CISOs Mark Data Proliferation as Growing Security Problem

The more the organization scales, the more proliferated its data becomes, making it harder to protect the data, keep it secure, and keep tabs on who has access to what.
The stakes are high when it comes to securing expanding volumes of distributed data, as every business is dependent on data confidentiality, integrity, and availability.
Organizations may lose customers, violate a compliance standard, or make an ill-informed business decision if data is compromised.
Meanwhile, cybercriminals use data to gather intelligence on a target, access unauthorized systems, or extort victims.
Claude Mandy, chief evangelist of data security at Symmetry Systems, says data sprawl is a headache for security teams because they have historically designed their security to protect the systems and networks that data is stored or transmitted on, but not the data.
“As data proliferates outside of these secured environments, they have realized their security is no longer adequate,” he says. “This is particularly concerning when the traditional perimeter that provided some comfort has all but disappeared as organizations have moved to the cloud.”
He adds organizations are being forced to wake up to this issue due to increasing privacy rights such as enacted by California Privacy Rights Act (CPRA) and California Consumer Privacy Act (CCPA), which allow individuals to request organizations to provide information on what data they hold about it.
“Responding to such requests is really highlighting that organizations don’t really understand where their data is and need to invest in modern data security or data privacy tools to discover, classify and monitor data flows within their environment,” Mandy says.
In the new era of data security, CISOs must have the ability to learn where sensitive data is anywhere in the cloud environment, who can access these data, and their security posture and deploy these solutions.
“Traditionally, data security has been the ultimate goal of infosec organizations,” says Ravi Ithal, Normalyze CTO and cofounder. “As the volume of data increases and the number of places where data exists increases — data proliferation — the number of ways in which it can be accessed and misused also increases.
Ithal points out that while other business units and IT organizations happily reap the upsides of having data available in more places, the burden of securing it squarely falls on the infosec organizations. “It behooves security organizations to treat data proliferation as their problem in order to get ahead of the game of securing it,” he says.
Shira Shamban, CEO of Solvo, notes data proliferation is a problem because while the data is moving around, the security mechanisms and guardrails are usually not.
“That means even if you have a good security practice in one environment, once the data is duplicated into another environment, it is not handled in the same way by default,” she explains.


