TL;DR: Forrester Consulting’s June 2026 TEI study models a composite fintech environment and finds 351% three-year ROI, $3.6M net present value, and payback in under six months, with most benefit driven by automation, reduced compliance effort, and lower cloud waste, according to Sentra research. The result is a governance case for data security that now needs to be argued in operational terms, not just risk language.
At a glance
What this is: Forrester’s TEI study models a strong business case for Sentra by tying data security automation to quantified labour savings, compliance reduction, and avoided cloud waste.
Why it matters: For IAM, NHI, and security governance teams, the study matters because data visibility and access control now intersect directly with AI usage, hybrid cloud risk, and the operational cost of proving control effectiveness.
By the numbers:
- Forrester Consulting’s study found 351% three-year ROI, $3.6M net present value, and payback in under six months.
- The composite organisation in the study had 3,500 employees and a 100 petabyte data footprint across hybrid multi-cloud infrastructure.
👉 Read Sentra's TEI analysis of data security ROI and governance savings
Context
Data security programmes often struggle to prove value because the benefits are split across risk reduction, compliance effort, cloud waste, and analyst time. That makes ROI conversations difficult, especially when the same control set is also being asked to support AI governance and sensitive-data discovery across hybrid environments. The primary issue is not whether control matters, but whether the organisation can measure what it is actually protecting and who can reach it.
This article is about a third-party economic model rather than a technical product benchmark. The useful question for practitioners is whether automation in data security can reduce manual governance work enough to change budget decisions, especially when data access is intertwined with human identity, service accounts, and AI-driven workflows. The study’s starting position is not unusual for large enterprises, but the scale of the environment makes the economics more visible.
In identity programmes, data governance and access governance increasingly overlap. The more sensitive data lives across cloud estates, test environments, and AI workflows, the more access decisions become a governance problem rather than a narrow security operation. That is why this study is relevant to IAM, NHI, and broader security architecture discussions even though the subject is data security economics.
Key questions
Q: How should security teams justify data security investments to leadership?
A: They should tie the case to measurable labour reduction, avoided cloud waste, and compliance effort rather than relying only on breach fear. A strong justification shows how automation reduces recurring manual work, shortens governance cycles, and lowers the cost of proving control. That gives CISOs and CIOs a common financial language for the same control set.
Q: Why do sensitive-data programmes often overlap with IAM and NHI governance?
A: Because data risk is usually created by access, not storage alone. If humans, service accounts, contractors, or AI workflows can reach sensitive data without clear ownership and review, classification becomes incomplete. Identity and access controls determine whether the right systems and people can use the data at all.
Q: What breaks when data discovery is separated from access review?
A: Teams can know where sensitive data exists without knowing who can reach it or whether that access is still justified. That gap creates overexposure, weak audit evidence, and slower remediation when permissions change. It also makes AI governance harder because the organisation cannot prove which identities fed which data into downstream systems.
Q: How should teams evaluate a data security platform that runs inside their cloud account?
A: They should ask whether the platform preserves identity context, reduces data movement, and avoids creating a second infrastructure layer that must be governed separately. In-place operation matters because it keeps classification tied to the same cloud identities and access paths that create the risk in the first place.
Technical breakdown
How TEI models convert security controls into business value
A Total Economic Impact study is not a vendor benchmark and not a raw ROI calculator. It estimates benefits by combining customer interviews, a composite organisation, and quantified labour, infrastructure, and risk outcomes over a fixed period. That matters because the model reflects operational change, not only software capability. In this case, the value comes from automating discovery, classification, and governance tasks that would otherwise require analysts to manually inspect data, chase false positives, and maintain environment-wide coverage. Practical implication: treat TEI as an economic model to test budget assumptions, not as proof that every environment will realise the same result.
Practical implication: Use TEI as a budgeting model, then validate the assumed labour and compliance savings against your own operating data.
Why data security economics depend on cloud account placement
The study’s architecture claim is important: if a platform must duplicate data elsewhere to analyse it, the cost profile changes and governance questions expand. Running scanners inside the customer’s own cloud account reduces data movement, lowers deployment overhead, and limits the need for separate outpost infrastructure. It also means the platform is not just classifying data, but doing so where the access context already exists. That matters for cloud security and identity governance because the same environment contains workload identities, service accounts, and AI workflows that can touch sensitive data. Practical implication: evaluate data security tools on where they operate and what identity context they preserve.
Practical implication: Prefer controls that operate in place and preserve cloud identity context rather than adding a second data-copying layer.
How AI governance increases the value of sensitive data discovery
The article links data security to AI governance because organisations now need to know what can be seen by models, pipelines, and users before they can govern downstream behaviour. Sensitive data discovery becomes a prerequisite for understanding training exposure, test environment risk, and over-broad access. This is especially relevant where human users, contractors, and non-human identities all interact with the same data estate. The governance question is no longer just where data sits, but which identities can touch it and whether those accesses are still justified. Practical implication: align data classification with identity and access review processes, not with storage inventory alone.
Practical implication: Tie sensitive-data discovery to access review so model and workload exposure are governed as part of identity control.
Threat narrative
Attacker objective: The attacker or risk event seeks exposure of sensitive data and the operational disruption that follows from weak governance over who can access it.
- Entry occurs when sensitive data is left exposed across hybrid cloud, test, or AI-adjacent environments that are not tightly scoped by access control.
- Escalation follows when excessive permissions, shadow data, or unmanaged identities widen the set of users and systems that can reach the data.
- Impact is realised through data leakage, compliance burden, insider-risk noise, and avoidable cloud cost from redundant or ungoverned data stores.
Breaches seen in the wild
- Codefinger AWS S3 ransomware attack — Codefinger used compromised AWS credentials to encrypt S3 buckets via SSE-C.
- DeepSeek breach — DeepSeek breach exposed 1M+ log lines and sensitive secret keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Data security is now an identity governance problem, not just a discovery problem. When sensitive data is spread across cloud estates, test systems, and AI workflows, the real risk is which identities can reach it and whether that access is still legitimate. Classification alone does not answer that. Practitioners should treat data visibility, access scope, and identity lifecycle as a single governance chain.
Cloud-native deployment economics now matter as much as control coverage. A data security platform that avoids duplicating data and runs in the customer’s cloud account changes the cost model materially. That does not remove governance complexity, but it does reduce the operational friction that often causes programmes to stall before broad coverage is reached. Practitioners should evaluate how much control is gained per unit of deployment overhead.
AI governance debt: the hidden exposure grows when sensitive data can feed models before it is classified. The study’s strongest signal is not just labour reduction, but the growing need to know what data is available to AI systems before those systems use it. That creates a governance debt if discovery, access review, and AI policy are run separately. Practitioners should align AI controls with identity and data governance workflows.
Standing access to sensitive data remains the real scaling problem. The more automated the environment becomes, the more dangerous persistent permissions, broad analyst access, and contractor reach become. The governance objective is to reduce the default surface area before risk has to be triaged manually. Practitioners should push toward access scoping that is reviewed alongside data classification.
Manual compliance work is still a control tax on every mature data programme. The study shows that much of the value comes from reducing repetitive governance labour in production, test, and non-production environments. That is a sign that many organisations are still paying for consistency with people instead of policy. Practitioners should convert recurring review work into measurable control automation.
From our research:
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, according to The State of Secrets in AppSec.
- The trust gap between discovery, access review, and AI governance is widening, which is why identity-linked data controls need to move earlier in the lifecycle.
What this signals
AI governance will increasingly be judged by how well organisations can connect sensitive-data discovery to identity control. The practical test is no longer just whether data can be found, but whether access to it is scoped, owned, and reviewed before AI workflows touch it. Programmes that keep data classification separate from IAM will struggle to explain exposure, especially where contractors and service accounts are involved.
The more cloud estates and AI use cases expand, the more recurring review work becomes a cost centre that security leaders can no longer ignore. The next phase of data security will reward teams that can show less manual effort without losing control fidelity, especially in hybrid environments where access paths change faster than policy cycles.
For practitioners
- Map data access to identity ownership Link sensitive-data discovery to the human and non-human identities that can reach each dataset, then assign an owner for every high-risk repository, workspace, and pipeline touchpoint.
- Measure governance effort by environment Track manual classification, review, and compliance hours separately for production, test, and AI-connected environments so the business case reflects where effort is actually spent.
- Reduce hidden data sprawl before expanding AI use Find redundant databases, shadow copies, and unmanaged storage layers before they become training, testing, or analytics inputs that multiply access risk and cloud cost.
- Review access scope alongside data classification Do not rely on data labels alone. Revalidate who can access sensitive data whenever permissions, workloads, or contractor relationships change.
- Use ROI to quantify control debt Translate recurring compliance labour, analyst time, and infrastructure waste into financial terms so leadership can see where control automation removes operating friction.
Key takeaways
- The study frames data security as a measurable operating problem, not only a risk statement.
- The biggest value comes from shrinking manual governance work, reducing cloud waste, and improving auditability across hybrid environments.
- For IAM and NHI teams, the key question is who can touch sensitive data before AI or analytics systems ever use it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Data access scoping and review sit at the centre of this study's governance implications. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the main identity control behind the study's access and governance themes. |
| OWASP Non-Human Identity Top 10 | NHI-01 | The article's overlap with secrets, workload access, and hidden identities connects to NHI governance. |
| NIST AI RMF | GOVERN | AI governance is explicitly part of the study's value case and exposure model. |
Use NHI-01 to inventory identities that can reach sensitive data and classify their access paths.
Key terms
- Total Economic Impact: A Total Economic Impact study estimates the financial effect of a technology investment by combining interview-based input, a composite organisation, and quantified costs and benefits. It is useful for budget conversations, but it remains a model, not a guarantee of realised results in every environment.
- Shadow Data: Shadow data is sensitive information that exists outside the places security teams expect to find it. It often appears in testing copies, ad hoc exports, SaaS tools, or AI workflows, which makes it hard to govern with inventory-based controls alone.
- AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
- Hybrid cloud: A hybrid cloud combines public cloud with private cloud or on-premises infrastructure. It often helps with regulation and legacy modernisation, but it also introduces mixed trust boundaries, uneven logging, and more credential handling complexity across environments.
What's in the full article
Sentra's full article covers the operational detail this post intentionally leaves for the source:
- The full Forrester benefit model behind the 351% ROI figure, including category-by-category assumptions.
- The customer interview basis for the composite fintech organisation and how the study translated interviews into quantified outcomes.
- The detailed cost breakdown for compliance effort, analyst time, cloud infrastructure savings, and breach avoidance.
- The deployment and architecture discussion showing why in-account operation changes the economics of data security.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and identity lifecycle controls. It is designed for practitioners who need to connect identity decisions to real operational risk across cloud and AI environments.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org