TL;DR: Data security programs often fail because teams build isolated controls instead of a coherent strategy, and because the business treats protection as a security-only concern, according to Cyera’s DataSec 2024 conference recap. The takeaway for identity and access teams is that governance breaks when visibility, control, and ownership are not designed together.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Tips to Build A Successful Data Security Program”.
Key questions
Q: What breaks when data protection is built as isolated controls?
A: When discovery, classification, access control, and response are handled as separate efforts, teams lose the feedback loop that turns findings into governed action.
Q: Why does a data security programme stall without business buy-in?
A: Because enforcement then looks like security-only friction rather than a shared operating model.
Q: How do teams know whether visibility is actually enough for governance?
A: Visibility is sufficient only when it gives reviewers enough context to decide who should have access, what data is sensitive, and whether that access still matches the business need.
Practitioner guidance
- Build a data protection operating model Define how discovery, classification, entitlement decisions, and exception handling move through one governance process instead of separate tool workflows.
- Tie visibility to access review Use current data inventory and usage context when certifying access, so reviewers can judge whether entitlement still matches the business need.
- Create shared ownership with business teams Assign privacy, legal, compliance, product, and data stakeholders explicit decision rights so controls are treated as part of operations, not only security.
Bottom line: Data protection programmes fail when organisations layer tools without a shared strategy, because fragmentation breaks the path from discovery to governed action.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Data protection fails first as a governance design problem, not a control-selection problem. Organisations often mistake layering tools for building a programme, but fragmentation leaves no clear line from discovery to decision to enforcement. That is why visibility and operating model design must be treated as core control requirements, not supporting features. Practitioners should judge data protection by whether it changes how the business governs access, not by how many tools are deployed.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What is the difference between data security and data protection in practice?
A: Data security aims to prevent unauthorized access, alteration, or loss of data during normal operations. Data protection is about preserving integrity and enabling recovery after destructive events, such as disasters or attacks. In practice, security reduces the chance of compromise, while protection provides the backup and recovery layer that limits lasting damage when prevention fails.
👉 Read our full editorial: Data protection programs fail when visibility and buy-in lag