By NHI Mgmt Group Editorial TeamBased on Cyera: “Cyber Security Tribe’s Annual State of the Industry Report” (February 2, 2026)

TL;DR: Cyber Security Tribe’s annual state of the industry report says 40% of CISO executives are prioritising data security investments in 2024, using people, process, and technology as the benchmark for planning according to Cyera. That shift makes data security programme design a business planning issue, not just a tooling discussion.


At a glance

What this is: Cyera’s source article summarises a state-of-the-industry report showing that data security is rising in priority, with 40% of CISO executives prioritising investment in 2024.

Why it matters: For IAM, NHI and autonomous programme owners, the signal is that data security now influences control design, prioritisation and governance choices across identity and access stacks.


Context

Data security is the practice of finding, classifying and protecting sensitive data so controls can be aligned to real business risk. In this report summary, the core governance gap is not absence of intent but the need to decide where security investment belongs when priorities are shifting.

Cyera’s article frames the report as a benchmark across people, process and technology, which matters because data security decisions increasingly sit alongside IAM, NHI governance and broader control planning. The article is also clear that 2024 planning is being shaped by executive prioritisation rather than by tooling alone.


Key questions

Q: How should security teams prioritise data security investment in 2024?

A: Start with the data sets that carry the highest operational, regulatory or revenue impact, then map the controls needed to reduce exposure on those paths. A useful prioritisation model ties spending to ownership, classification, access patterns and measurable loss scenarios instead of buying tools in isolation.

Q: What breaks when data security controls are managed separately across different teams and tools?

A: Fragmented management usually creates inconsistent policies, slower remediation, and blind spots around where sensitive data is exposed. Teams lose a shared view of risk, which makes it harder to align access controls, DLP tuning, and compliance workflows. The result is often more manual effort, weaker coordination, and slower response when a data incident requires immediate action.

Q: What are the signs that a data security programme lacks operational maturity?

A: Common signs include unclear data ownership, inconsistent classification, duplicated controls across teams, and access paths that are not tied to specific data risks. If the programme cannot explain which business assets it protects and why, it is probably functioning as a set of disconnected activities rather than a governed capability.

Q: Should data security or identity governance be addressed first?

A: Neither should be treated as independent if the same users, service accounts or workloads can reach sensitive data. Identity governance should establish who can access what, while data security should define what is worth protecting and monitoring. The right sequence is to align them around the highest-value data paths.


Technical breakdown

Why data security is becoming a budget priority

The report summary shows a shift from data security as a specialist concern to a programme-level investment category. That matters because sensitive data discovery, classification and protection now drive decisions about where to spend across controls, staffing and operating model. When 40% of CISO executives elevate data security, the practical effect is that data risk is being treated as a planning input for the wider security portfolio, not as a downstream cleanup activity after other projects finish.

Practical implication: security leaders should map data security spending to business risk, not to isolated tooling requests.

People, process and technology as the planning model

The report uses people, process and technology as its benchmark, which is a reminder that data security failure is usually organisational before it is technical. Classification rules, ownership, escalation paths and control coverage all matter as much as scanners or policies. For IAM and NHI teams, that means data-centric programmes fail when ownership is unclear, when processes are inconsistent, or when technology is deployed without a governance model that tells teams what to protect first and why.

Practical implication: align data security controls to ownership, process and operating model before expanding tooling.

Data security and identity governance now overlap

Data security priorities increasingly intersect with identity governance because access decisions are often the path by which sensitive data becomes exposed. That overlap is especially relevant where service accounts, workload identities and privileged users can reach high-value data without tight lifecycle controls. The article does not claim that identity and data security are the same discipline, but it does show that programme planning now has to connect them if risk reduction is meant to be measurable.

Practical implication: review where access governance and data protection controls depend on each other and close those handoffs.


  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Data security has become a governance priority, not just a protection layer. When executives rank it alongside broader security planning, the discipline shifts from reactive control buying to portfolio allocation. That matters because data security now competes for budget with identity, cloud and endpoint programmes. The practitioner conclusion is that data security has to be managed as a board-visible risk domain, not a tactical subsystem.

The people, process and technology frame is a useful warning about false maturity. Organisations often buy controls before they define ownership, escalation and data handling rules. This report summary reinforces that a tool-first posture will not produce consistent protection if the operating model is weak. The practitioner conclusion is that governance design must precede scale.

Identity-aware data security: access governance and data protection are converging around the same high-value assets. Service accounts, privileged users and machine access paths can all become the route to sensitive data if lifecycle and authorisation controls are not joined up. The practitioner conclusion is that identity programmes must be evaluated for how well they reduce data exposure, not only how well they manage accounts.

Data security investment signals a broader shift in security architecture. The article suggests that practitioners are being asked to justify controls by business outcomes rather than by technical preference. That changes prioritisation across IAM, NHI and data teams because the real question becomes which controls reduce exposure fastest across the most valuable data paths. The practitioner conclusion is that programme design should start from data risk, then map identity controls to it.

What this signals

Data security investment is becoming a planning signal for the wider security programme. Teams should expect board and executive scrutiny to focus less on individual tools and more on whether control coverage matches business risk.

Identity and data governance will continue to converge. Where privileged access, service accounts or workload identities reach sensitive datasets, the maturity test is whether access decisions and data controls are managed as one operating model.


For practitioners

  • Define a data security investment model Tie planned spending to named business risks, protected data classes and decision owners so the budget conversation is anchored in outcomes rather than features.
  • Map people, process and technology gaps Identify where ownership, escalation and control execution break down before adding more tooling, especially in classification and access workflows.
  • Connect identity controls to data exposure paths Review how privileged users, service accounts and workload identities reach sensitive datasets, then prioritise the access paths that create the largest blast radius.
  • Use data risk to sequence governance work Start with the data sets that carry the most operational or regulatory impact, then align access review, protection and monitoring effort to those assets first.

Key takeaways

  • Data security is moving up the priority list because executives are treating it as a programme-level issue rather than a narrow technical concern.
  • The report summary points to people, process and technology as the real benchmark, which means governance quality will shape results more than product selection alone.
  • IAM and NHI teams need to show how access controls reduce data exposure, because the same identity paths often determine whether sensitive information stays protected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe article is about prioritising security investment through a governance lens.
PR.DS-01 — Data-at-Rest ProtectionData security spending is directly about protecting sensitive data assets.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity governance shapes who can reach sensitive data in practice.
Recommendation — Use risk appetite and business impact to sequence data security investments. Map protection controls to the data sets that create the highest exposure. Review access entitlements on the paths that expose sensitive datasets.
CIS Controls v8CIS-5 — Account ManagementIdentity and access ownership are part of the data security operating model.
Recommendation — Assign and review account ownership for identities that can reach sensitive data.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCloud data security depends on governing access to sensitive resources.
Recommendation — Align IAM controls with the data classes and cloud assets they protect.

Key terms

  • Data Security: Data security is the set of technical and operational controls that protect information from unauthorized access, alteration, disclosure, and loss. It typically includes authentication, authorization, encryption, monitoring, and recovery measures that reduce exposure and preserve confidentiality, integrity, and availability.
  • People, Process, And Technology: People, process, and technology is a simple operating model used to examine whether security capability is supported by ownership, repeatable workflows, and enforceable controls. For identity programmes, it helps show when one layer is mature while the others still leave human or non-human access exposed.
  • Data Exposure Path: A data exposure path is the route by which sensitive information becomes reachable by people or systems that should not have access. It can emerge through permissive roles, shared storage, ingestion workflows, or unmanaged copies that outlive the original business need.
  • Security Investment Prioritisation: Security investment prioritisation is the discipline of deciding where budget and effort should go first based on risk, impact and governance gaps. It matters when multiple security programmes compete for resources and leaders need a defensible way to sequence work.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org