惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Martin Fowler
Martin Fowler
雷峰网
雷峰网
IT之家
IT之家
小众软件
小众软件
M
MIT News - Artificial intelligence
博客园 - 聂微东
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
About on SuperTechFans
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
C
Check Point Blog
云风的 BLOG
云风的 BLOG
腾讯CDC
H
Help Net Security
Y
Y Combinator Blog
I
InfoQ

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Agentic Payments in Financial Services | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA
Unstructured Data Surges as Enterprises Struggle to Maint...
2026-03-30 · via Cloud Security Alliance

Despite growing awareness of unstructured data risks, many organizations lag in scalable security as cloud, AI, and automation deployments accelerate

SEATTLE – March 31, 2026 – The Rise in Unstructured Data and AI Security Risks, a new survey report from the Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, has revealed that traditional security and governance practices are straining to keep pace with the rampant growth of unstructured data. The survey, commissioned by Thales, the leading global technology and security provider, found that while three-quarters of organizations are confident in their ability to secure unstructured data, more than two-thirds (68%) report that less than 80% of their unstructured data is protected—a security gap exacerbated by limited visibility and distributed environments. 

Unstructured data is a prime target for breaches and cyberattacks because it often contains sensitive information yet remains difficult to track, govern, and secure at scale. The survey highlights strong concern among executives and IT professionals about gaining visibility into this unstructured (and potentially sensitive) data—often buried in documents, emails, chats, images, and other free-form files—where critical assets such as personally identifiable information (PII), financial records, intellectual property, and legal documents are housed. Scattered, inconsistently labeled, and difficult to monitor, unstructured data presents a high-value opportunity for attackers seeking credentials, confidential business plans, trade secrets, payment data, and other exploitable assets.

“The explosive growth of unstructured data—estimated by Gartner to account for between 70% and 90% of enterprise data—has become a defining characteristic of modern organizations. While it enables significant operational value, it also introduces substantial security risk. What is clear from this study is that as unstructured data continues to expand and spread across environments, many organizations are struggling to keep pace with the visibility, governance, and protections needed to manage it securely,” said Hillary Baron, AVP of Research, Cloud Security Alliance.

Among the survey’s key findings:

  • Unstructured data is fueling enterprise data growth. Organizations reported that unstructured data accounted for approximately 33% of enterprise data, with semi-structured data making up an additional 21%. Additionally, nearly a third (29%) stated that unstructured data accounted for more than half of their annual data growth. 
  • Persistent gaps in visibility, classification, and sensitive data awareness undermine unstructured data security. More than half (56%) of those surveyed indicated they have only partial visibility into where their data is stored. Despite listing security (74%), governance (57%), privacy (54%), and compliance (50%) as top concerns, companies are struggling to execute foundational controls such as sensitive data protection, access monitoring, and classification scanning.
  • Organizations are overestimating their ability to secure unstructured data. Seventy-five percent of organizations expressed confidence in their ability to secure unstructured data, even as 68% reported that a significant portion of their unstructured data remains unprotected. Still another 10% are unsure of their actual coverage. 
  • Fragmented tools, manual processes, and shared ownership limit scalability. Nearly one-third (32%) of organizations use 11 or more tools to manage their unstructured data, and of those, 12% rely on at least 21 tools. This tool sprawl also extends to the types of tools in use: data encryption (62%), cloud security (60%), application security (59%), and identity and access management (56%) are among the most popular.
  • Artificial intelligence amplifies existing security blind spots. Organizations view AI as both a top future threat (47%) and a core security capability (40%) for unstructured data. While many said they plan to rely on AI for detection, classification, and automation, foundational gaps remain. Only 9% of organizations reported having real-time scanning capabilities, and 23% can’t scan at all, raising concerns that AI may amplify existing blind spots rather than improving security outcomes.

”As the CSA research highlights, today's organizations are generating and sharing unstructured data at a pace that traditional tools and governance models were never designed to handle. This puts them at a critical point of failure, where inconsistent and manual approaches can no longer keep up with the volume, velocity, and distribution of data across cloud, collaboration platforms, and AI-driven environments. Without addressing these gaps, AI, automation, and emerging technologies like post-quantum cryptography will only increase exposure. Establishing a unified, scalable approach to securing unstructured data is now an operational imperative,” said Todd Moore, Vice President, Thales Data Security. 

The survey and report were commissioned to better understand the industry’s knowledge, attitudes, and opinions regarding unstructured data, its security and challenges. Thales financed the project and co-developed the questionnaire with CSA research analysts. The survey was conducted online by CSA in November 2025 and received 210 responses from IT and security professionals from organizations of various sizes and locations. CSA’s research analysts performed the data analysis and interpretation for this report.

Download The Rise in Unstructured Data and AI Security Risks.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite technical experts, industry practitioners, and varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovation and pragmatic security execution. Visit CSA’s website to learn more.

Media Contact
Kristina Rundquist
ZAG Communications for the CSA
[email protected]