Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Data-in-use risk is shifting insider controls beyond files


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: More than 60% of blocked activity and policy violations occurred in everyday channels like web apps, email, and instant messaging, while ChatGPT-related blocks surged 86% from Q3 to Q4 and free-form text and screenshots rose in blocked content, according to Safetica’s Data Protection Trends report. The real control problem is moving from file-centric policy to context-aware governance of data-in-use.

NHIMG editorial — based on content published by Safetica: Data Protection Trends and the shifting insider-risk surface

By the numbers:

Questions worth separating out

Q: What should teams do when sensitive data is copied into collaboration tools?

A: Treat the copy event as a new governance checkpoint, not a harmless duplication.

Q: Why do generative AI tools increase data security risk?

A: Generative AI tools increase risk because they expand the number of places where sensitive content can be ingested, copied, surfaced, or misused.

Q: What do organisations get wrong about blocking risky data movement?

A: They often assume a blocked channel means the risk has been reduced.

Practitioner guidance

  • Map sensitive-data movement across collaboration channels Inventory where sensitive content actually moves across web apps, email, instant messaging, cloud tools, and USB.
  • Apply context-aware controls to routine work surfaces Use role, destination, device posture, and content type to decide whether a transfer is allowed.
  • Treat AI prompts and outputs as governed data flows Classify copied text, pasted prompts, screenshots, and generated outputs as part of the protected data lifecycle.

What's in the full report

Safetica's full report covers the operational detail this post intentionally leaves for the source:

  • Quarter-over-quarter trend tables showing how blocked activity shifted across email, web, chat, cloud, and USB channels
  • Breakdowns of which content types were blocked most often, including free-form text, screenshots, and AI-related interactions
  • The underlying aggregate methodology behind the anonymized H2 2025 signal set
  • Visual comparisons that show how user behaviour changed when one channel was restricted

👉 Read Safetica's Data Protection Trends analysis of insider-risk shifts in H2 2025 →

Data-in-use risk is shifting insider controls beyond files?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16123
 

Data-in-use is becoming the new center of insider-risk governance. The report shows that risk is no longer concentrated in obvious file transfer events. It is increasingly embedded in routine collaboration, which makes the control problem less visible and more persistent. That means identity and data teams need to govern the work surface itself, not just repositories and endpoints.

A question worth separating out:

Q: How do organisations know whether insider threat controls are actually working?

A: They should look for reduced standing privilege, faster revocation after role change, better session traceability, and fewer unexplained data movement events. If alerts keep firing but entitlements remain broad and offboarding is slow, the control environment is not improving. The signal is not noise volume, but narrower blast radius and quicker containment.

👉 Read our full editorial: Data-in-use risk is shifting insider security beyond documents



   
ReplyQuote
Share: