By NHI Mgmt Group Editorial TeamBased on Cyera: “Data Security Platforms: The New Frontier in Cybersecurity & AI” (February 2, 2026)

TL;DR: Data security is shifting toward a data-centric model as AI, data growth, and compliance pressure outpace legacy network controls, according to Cyera’s report on data security platforms. The core issue is that discovery, classification, protection, and destruction now define the control plane, not the perimeter.


At a glance

What this is: Cyera’s report says data growth, generative AI, and compliance pressure are pushing security away from network boundaries and toward data-centric controls.

Why it matters: IAM and governance teams need to treat data discovery, classification, and protection as part of the identity control plane because access decisions now hinge on where sensitive data lives and how it is governed.


Context

Data security is no longer defined primarily by the network boundary. As data volumes expand and generative AI consumes more enterprise information, the question shifts from who can reach a system to what data exists, where it lives, and how it is governed.

Cyera’s report frames this as a broader control-plane change: organisations need data discovery, classification, protection, and destruction to work together as one programme. For identity teams, that means access governance, data governance, and AI governance are converging around the same sensitive data estate.


Key questions

Q: How should teams govern access when there is no reliable perimeter?

A: Teams should govern access through authenticated identity, device trust and context rather than network location. The practical shift is to treat every access request as untrusted until the identity, device and policy conditions are verified, including for cloud apps, connected devices and machine-to-machine connections.

Q: Why do data discovery and classification matter when organisations manage sensitive data in hybrid environments?

A: They matter because security cannot protect data it cannot find, and it cannot prioritize data it has not labeled. In hybrid environments, sensitive information is scattered across systems with uneven ownership and inconsistent controls. Discovery creates the inventory, classification assigns handling rules, and together they make compliance defensible, reduce exposure, and improve decision-making around risk.

Q: What breaks when organisations rely on network controls instead of data governance?

A: Network controls can still limit some exposure, but they do not tell you which datasets are sensitive, how long they should be retained, or whether they should be available to AI tools. The result is policy drift, where access looks controlled at the boundary but remains overexposed at the data layer.

Q: Should organisations treat data destruction as part of security governance?

A: Yes. Destruction reduces the amount of data available for misuse, oversharing, and AI-enabled leakage. When retention and deletion are separated from security governance, stale information remains accessible long after it should have been removed, expanding the practical attack surface for both humans and non-human identities.


Technical breakdown

Why the data perimeter is replacing the network perimeter

A network perimeter assumes that controlling ingress and egress meaningfully constrains risk. That assumption weakens when sensitive data is distributed across cloud services, collaboration tools, SaaS platforms, and AI workflows. Data-centric security instead starts from the location and sensitivity of the asset itself. Discovery identifies where regulated or high-value data exists, classification assigns meaning to it, and policy enforcement follows the data rather than the network zone. This is why traditional segmentation alone cannot answer modern exposure questions. Practical implication: security programmes need visibility into data locations before they can govern access, retention, or downstream AI use.

Practical implication: Build governance around data location and sensitivity, not around network trust zones alone.

How discovery and classification become identity controls

Discovery and classification are often treated as data management functions, but they increasingly determine identity outcomes. If you cannot identify sensitive data, you cannot set meaningful access rules, retention rules, or sharing limits for humans, service accounts, or AI systems. Classification also informs whether a dataset should be excluded from certain workflows, especially generative AI pipelines that can unintentionally amplify exposure. The control is not just about seeing data, but about making that visibility actionable across policy, access, and lifecycle management. Practical implication: connect classification results to entitlement decisions, not just to reporting dashboards.

Practical implication: Tie classification outputs to access policy, retention, and AI usage restrictions.

Why destruction matters in the AI-era data lifecycle

Destruction is the least discussed but most operationally important part of the data security lifecycle. Retained data continues to create exposure long after the original business need has passed, and AI increases the odds that stale or over-retained information remains reachable by users and systems that were never meant to process it. In a data-centric model, destruction is a governance control, not a housekeeping task. It reduces the amount of data available for misuse, accidental sharing, and model-adjacent exposure. Practical implication: align retention and deletion policy with access governance so old data does not remain a standing security liability.

Practical implication: Treat retention and deletion as security controls that reduce the identity blast radius of stale data.


NHI Mgmt Group analysis

Data security is becoming the governing layer for identity decisions. When data itself defines the perimeter, IAM can no longer stop at authenticating a user or workload. The real control question becomes whether access is appropriate for the sensitivity, residency, and downstream use of the data being touched. That shifts governance from perimeter enforcement to data-conditioned authorisation.

Data discovery blind spots create identity blind spots: if teams do not know where sensitive data lives, they cannot scope access or lifecycle controls accurately. This is especially true for non-human access paths, where service accounts, APIs, and AI workflows may reach data at scale without the same human review patterns. The implication is that data visibility now determines identity governance quality.

Generative AI turns data classification into an operational prerequisite. AI systems consume, transform, and redistribute information quickly enough that unclassified data becomes uncontrolled data. That does not mean AI introduces a new security model so much as it exposes the weakness of existing ones: classification must be machine-actionable if it is to govern humans and non-humans consistently. Practitioners should treat AI usage as a forcing function for better data governance.

The cyber perimeter is now a policy problem, not a topology problem. Legacy network thinking is too coarse for hybrid estates where the same dataset may be consumed by people, applications, and AI services. The more useful boundary is policy-driven control over discovery, protection, retention, and destruction. That is where identity, data, and compliance programmes need to converge.

Data-centric security changes the unit of governance. The old unit was the system or subnet. The new unit is the dataset and its lifecycle. Security teams that keep optimising around network boundaries will miss the actual exposure surface, while teams that govern data lifecycle can reduce risk across human users, machine identities, and emerging AI workflows.

What this signals

Data-centric security is forcing identity teams to think in terms of datasets, not just accounts. When classification determines how information is handled, access reviews and policy design need to start from the data estate. That makes governance more precise, but it also raises the bar for visibility across cloud, SaaS, and AI usage.

Generative AI makes poor data hygiene visible faster. Unclassified or over-retained data becomes easier to spread, reuse, and expose when machine systems can ingest and transform it at scale. The practical response is to align data discovery, retention, and AI usage rules before AI becomes the default consumer of enterprise information.


For practitioners

  • Map sensitive data before setting access policy Use discovery and classification to identify where sensitive and regulated data resides across cloud, SaaS, and collaboration systems before reworking entitlements or sharing rules.
  • Connect classification to entitlement decisions Treat classification results as input to access governance so data sensitivity, not just user role, influences who or what can reach a dataset.
  • Define retention and destruction as security controls Align deletion schedules, legal holds, and data retention policies with security objectives so stale information does not remain exposed indefinitely.
  • Review AI data-use boundaries Identify which datasets can flow into generative AI tools, which must be excluded, and which require extra protection before any model or assistant can process them.
  • Extend governance to non-human access paths Include service accounts, APIs, and AI workflows in data access reviews so machine-driven access is governed against the same data sensitivity rules as human access.

Key takeaways

  • Traditional network controls are no longer enough when sensitive data is distributed across cloud, SaaS, and AI workflows.
  • Discovery, classification, protection, and destruction now operate as the real control plane for modern data security.
  • IAM teams need to align access governance with data sensitivity and lifecycle controls, or the perimeter problem simply moves inward.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixDSP — Data Security and PrivacyThe article centres on protecting and governing data as the new perimeter.
Recommendation — Align data discovery, classification, protection, and destruction to the DSP domain.
NIST CSF 2.0PR.DS-01 — Data-at-rest is protectedThe report emphasises data-centric protection as the control plane.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity decisions now depend on data sensitivity and handling rules.
ID.AM-01 — Physical devices and systems within the organisation are inventoriedDiscovery is foundational to knowing where sensitive data exists.
Recommendation — Extend protection controls to cover sensitive data wherever it resides. Use data classification to drive entitlement decisions and access boundaries. Inventory data repositories and connected systems before setting governance policy.

Key terms

  • Data Centric Security: Data Centric Security protects information itself, rather than relying only on the security of systems that store or move it. It uses controls such as classification, encryption, tokenization, access policies, and usage restrictions so data remains protected wherever it travels, is copied, or is processed across cloud, endpoint, and application environments.
  • Data classification: Data classification is the process of labelling information according to sensitivity, regulatory impact, or business value so controls can be applied consistently. For AI governance, it allows policy to follow the data into prompts, sessions, and destinations rather than relying on brittle text matching.
  • Data destruction: The controlled removal of data so it no longer remains recoverable or usable beyond its approved lifecycle. In practice, this includes deletion, sanitisation, and disposal of copies and derivatives. It matters because stale data and duplicated artefacts often create the longest-lived exposure.
  • Data Discovery: Data discovery is the process of finding where information lives across cloud, SaaS, endpoints, backups, and analytics systems. In practice, it creates the inventory that makes classification, access decisions, recovery planning, and AI governance possible rather than speculative.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org