April 24, 2020 By Robyn Westervelt 3 min read

There is no silver bullet when it comes to protecting sensitive data. No single security technology investment will eliminate the risk of data theft or a mistake exposing sensitive information. To proactively defend against attackers, enterprise security teams are learning that they need to collect and centralize security and compliance information from all the tools at their disposal.

Current Approaches to Data Security Lack Scale

Organizations today need to effectively secure and maintain the integrity of corporate data, which is growing at a compound annual growth rate of 40–50 percent, according to IDC’s Global DataSphere research. This growth is influenced by digital transformation strategies, a continuous process in which enterprises analyze customer data to create new business models, products and services that enhance the customer experience.

Download the IDC white paper, “Adopting a Next-Generation Data Security Approach,” sponsored by IBM

To help enable transformation, businesses are turning to a hybrid mix of on-premises and cloud-based technologies to increase agility, remain competitive and drive their organizations forward. This has resulted in an influx of cloud-hosted database infrastructure and services proliferating within the enterprise.

Data Security Challenges that Arise When Adapting to Modern Technologies

Attackers are seizing on the vulnerabilities generated by the struggle of enterprise security teams to manage data security across hybrid and multicloud environments. Likewise, data security tools for discovering, classifying, monitoring and protecting sensitive data are often designed for specific environments and narrow use cases. As a result, teams are overwhelmed with limited data security visibility, fragmented compliance reporting and disjointed workflows across their on-premises and cloud-hosted data stores.

IDC studies have identified this lack of situational awareness and the ineffectiveness of existing security infrastructure to enforce data governance policies. The result is data exposure or worse. Nearly 40 percent of respondents indicated their organization experienced four or more security breaches in the last three years, according to IDC’s 2020 Data Security Survey. The survey, which reached 620 IT and IT security professionals in North America and Europe, detailed the daunting challenges that today’s security teams are facing.

A Next-Generation Data Security Approach to Support the Hybrid Multicloud

Forward-leaning organizations are managing these challenges by adopting a next-generation data security approach to protect sensitive data across heterogeneous and highly distributed environments. A next-generation data security approach is centered around holistic visualization that provides a comprehensive overview of the organization’s security posture. Taking this approach, security teams can quickly identify areas of risk and mitigate the highest risks to sensitive data, no matter where it resides.

This approach deals with the bottlenecks and inefficiencies that lead to data exposure and costly data breaches. It also addresses the declining visibility and control over sensitive data as it spans hybrid multicloud environments. Through a set of powerful, integrated data security components, security teams can gain a comprehensive, centralized view of security risks and take action.

IDC studies have found that the most successful organizations take systematic steps when embarking on a next-generation data security approach. These steps include establishing a data triage team of key stakeholders who understand established business processes and typical workflows, and considering how existing security is applied to address data in motion, data at rest (stored in databases and data stores) and data in use (cached in places not intended for long-term storage).

How to Kick-Start Your Next-Generation Data Security Program

To help ensure the success of a next-generation data security approach, security teams need to utilize data security solutions that integrate and interoperate with the rest of the security and IT infrastructure, and extend protection policies to data wherever it currently resides or will reside in the future. This includes solutions that can interoperate with software-as-a-service (SaaS), platform-as-a-service (PaaS) and infrastructure-as-a-service (IaaS) applications and cloud repositories to augment native data protection capabilities and ensure data governance policies remain consistent regardless of the location of sensitive data assets.

An effective solution must incorporate the following:

  • Automated discovery and classification
  • Ongoing vulnerability assessments
  • Real-time activity monitoring
  • Risk posture assessment
  • Customizable key performance indicators (KPIs)
  • Ability to protect data across environments
  • Long-term security and compliance reporting across on-premises and cloud-hosted data stores

Learn more about how such solutions can safeguard critical data in hybrid and multicloud environments:

Download the IDC white paper, “Adopting a Next-Generation Data Security Approach,” sponsored by IBM

More from Data Protection

Third-party access: The overlooked risk to your data protection plan

2 min read - A recent IBM Cost of a Data Breach report reveals a startling statistic: Only 42% of companies discover breaches through their own security teams. This highlights a significant blind spot, especially when it comes to external partners and vendors.The financial stakes are steep. On average, a data breach affecting multiple environments costs a whopping $4.88 million. A major breach at a telecommunications provider in January 2023 served as a stark reminder of the risks associated with third-party relationships. In this…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

SpyAgent malware targets crypto wallets by stealing screenshots

4 min read - A new Android malware strain known as SpyAgent is making the rounds — and stealing screenshots as it goes. Using optical character recognition (OCR) technology, the malware is after cryptocurrency recovery phrases often stored in screenshots on user devices.Here's how to dodge the bullet.Attackers shooting their (screen) shotAttacks start — as always — with phishing efforts. Users receive text messages prompting them to download seemingly legitimate apps. If they take the bait and install the app, the SpyAgent malware gets…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today