bad quarter from an ending. - **Aggregation.** A single record may be trivial while the assembled set is the crown jewel; the set is the asset, not the row. - **Blast radius.** Some assets are **multipliers**: their compromise invalidates controls elsewhere. Key material is the standard case — in a payment-terminal key-injection facility, the injected keys are the asset whose disclosure silently voids every downstream protection that assumed they were secret, across every terminal ever provisioned. Rank multipliers by what they unlock, not by their size. ## Volume is not value The most common ranking error is counting records. A million rows of low-sensitivity data can matter less than a few gigabytes of trained weights. Regulatory exposure pushes the same way — teams over-rank whatever carries a reporting obligation, because that loss is legible and has a process attached, while the loss of a trade secret has neither and quietly outranks it. ## When everyone says they are critical The pathology is universal: ask owners to classify and every system comes back critical. Labels do not force a choice, so ask for one directly. Give a fixed budget — if you can genuinely protect three things this quarter, which three? — and ask what the board is told if the fourth is lost. Owners who cannot state a loss in one sentence usually discover on the spot that their system is not a crown jewel. The output must be an **ordering**, not a set of tiers, because tiers refill. ## What the ranking is for A crown-jewel list is not the threat model, and over-narrowing is its own failure: threats against non-jewel assets still exist and still get modelled, they just do not go first. What the ranking changes is which threats survive triage. Here, once insider-reachable research artifacts are on top, the dominant actor stops being an anonymous internet attacker and becomes someone with legitimate access — a departing computational chemist who can already read exactly those artifacts. The surviving threats are bulk export dressed as ordinary work, copies onto personal devices, and access that outlives a notice period. None of those would have led the list if the CRM had been ranked first, and none of them is found by working harder on the same diagram. They are found by ranking the assets differently. ## Keeping it honest Re-rank when the business changes shape, not on a calendar. A company that starts selling a product to enterprises acquires customer-data obligations that genuinely climb the list, and one whose research artifacts get published loses a crown jewel. State the ranking, date it, name who agreed to it, and expect to be held to it in the next design review.
- Where does key material sit in a crown-jewel ranking?Usually above most of the data it protects. In a payment-terminal key-injection facility, the injected key material is the asset whose disclosure silently invalidates every downstream control that assumed it was secret — and the loss spans every terminal ever provisioned, not one system. Multiplier assets rank by blast radius, never by size.
- Every owner says their system is critical. How do you break the tie?Force a ranking against a fixed budget: if you can protect three things this quarter, which three, and what do you tell the board if the fourth is lost? Owners who cannot state the loss in one sentence usually concede on the spot. Insist the output is an ordering rather than a set of tiers, because tiers refill within a quarter.
- Does the crown-jewel ranking actually change which threats you keep?That is its entire purpose. Once research artifacts outrank the CRM, the threats that survive are bulk export by someone with legitimate access, copies on personal devices, and access outliving a notice period — not anonymous internet scanning. Rank a different asset first and a genuinely different threat list is left standing from the same diagram.
saying these in an interview costs you the question
- Ranks assets by record count rather than by loss
- Calls every system a crown jewel
- Assumes the crown jewel is always customer personal data
- Excludes key material because it is 'a control, not an asset'
- Treats the crown-jewel list as the whole threat model