Security and risk leaders face a problem they have not met before. They have to keep data safe in a world where new ideas arrive faster than anyone can vet them.
The way through is to take up new tools, chief among them data security posture management and data security platforms. At the same time, they have to get ready for what quantum computing and AI will do to the picture.
Gartner named PKWARE in the 2023 Gartner Hype Cycle for Data Security, for a number of reasons. PKWARE’s PK Protect Endpoint Manager and Data Store Manager both line up with data security posture management.
So a customer can run one tool and cover the whole estate. It guards data on laptops, in the cloud, on servers, and on mainframes.
The Data Security Evolution
According to Gartner, cloud service providers (CSPs) have changed how we handle data analytics and data pipelines. Being able to stand a pipeline up on demand has opened a new era.
It has also handed data security teams a fresh set of problems. There is more storage, more backup, more subsets, more extracts, and more formats. Keeping data security even across all of that is now a very heavy lift.
One of the larger blocks is how siloed most security products are. They tend to use their own way of sorting data and to work on their own.
That is why firms struggle to apply one strong set of data controls. Weighing the need for access against the need for safety can look like a losing game.
Sovereign data plans and products such as PK Protect are changing that. Both are new to the Hype Cycle, and both support data security governance and privacy impact assessment.
They also support financial data risk assessment (FinDRA) and data risk assessment. The aim is a framework that closes the gap between how data teams sort data and how security teams sort it.
Firms can then bring discovery, classification, and metadata management together in one flow. Learn more about PKWARE’s data risk assessment to see how your data security posture measures up.
Technology keeps moving. Generative AI is lifting what these tools can do, and privacy law is shifting under them. Data security plans have to keep pace with the risks that generative AI and the rest of it bring.
Navigating the Gartner Hype Cycle
The Hype Cycle gives a full view of data security. It helps security and risk leaders match their plans to the risk they are willing to carry.
It spans governance, privacy, data discovery, sorting, data processing, and analytics.
- Data Security Governance, Privacy, and Risk: Explore entries such as data security governance, data risk assessment, privacy impact assessments, data breach response, privacy by design, sovereign data plans, and FinDRA.
- Data Discovery and Categorization: Look at data security posture management, data discovery, data classification, and augmented data catalog and metadata management.
- Data Protection Techniques: Look at encryption, format-preserving encryption, and enterprise key management.
- Multicloud Platforms: Explore entries for data security as a service and data security platforms.
The Priority Matrix
To find your way through, look for tools that pull many controls together and make them simpler to run. Some choices will pay off more than others, by cutting both cost and daily effort.
Data security platforms are the clearest case. Vendors are building ways to support data security governance through focused data and privacy risk assessments.
Data security posture management, in turn, is set to reshape how risk is assessed across a wide range of data security tools. And as financial risk and security risk come together, the two will guide where a firm spends its data security budget.
In the 2022 Gartner Shifting Cybersecurity Operating Model Survey, the need for one consistent policy came out as a main driver. It is what pushed firms to centralize how cyber risk decisions get made.
So many firms now hold those decision rights centrally. They press for the same features across products, and for fewer moving parts in policy. Tools are merging, and the merged ones work better.
On the Rise: Data Security Posture Management (DSPM)
One of the standouts on the horizon is Data Security Posture Management (DSPM). It is set to shake up the data security landscape. Here is why it matters.
What You Need to Know About DSPM
DSPM is about finding data across cloud providers that nobody knew was there. It then sorts and labels that data, structured and unstructured alike.
As data keeps spreading across the cloud, DSPM becomes a key tool. It judges your data security posture and finds where privacy and security risk sit. It is also the base under data risk assessments and data security governance.
Why DSPM Is Important
With data growing across cloud estates, firms have to face privacy and security risk. That risk starts with data nobody has found or named.
DSPM changes the game because it maps data and traces how it flows, which is what tells you your posture. It also shows how sensitive the data is, how the systems are set up, and who can reach what.
Its knack for finding shadow data is what makes it useful. It surfaces business risk nobody had weighed before.
The result is one steady data security posture across controls that used to be separate, which helps a firm keep track of where its data has ended up.
Drivers and Obstacles
Data pipelines and CSP services change fast, and they leave shadow data behind them. That is where the risk builds up.
Mapping who can reach which dataset used to be hard, because data security and identity access management (IAM) products sat apart. Firms now have to track data across many formats and many places.
Rules that require a data risk assessment are also on the rise, so the need for tools that check compliance grows with them. And the push to guard data from bad settings, wide access rights, or where it lives is driving DSPM to link up with cloud-native protection platforms.
There are problems to get past. Most DSPM products come from young vendors, which some firms will pause over.
Each product does a different set of things, so it is hard to get a consistent result or to plug one into the controls you already run. DSPM products link to only a few third-party security tools today, which makes both orchestration and fixing what you find harder.
Recommendations
- Start with data security governance to find the datasets that need their own policy for DSPM to assess.
- Compare DSPM products on how well they find shadow data and how well they fit your cloud security stack.
- Treat DSPM spending as tactical, and think about shorter contracts while the market settles.
- Compare how each DSPM tool responds when it comes to building and updating data maps.
- Find third-party data security products that link to DSPM, and judge how well they use what it offers.
Data security is going through a deep shift. New tools and a changing threat picture are both driving it.
By taking up DSPM and keeping abreast of what comes next, firms can guard the data they rely on. They also put themselves in good shape for a world that gets more digital every year. Stay tuned for more on where data security goes in the age of quantum computing and AI.
