Data security becomes critical because data is no longer anchored to a single perimeter. It moves across cloud platforms, mobile devices, and laptops, which makes location-based trust unreliable. When access is tied to sensitivity, user role, and context, organisations can protect customer records, intellectual property, and financial data even as the attack surface expands.
Why Zero Trust makes data security a control, not a storage choice
When data moves between SaaS platforms, mobile endpoints, browsers, and personal devices, the control point has to move with it. That is why Zero Trust treats data security as an enforcement problem, not a network placement problem: access must be evaluated every time, and protection has to follow the data even when the device or service boundary changes.
The practical implication is that organisations cannot rely on “inside the network” assumptions to protect sensitive information. A spreadsheet in cloud storage, a record exported to a laptop, or a file previewed on a phone all need consistent policy, encryption, and access decisions if the same data is to remain protected across very different trust zones.
- Classify the data first, then apply controls based on sensitivity rather than location.
- Use policy enforcement that remains consistent across cloud and endpoint contexts.
- Treat every transfer, sync, preview, and download as a new decision point.
As a cross-check, zero-trust guidance centres on least privilege and continuous verification, which is why NIST SP 800-207 Zero Trust Architecture is the right architectural anchor for this problem.
Why cloud services and personal devices expand the attack surface
Each new service or device introduces a new place where data can be copied, cached, synced, cached in offline mode, or exposed through misconfiguration. Cloud services add sharing links, integrations, and tenant configuration risk; personal devices add local storage, unmanaged apps, and weaker visibility. The result is that the same record can exist in several places at once, each with different control quality.
This is also where policy drift becomes dangerous. If one platform enforces strict sharing rules while another allows broad download or forwarding, the weakest copy becomes the easiest route for leakage. Data security has to be designed for replication, not just for primary storage.
- Review where sensitive data is duplicated, not only where it is originally stored.
- Harden sharing, export, and offline access paths before broad user rollout.
- Prefer controls that survive sync and cross-device movement.
For cloud-aligned control coverage, CSA Cloud Controls Matrix is useful because it maps cloud security, IAM, and data security into one control view.
Practitioner guidance for protecting sensitive data across trust boundaries
Security teams should start by defining which data classes are allowed on unmanaged or personal devices, then enforce those decisions through conditional access, encryption, and revocation capability. The key judgement is whether the organisation can still protect the information after it leaves the primary system, because if it cannot, the policy is weaker than the user workflow.
One common mistake is over-focusing on the device while under-controlling the data. If the data can be exported, shared externally, or opened in an untrusted app, endpoint hardening alone will not close the gap. Strong practice is to pair access policy with data-centric controls such as sensitivity labels, download restrictions, and traceable sharing.
Practitioner takeaway: If your Zero Trust model cannot make the data itself carry policy across cloud and personal devices, you still have a perimeter problem, only distributed across more places.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | Data access must be continuously verified as information moves across trust boundaries. |
| Recommendation — Apply PR.AC controls to enforce sensitivity-based access decisions across cloud and endpoint contexts. | ||
| NIST Zero Trust (SP 800-207) | 3.1 — Policy Engine | Zero Trust depends on policy decisions that follow the data, not the network location. |
| Recommendation — Use the policy engine to evaluate each access request against data sensitivity and context. | ||
| CIS Controls v8 | 6 — Access Control Management | Sensitive data crossing devices and services needs tightly managed access and revocation paths. |
| Recommendation — Restrict, review, and revoke access paths for data that can move beyond managed systems. | ||
| ISO/IEC 42001:2023 | A.5 — Policies for AI system use | Only if AI-mediated access or processing is part of the data movement path, governance must define acceptable handling. |
| Recommendation — Define governance and accountability rules for AI-mediated handling of sensitive data. | ||
Related resources from NHI Mgmt Group
- How should security teams modernise asset management when sensitive data moves across cloud, endpoints, applications and services?
- How should security teams assess whether compliance tools are enough when sensitive data moves across SaaS, cloud, and AI systems?
- How should security teams govern personal data across APIs and cloud services under DPDP?
- How should technology companies prioritize data security work when data sprawl hides sensitive information across cloud, SaaS, and on-prem environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org