惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
Microsoft Security Blog
Microsoft Security Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Vercel News
Vercel News
Application and Cybersecurity Blog
Application and Cybersecurity Blog
C
Check Point Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
W
WeLiveSecurity
The Hacker News
The Hacker News
L
LINUX DO - 热门话题
T
Tenable Blog
Hugging Face - Blog
Hugging Face - Blog
Google Online Security Blog
Google Online Security Blog
博客园 - Franky
P
Proofpoint News Feed
H
Hacker News: Front Page
P
Privacy & Cybersecurity Law Blog
月光博客
月光博客
P
Proofpoint News Feed
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
博客园_首页
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
Forbes - Security
Forbes - Security
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Attack and Defense Labs
Attack and Defense Labs
N
News and Events Feed by Topic
博客园 - 叶小钗
T
Threat Research - Cisco Blogs
aimingoo的专栏
aimingoo的专栏
D
Darknet – Hacking Tools, Hacker News & Cyber Security
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
MongoDB | Blog
MongoDB | Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hacker News - Newest:
Hacker News - Newest: "LLM"
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
O
OpenAI News
G
Google Developers Blog
Martin Fowler
Martin Fowler
罗磊的独立博客
S
SegmentFault 最新的问题
T
Tor Project blog
量子位

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Deepfake era demands proof-based security, not just awareness Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How to improve the SOC analyst experience -- and why it matters How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam Watch your words: Tim Brown's advice for CISOs News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
Beyond the perimeter: The shift to data-centric protection | TechTarget
Damon Garn · 2026-06-29 · via Search Security Resources and Information from TechTarget

Traditional network boundaries have all but disappeared. Enterprises must find new ways to protect their digital assets in a world where SaaS and multi-cloud deployments dominate.

The traditional network perimeter has effectively disappeared, creating a major data security problem for CISOs and their teams.

Organizations today operate across on-premises, multi-cloud, API and edge systems with no fixed boundaries. Data traverses SaaS platforms and cloud services, remote user systems, APIs and partner ecosystems, changing the data security game. SaaS sprawl, shadow IT and API-driven integrations only make the data security challenge more difficult.

Simply put, data protection has moved from perimeter security to distributed, lifecycle-based controls. Organizations must unify governance, encryption, tokenization and policy-based access into a single operating model to protect the organization's data, maintain resilience, meet compliance obligations and retain the performance that employees and customers expect.

The focus must shift from infrastructure security to data-centric protection, where identity and context -- not location -- determine access decisions. This requires applying consistent controls where data is created, stored, shared or processed.

Governance, visibility and data lifecycle control

Effective data protection begins with governance. Organizations need clear data ownership models. Define responsibility for classifying data, approving access and managing protection policies across business units, cloud platforms and SaaS applications. Without accountability, security controls become fragmented and inconsistent.

Visibility is equally crucial. Continuously discover and monitor sensitive data across cloud, SaaS, databases, endpoints and edge environments. Data classification enables appropriate protections based on business value, sensitivity and regulatory requirements.

Establish data lifecycle controls to protect data from creation and active use to sharing, retention, archival and deletion. Lifecycle-based policies keep controls consistent and comprehensive as data moves among systems, platforms and users. Data lineage and audit trails provide the transparency needed for compliance and incident investigations. Use automated monitoring to identify policy drift and emerging risks before they become security incidents.

Core protection model: Encryption, tokenization and policy enforcement

The core data-centric protection model supports safe, scalable data use across diverse systems. It relies on encryption, tokenization and policy-based access controls.

  • Encryption is applied to data at rest, in transit and in use.
  • Tokenization replaces sensitive data with placeholder values, aka tokens, in analytics, SaaS tools and operational systems.
  • Policy-based access control enables dynamic enforcement based on identity, device, location and data sensitivity.

These capabilities extend beyond the traditional infrastructure into APIs, microservices and third-party integrations. Consistency is critical -- fragmented policies create bypass paths and compliance gaps. Controls must also minimize friction for engineering teams while maintaining strict enforcement.

Key management and cryptographic control

Key management a critical component of data protection, providing security and resilience while ensuring regulatory compliance. Establish centralized governance over key policies while permitting distributed enforcement where operationally necessary, such as SaaS systems, edge environments and cloud platforms.

Effective key management spans secure key generation, storage, rotation, revocation and auditing. Automate these processes to reduce operational complexity and minimize human error. Use hardware security modules, which safeguard keys in tamper-resistant hardware, for additional protection for highly sensitive workloads.

Multi-cloud environments create unique key management challenges, including key portability, policy consistency and potential vendor lock-in. Clear separation of duties, comprehensive audit trails and continuous monitoring help ensure that only authorized users and systems can access protected data.

Performance, automation and risk-based architecture

Protecting data at scale requires balancing strong security with operational efficiency. Encryption and tokenization can introduce latency and computational overhead, particularly in high-volume cloud environments and resource-constrained edge deployments. Classification enables organizations to adopt a risk-based approach that applies the strongest protections to the most sensitive and business-critical data while enabling efficient automated management.

Automation keeps controls consistent across multi-cloud, SaaS and edge environments. Policy-as-code and continuous integration/continuous delivery pipeline integration enforce security requirements automatically throughout the data lifecycle. Automated monitoring and real-time policy enforcement also reduce the risk of configuration errors, avoid control gaps and enhance visibility.

From an architectural perspective, organizations should limit the impact of breaches through segmentation, isolation and zero-trust policies. The goal extends beyond preventing unauthorized access to include containing incidents, reducing exposure and maintaining business continuity when security events occur.

Resilience, incident response and business continuity

Modern data protection strategies assume breaches are inevitable. Establishing data-centric incident response enables rapid containment through:

  • Encryption key revocation and invalidation to address encryption-based incidents.
  • Immutable backups and encrypted recovery systems to support operational continuity.
  • Automated responses to reduce dwell time and limit exposure.
  • Incident planning aligned with regulatory obligations and business uptime requirements to ensure availability.

With effective governance and planning in place, data resilience becomes a competitive advantage, not just a compliance requirement.

Regulatory alignment and business value

Strong data protection supports trust, continuity and enterprise scalability across diverse, distributed environments. Regulatory alignment ensures data protection controls map to frameworks, such as GDPR, HIPAA and industry-specific requirements, through consistent, auditable enforcement. Automated classification, encryption and access logging reduce compliance burden and operational overhead while improving accuracy and traceability.

From a business perspective, evaluate data protection in terms of risk reduction, operational continuity and breach-impact mitigation, not just cost. Strong controls support customer trust, market expansion and reduced financial exposure.

The perimeter is gone. The question is no longer whether data will be exposed, but how quickly security teams can detect, contain and recover when it is. Organizations that succeed will be those that treat data as a continuously governed asset, not an infrastructure byproduct.

Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to Informa TechTarget, The New Stack and CompTIA Blogs.

Dig Deeper on Data security and privacy