This document is a checklist designed to assist organizations in managing data risks effectively. It outlines the increasing volume, variety, and velocity of data and the associated risks, including cybersecurity threats and potential legal repercussions from privacy regulators. The checklist aims to help executives, including general counsel and chief information officers, understand the risks they face and evaluate their preparedness. It includes specific questions regarding cybersecurity readiness, internal and external threat assessments, data security policies, and compliance with privacy requirements. Additionally, it addresses the importance of maintaining an accurate asset inventory and understanding applicable privacy regulations based on industry and jurisdiction. The document emphasizes the necessity of conducting regular risk assessments to evaluate security controls and recommend necessary changes to mitigate risks. Overall, it serves as a practical guide for organizations to enhance their data risk management strategies.