TL;DR: 60% of enterprises lack visibility into at least half of their data estate, leaving cyber resilience, recovery, and AI security decisions built on incomplete discovery and classification, according to Cyera research. The governance gap is now operational, because you cannot protect or recover what you cannot consistently find.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “A Future-Ready Approach to Securing Data for Cyber Resilience with Cyera and Cohesity”.
Key questions
Q: How should security teams improve data visibility before expanding cloud and AI programs?
A: Security teams should start with a clear inventory of where sensitive data lives, who can access it, and how it moves across cloud and endpoint environments.
Q: Why does incomplete data discovery weaken cyber resilience?
A: Because recovery, protection, and access decisions all depend on knowing what data exists, where it resides, and how sensitive it is.
Q: What are the signs that data classification is too weak for AI programmes?
A: Common signs include repeated surprises during data access reviews, inconsistent sensitivity labels across the same dataset, and recovery plans that cannot distinguish critical records from low-value content.
Practitioner guidance
- Map sensitive data visibility gaps Inventory which cloud, SaaS and endpoint repositories still lack reliable discovery or classification, then rank them by business criticality and AI exposure.
- Tie AI use cases to source datasets Require each AI use case to document the datasets it reads, the sensitivity labels attached to those datasets, and the access paths that can reach them.
- Unify recovery prioritisation and classification Use data classification to drive restore order, validation requirements and post-recovery access approvals so critical data is restored first.
Bottom line: Weak data visibility undermines cyber resilience because protection and recovery decisions are only as good as the data inventory behind them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Data visibility is the control plane for AI-era resilience: when organisations cannot locate or classify sensitive data, every downstream control is operating with partial truth. Discovery determines what can be protected, what can be restored, and what can safely be used by AI systems. The practitioner conclusion is simple: visibility is no longer an inventory exercise, it is the prerequisite for operational cyber resilience.
A few things that frame the scale:
- Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: When should organisations prioritise data visibility before expanding AI or cloud initiatives?
A: Organisations should prioritise visibility before expansion when they cannot reliably answer which data is sensitive, where it resides, or who can access it. Without that baseline, AI and cloud projects increase risk faster than controls mature. Visibility creates the decision layer for classification, policy enforcement, remediation, and audit readiness across changing environments.
👉 Read our full editorial: Data visibility gaps are weakening cyber resilience for AI adoption