• bitcoinBitcoin(BTC)$77,224.000.16%
  • ethereumEthereum(ETH)$2,504.14-0.52%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$720.79-0.70%
  • rippleXRP(XRP)$1.35-0.65%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$100.84-0.43%
  • tronTRON(TRX)$0.3411870.42%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.31%
  • zcashZcash(ZEC)$1,082.84-3.11%
  • HyperliquidHyperliquid(HYPE)$77.93-2.04%
  • dogecoinDogecoin(DOGE)$0.084109-0.77%
  • RainRain(RAIN)$0.015310-2.76%
  • moneroMonero(XMR)$529.69-0.78%
  • USDSUSDS(USDS)$1.00-0.01%
  • whitebitWhiteBIT Coin(WBT)$80.11-0.02%
  • chainlinkChainlink(LINK)$11.41-0.55%
  • leo-tokenLEO Token(LEO)$9.06-0.52%
  • cardanoCardano(ADA)$0.2081100.49%
  • stellarStellar(XLM)$0.179179-0.36%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • daiDai(DAI)$1.000.02%
  • bitcoin-cashBitcoin Cash(BCH)$223.74-0.53%
  • USD1USD1(USD1)$1.000.00%
  • litecoinLitecoin(LTC)$54.832.17%
  • uniswapUniswap(UNI)$6.24-0.77%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.36-1.43%
  • CantonCanton(CC)$0.095536-1.50%
  • hedera-hashgraphHedera(HBAR)$0.0759802.16%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • avalanche-2Avalanche(AVAX)$7.410.58%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.01%
  • nearNEAR Protocol(NEAR)$2.33-0.34%
  • suiSui(SUI)$0.72-0.37%
  • crypto-com-chainCronos(CRO)$0.058165-0.86%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,346.30-0.10%
  • Circle USYCCircle USYC(USYC)$1.140.00%
  • MemeCoreMemeCore(M)$1.14-3.19%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • okbOKB(OKB)$113.49-0.08%
  • BittensorBittensor(TAO)$234.511.23%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.10%
  • aaveAave(AAVE)$126.200.09%
  • BitwayBitway(BTW)$0.7127.28%
  • AsterAster(ASTER)$0.701.93%
  • pax-goldPAX Gold(PAXG)$4,349.02-0.14%
  • mantleMantle(MNT)$0.56-0.91%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.056936-1.53%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Closing the data security maturity gap: Embedding protection into enterprise workflows

April 6, 2026
in AI & Technology
Reading Time: 5 mins read
A A
Closing the data security maturity gap: Embedding protection into enterprise workflows
ShareShareShareShareShare

Presented by Capital One


Data security remains one of the least mature domains in enterprise cybersecurity. According to IBM, 35% of breaches in 2025 involved unmanaged data source or “shadow data.” This reveals a systemic lack of basic data awareness. It’s not because of a lack of tooling or investment. It’s because many organizations still struggle with the most fundamental questions: What data do we have? Where does it live? How does it move? And who is responsible for it?

In an increasingly complex ecosystem of data sources, cloud platforms, SaaS applications, APIs, and AI models, those questions are only becoming more difficult to answer. Closing the maturity gap in data security demands a cultural shift where security is no longer treated as an afterthought. Instead, protection is embedded throughout the full data lifecycle, grounded in a robust inventory, clear classification, and scalable mechanisms that translate policy into automated guardrails.

Visibility as the foundation

The most persistent barrier to data security maturity is basic visibility. Organizations often focus on how much data they hold, but not on what that data is made up of. Does it contain personally identifiable information (PII)? Financial data? Health information? Intellectual property? Without this level of understanding and inventory, it’s a lot tougher to implement meaningful protection.

This can be avoided, however, by prioritizing enterprise capabilities that can detect sensitive data at scale across a large and varied footprint. Detection must be paired with action, deleting data where it’s no longer needed, and securing data where it is by aligning enforcement to a well-defined policy.

Mature organizations should start by treating data security as an “understanding your environment” problem. Maintain an inventory, classify what’s in the ecosystem, and align protections with the classification rather than solely relying on perimeter controls or point solutions to scale.

Securing chaotic data

One reason data security has lagged behind other security domains is that data itself is inherently chaotic. Unlike perimeter security, which relies on explicit ports and defined boundaries, data is largely unpredictable. That is to say, the same underlying information may appear across very different formats: structured databases, unstructured documents, chat transcripts, or analytics pipelines. Each may have slightly different encodings or transformations that introduce unforeseen, and often undetected, changes to the data itself.

Human behavior compounds the challenge, with different actions introducing risks in ways that perimeter controls simply can’t anticipate. This could be anything from a credit card number copied into a free-form comment field, a spreadsheet emailed outside its intended audience, or a dataset repurposed for a new workflow.

When protection is bolted on at the end of a workflow, organizations create blind spots. They rely on downstream checks to catch upstream design flaws. Over time, complexity accumulates and the risk of exposure becomes a question of when, not if.

A more resilient model assumes that sensitive data will surface in unexpected places and formats, so protection is embedded from the moment data is captured. Defense-in-depth becomes a design principle: segmentation, encryption at rest and in transit, tokenization, and layered access controls.

Critically, these safeguards travel with the data lifecycle, from ingestion to processing, analytics and publishing. Instead of retrofitting controls, organizations design for chaos. They accept variability as a given and build systems that remain secure even when data diverges from expectations.

Scaling governance with automation

Data security becomes operationally sustainable when governance is enforced through automation from its genesis. When coupled with clear expectations to create bounded contexts: teams understand what is permitted, under what conditions, and with what protections data can be used effectively.

This matters more than ever today. AI systems often require access to huge volumes of data, across domains. This makes policy implementation particularly challenging. To do so effectively and safely requires deep understanding, strong governance policies, and automated protection.

Security techniques such as synthetic data and token replacement enable organizations to preserve analytical context while making sensitive values harder to read. Policy-as-code patterns, APIs, and automation can handle tokenization, deletion, retention constraints, and dynamic access controls. With guardrails built into the platforms they use, engineers can focus more on innovating with data and elevating business outcomes securely.

AI systems must also operate within the same governance and monitoring expectations as human workflows. Permissions, telemetry, and controls around what models can access, along with the information they can publish, are essential. Governance will always introduce a degree of friction. The goal is to make that friction well understood, navigable and increasingly automated. Confirming purpose, registering a use case, and provisioning access dynamically based on role and need should be clear, repeatable processes.

At enterprise scale, this requires centralized capabilities that implement cyber security policy in the data domain. This includes detection and classification engines, tokenization and detokenization services, retention enforcement, and ownership and taxonomy mechanisms that cascade risk management expectations into daily execution.

When done well, governance becomes an enablement layer rather than a bottleneck. Metadata and classification drive protection decisions automatically while accelerating business discovery and usage. Data is protected across its lifecycle by strong defenses like tokenization and deleted when required by regulation or internal policy. There should be no need for teams to “touch the data” manually for every control decision, with policy enforced by design.

Building for the future

Put simply, closing the data security maturity gap is less about adopting a single breakthrough technology and more about operational discipline. Build the map. Classify what you have. Embed protection into workflows so that security is repeatable at scale.

For business leaders seeking measurable progress over the next 18–24 months, three priorities stand out.

First, establish a robust inventory and metadata-rich map of the data ecosystem. Visibility is non-negotiable. Second, implement classification tied to clear, actionable policy expectations. Make it obvious what protections each category demands. And finally, invest in scalable, automated protection schemes that integrate directly into development and data workflows.

When protection shifts from reactive bolt-on controls to proactive built-in guardrails, compliance becomes simpler, governance becomes stronger, and AI readiness becomes achievable, without compromising rigor.

Learn more how Capital One Databolt, the enterprise data security solution from Capital One Software, can help your business become AI-ready by securing sensitive data at scale.


Andrew Seaton is Vice President, Data Engineering – Enterprise Data Detection & Protection, Capital One.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact [email protected].

YOU MAY ALSO LIKE

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why

A Princeton Researcher Proposes Recurrent Looped Transformer (RLT) that Carries Decoder State across Every Token, Fixing 96 Blocks per Token with Unbounded Temporal Depth

Credit: Source link

ShareTweetSendSharePin

Related Posts

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why
AI & Technology

Car Manufacturers Are Ditching CarPlay In 2026: Here’s Why

September 13, 2026
A Princeton Researcher Proposes Recurrent Looped Transformer (RLT) that Carries Decoder State across Every Token, Fixing 96 Blocks per Token with Unbounded Temporal Depth
AI & Technology

A Princeton Researcher Proposes Recurrent Looped Transformer (RLT) that Carries Decoder State across Every Token, Fixing 96 Blocks per Token with Unbounded Temporal Depth

September 13, 2026
If Your Laptop Trackpad Is Popping Out, Stop Using It Immediately
AI & Technology

If Your Laptop Trackpad Is Popping Out, Stop Using It Immediately

September 13, 2026
How To Get Your Cut Of PlayStation’s .85 Million Settlement
AI & Technology

How To Get Your Cut Of PlayStation’s $7.85 Million Settlement

September 13, 2026
Next Post
The Poor Man’s Covered Call (Run Covered Calls Without 100 Shares)

The Poor Man's Covered Call (Run Covered Calls Without 100 Shares)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Amazon, Qualcomm Deal Broadens the AI Chip Race | Bloomberg Tech 9/08/2026

Amazon, Qualcomm Deal Broadens the AI Chip Race | Bloomberg Tech 9/08/2026

September 12, 2026
Column | Schools should stop banning peanuts. Here’s what really keeps kids safe. – The Washington Post

Column | Schools should stop banning peanuts. Here’s what really keeps kids safe. – The Washington Post

September 8, 2026
Paycheck-to-Paycheck And Can’t Tell Our Kids No

Paycheck-to-Paycheck And Can’t Tell Our Kids No

September 12, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!