decryptingtech

Technology. Business models. Market debates.

Browse this section

Data Security

Data security protects the information itself: where it lives, who can reach it, how it moves and what happens when access becomes risky. That makes it different from infrastructure security. A cloud account, endpoint or network session can be technically secure while the data inside it remains overexposed, overshared or copied into an uncontrolled application.

Summary

The domain has expanded well beyond traditional data loss prevention. The modern control plane combines discovery and classification, entitlement analysis, encryption and key management, policy enforcement, activity monitoring, data detection and response, and resilient recovery. Data security posture management (DSPM) supplies the context: which data is sensitive, whether it is exposed, who can access it and how important the risk is.

The central architectural shift is from protecting repositories to protecting data across repositories. Sensitive information now moves through collaboration suites, SaaS applications, databases, object stores, endpoints, data pipelines and AI systems. A useful platform must therefore follow the data, understand permissions and enforce policy across more than one control point.

Why data became its own security domain

Security historically protected the container: the device, application, database or network. Cloud and SaaS weakened that model. Data is duplicated rapidly, access is inherited through complex groups and roles, public links are easy to create, and business users can move information without involving security teams. The problem is no longer only whether an attacker can enter the environment. It is whether a legitimate identity, compromised account, contractor, application or AI agent can reach more sensitive data than it should.

Data security is therefore tightly connected to Identity Security, Cloud Security, Endpoint Security and Security Operations. Identity decides who is asking, infrastructure controls the path, and data security determines whether the requested information is sensitive and whether the action should be allowed.

The control stack

LayerCore jobWhat good looks like
Discovery and classificationFind sensitive and regulated information across structured and unstructured stores.Persistent coverage, accurate labels and business context.
Data access governanceMap users, groups, roles, sharing links and machine identities to the data they can reach.Least privilege and automatic removal of excessive access.
DSPMCombine sensitivity, exposure, permissions and configuration into a prioritised risk view.Remediation, not another inventory of findings.
DLP and policy enforcementMonitor or block risky movement through email, web, endpoints, SaaS and cloud services.Consistent policy with tolerable false positives.
Encryption, tokenisation and maskingMake stolen or unnecessary data unusable and restrict who can reveal it.Strong key separation, rotation and revocation.
Data detection and responseDetect abnormal access, mass downloads, destructive activity and exfiltration.Behavioural context connected to investigation and containment.
Backup and recoveryRestore clean, trusted data after ransomware, deletion or corruption.Immutable copies, tested recovery and clear recovery points.
The control stack

How the architecture works

A mature design runs as a continuous loop. It discovers data, classifies sensitivity, maps effective access, identifies risky combinations, applies policy, watches actual use and sends high-confidence incidents into the response workflow. Classification without enforcement becomes a cataloguing exercise. DLP without accurate classification creates noise. Behaviour analytics without entitlement context cannot distinguish unusual activity from dangerous activity.

The decisive unit of risk is not a file or database alone. It is the combination of sensitive data, broad access, exposure and active behaviour. A payroll folder available to the finance team is different from the same folder exposed through a public link and downloaded by a dormant account. Platforms that join these signals can prioritise the second case instead of treating both as equal alerts.

Competitive landscape

The market overlaps several established categories rather than forming one clean product boundary.

  • Enterprise suites such as Microsoft Purview, Broadcom’s Symantec portfolio, Forcepoint and IBM Guardium combine classification, DLP, encryption, compliance and policy controls.
  • Data-centric specialists such as Varonis focus on sensitive-data discovery, permission intelligence, behavioural monitoring and automated remediation across complex estates.
  • Cloud-security platforms such as Palo Alto Networks and Wiz embed DSPM beside cloud posture, workload, identity and attack-path controls.
  • Data-resilience platforms such as Rubrik and Cohesity approach the problem through backup integrity, sensitive-data visibility and cyber recovery.

These groups increasingly converge. The suite owns enforcement points, the specialist owns deeper data and permission context, the cloud platform owns infrastructure context, and the resilience platform owns the recovery copy. No supplier automatically wins merely by adding the DSPM label.

Where durable advantage comes from

The strongest moat is a continuously refreshed data-and-access graph: a map of sensitive information, identities, nested permissions, usage and policy across many repositories. It becomes more valuable as coverage deepens and remediation is trusted. Classification accuracy matters, but so do deployment friction, scanning cost, false-positive rates and the ability to act without interrupting legitimate work.

Distribution is the counterweight. A broad platform can attach data controls to an existing endpoint, identity, productivity or cloud estate and reduce procurement friction. Specialists must prove that deeper visibility and automation justify another platform. Incumbents must prove that nominal coverage is not shallow coverage. The long-term winners should combine broad telemetry with credible enforcement and measurable risk reduction.

AI expands both the need and the attack surface

AI systems consume enterprise data at machine speed. Retrieval pipelines, vector databases, prompts, responses, model-training sets and autonomous agents create new copies and new access paths. The security question shifts from “Can this employee open the file?” to “Can this user, application or agent retrieve, transform or disclose the underlying information through any interface?”

This strengthens demand for discovery, lineage, entitlement analysis and real-time controls. It also raises the cost of weak classification: an assistant cannot reliably respect sensitivity that the enterprise has never identified. AI can improve classification and alert triage, but it does not replace deterministic policy, scoped permissions, encryption or human review for consequential actions.

The investment debate

The bull case is that data sprawl, AI adoption and machine identities turn data security into a persistent control plane rather than a compliance project. The bear case is category compression: DSPM features can be bundled into cloud, identity, productivity, CNAPP and recovery platforms, limiting standalone pricing power.

The key test is remediation. Products that only find sensitive data risk becoming features. Platforms that can reduce excessive access, stop risky movement, detect abuse and prove recovery become operational systems with stronger retention and expansion potential. Investors should track repository coverage, time to value, automatic remediation, platform attach and whether deployments extend from posture into recurring enforcement and response.

Bottom line

Data security is the layer that follows sensitive information wherever it goes. DLP remains important, but it is now one enforcement mechanism inside a broader architecture built on discovery, classification, access intelligence, posture, detection and recovery. AI makes that architecture more urgent because the number of actors able to retrieve and redistribute data is rising faster than human security teams can review manually.