Being Right Is the Easy Part
The question I asked every data security vendor when my name was on the data.
Four point two million.
That was the number on the screen when the scan finished.
Social security numbers sitting in a shared drive. Card data in a spreadsheet somebody emailed to themselves in 2014. Live customer records in a test environment a contractor spun up and forgot about.
Nobody in the room said anything for a while.
The vendor's lead engineer looked proud, and he'd earned it. That scan was right. Verifiably, exhaustively right.
So I asked him the only thing I cared about.
“What do I do on Monday?”
He didn't have an answer.
Not because he was bad at his job. Because nobody had ever built him a product that had one. It was designed to be right, and being helpful was somebody else's problem. That somebody was me. I went home with four point two million reasons not to sleep.
I've asked that question in every vendor meeting since. I call it the Monday Question, and it's the whole test. If this system is completely right, does anyone's Monday get easier?
If the answer is no, you didn't buy a tool. You bought a mirror.
“If the answer is no, you didn't buy a tool. You bought a mirror.”
Four point two million is not a number of findings
It's a number of people.
Somewhere in that scan was a woman who opened a checking account at nineteen and never thought about it again. A man who sent money home every second Friday for eleven years and had no idea a scan of his passport was sitting in a folder called temp.
None of them agreed to live in a shared drive. They agreed to be customers.
That's the part that keeps you up, not the audit finding. Every row is a person who handed you something and has no idea you lost track of it.
The list is not the work. The list is the invoice for the work.
There's a line in my book: intelligence isn't about being right. It's about being helpful.
I wrote it about AI. It applies just as well here, and almost nobody in this category will say it out loud.
Most data security platforms are built to be right. They scan, they score, they hand you a list, and everything after the list is your problem.
That's not a security posture. That's a transfer of liability with a subscription attached.
I spent two decades on the buying side. Chief data architect at a payments company moving money across borders in more than two hundred markets, then chief data officer at a large US bank. Different logos, same job. My name wasn't on the dashboard. It was on the data.
So I stopped grading vendors on accuracy. Everybody's accurate now; it's been table stakes for years.
I graded them on four things instead.
Does protection travel with the record, or just live around it?
Walls fail. Data moves. It leaves the database, lands in a spreadsheet, and syncs to a laptop in an airport lounge in a country where you don't have a legal entity. If protection doesn't travel with the record itself, you don't have protection. You have a policy and some optimism.
Can it act, or can it only tell?
Discovery without remediation is a to-do list with a license fee. I don't need to be told there's PII in a bucket. I need it masked or gone before I finish reading the sentence.
Does it work where the data actually lives, including the parts nobody puts in the strategy deck?
Every large enterprise has a mainframe it doesn't mention at conferences. Mine had two. Most vendors nodded politely and changed the subject.
Does it make my people faster, or does it make them tired?
Alert fatigue is a design failure, not a staffing problem. If your platform needs three analysts to interpret it, you didn't sell me a solution. You sold me a second job, and you sold it to people who already have one.
I deployed PKWARE three times, at three institutions, across three stacks with almost nothing in common. Not one of those decisions was about the scan.
Here's what meeting that standard looked like, and it isn't dramatic.
A product team came asking for eighteen months of transaction history to train a fraud model. Two years earlier that would have taken six weeks, a legal review, an argument about scope, and a smaller dataset nobody trusted. This time they had a masked copy in a day and a half, because the classification had already happened and the rules were already written.
Nobody sent an email about it. They just started working.
Helpful looks like a Tuesday where nobody had to ask permission to do their job.
AI and quantum just ended the argument
For most of my career, right and helpful sat in tension. Security argued for one, the business begged for the other, and everybody left those meetings a little unhappy.
That tension is dead. Two things killed it.
AI killed it first. Every model your company is standing up right now is a data pipeline with an appetite. It will eat whatever you point it at, including the things you'd rather it didn't, and then it will say them out loud to a customer.
“Every model your company is standing up right now is a data pipeline with an appetite.”
You cannot govern what you have not classified. You cannot classify what you have not found.
So discovery and de-identification stopped being a compliance function and became the reason the business gets to say yes. Which makes security the fastest part of the company, and no security team I've met is used to hearing that.
Quantum killed it again. Nobody needs to break your encryption today to beat you. They only need to copy it today and be patient.
Harvest now, decrypt later is a real strategy with real budget behind it. It turns every long-lived record you hold into a bet you placed years ago on an algorithm you no longer think about. Mortgages. Claims. That checking account someone opened at nineteen.
You cannot re-encrypt what you cannot find.
Crypto-agility sounds like a cryptography problem. It's a data inventory problem wearing a cryptography costume. Being right about today's cipher means nothing in 2035 unless you know, at the record level, where everything actually is.
So the two standards collapsed into one. Helpful is right now. Find the data, protect it at the record, re-protect it when the math changes. That’s the job description. It used to be a wish list.
The call comes on a Friday
Let me end where nobody in this business wants to end. The bad day comes for all of us eventually.
The call comes on a Friday. It always comes on a Friday, usually around 4:40, usually ten minutes after you told someone you'd be home for dinner.
There are two versions of what happens next.
In the first, you spend the weekend reconstructing. Pulling logs, guessing at scope, asking a room of exhausted people whether that export from March held real customer data or the masked set. Tuesday you brief the regulator with hedges in your voice. You can hear how it sounds. So can they.
In the second, you spend the weekend producing. The data was already protected. The classification already happened. The history is already there. You're not building an answer, you're printing one.
Same incident. Same Friday. Completely different weekend.
That's the whole difference between a vendor that was right and a partner that was helpful. Not in the demo. At 4:40 on a Friday, when the only thing that matters is whether you can show your work.
I've had the exciting kind of weekend. Don't recommend it.
And here's the part I usually leave out of the talk.
I was on the wrong side of this once. There was a classification project I pushed into the next fiscal year because something louder happened that quarter. Nothing broke. We got lucky. I've thought about that call more than most of the ones that went well, because luck isn't a control, and I knew that when I signed the deferral.
“Nobody writes a case study about the weekend where nothing happened, which is a shame, because it's the only kind worth having.”
So when I ask about Monday, it isn't because I'm clever. It's because I've sat in that chair with no answer, hoping nobody would ask me.
The best compliment my team ever paid a security platform was that nobody mentioned it. It sat there working while the rest of us argued about something else. Nobody writes a case study about the weekend where nothing happened, which is a shame, because it's the only kind worth having.
Build the thing that lets people go home. The woman who opened that account at nineteen will never know your name. She shouldn’t have to.
Go home. Somebody has to.
If your name is on the data where you work, I want to know the one question you ask vendors that tells you who they really are. I'm still collecting them. The best one I ever heard came from a data steward three levels below anyone in the room, and it took the vendor four minutes to answer.
Harveer Singh is the author of When Data Moves: Building Technology That Remembers We're Human and the founder of Rizz Wireless. He spent 25 years in enterprise data, most recently as a Fortune 500 chief data officer, and writes the When Data Moves newsletter on LinkedIn.
Ask us the Monday Question.
PKWARE finds sensitive data wherever it lives and protects the data itself, across endpoint, cloud, servers, IBM Z and IBM i, under one policy. Bring us a finding and we'll show you what happens after the list.