DOMAIN 2 OF 8

Asset Security — Why Data Lifecycle Is the New Perimeter

Data classification, retention, and ownership are quietly the most leveraged controls in a modern security program. Lessons on building asset security that survives contact with reality.

Ishmael Chibvuri — Cybersecurity StrategistStrategic perspective by Ishmael Chibvuri, CISM · updated 6m ago

Asset security is the domain everyone agrees matters and almost nobody invests in until something goes wrong. That's a mistake I see organizations make again and again, and the cost of getting it wrong has gone up sharply now that data — including model training data — moves across more boundaries than ever.

What's shifting right now

  • Classification has to be machine-readable. Spreadsheet-based classification schemes break the moment you try to enforce policy at scale. The teams winning are the ones tagging data at the source (object stores, warehouses, message queues) and letting downstream policy engines do the rest.
  • Retention is now a contested decision. Litigation, regulator demands, AI-training appetite, and minimization mandates pull in opposite directions. Defensible retention policies are no longer a paperwork exercise; they're a board-visible position.
  • Data sovereignty is back, harder. GDPR was the opening act. India's DPDPA, Saudi PDPL, China's PIPL, and a wave of US state laws all impose location and processing constraints. Architects are designing for jurisdiction the way they used to design for region.

What keeps proving true

  • "Crown jewels" is a useful frame only if it's exclusive. If everything is critical, nothing gets the level of protection critical actually requires.
  • Encryption is not a control unless someone owns the keys. Cloud-native KMS defaults often leave the provider holding both halves; map that explicitly.
  • The hardest data problem in any company is the data nobody knows exists. Discovery scans run quarterly are not discovery.

The feed below is where I watch privacy regulators, data-protection vendors, and the breach economy intersect.

// LIVE FEED

Latest from across the industry

30 items · 5 sources
BleepingComputer2h ago

Race Against Time: Why Faster Vulnerability Alerts Matter

Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them. SecAlerts explains why faster vulnerability alerts can help reduce exposure and improve response times. [...]

Help Net Security2h ago

Brute-force attack triggers Dashlane account lockouts

Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after us…

BleepingComputer4h ago

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attack…

Future of Privacy Forum4d ago

SB 5 in Five: What to Know About Connecticut’s New AI Law

Connecticut’s SB 5 fits a lot of AI obligations into a small bill number. This week, Governor Lamont (D) signed the 39-section bill into law, creating new requirements across several fast-moving areas of AI policy, incl…

Future of Privacy Forum1w ago

Colorado Revises Its AI Act: What Changed and Why

On May 15, Governor Polis signed SB 189, revising the Colorado AI Act (CAIA) after two years of intense negotiations and national debate over the original 2024 law’s approach to AI regulation. The revised law, the Color…

Future of Privacy Forum3w ago

Taking stock: The Impact of the India AI Impact Summit 2026

India’s hosting of the AI Impact Summit 2026 was an ambitious undertaking. With 600,000 attendees and 92 signatories to the New Delhi Declaration, the Summit was a showcase of a Global South country taking a leading rol…