惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
博客园 - 【当耐特】
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
IT之家
IT之家
T
Tailwind CSS Blog
月光博客
月光博客
Vercel News
Vercel News
V
V2EX
Engineering at Meta
Engineering at Meta
B
Blog
Stack Overflow Blog
Stack Overflow Blog
A
About on SuperTechFans
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
腾讯CDC
I
InfoQ

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt
Beyond the perimeter: The shift to data-centric protectio...
Damon Garn · 2026-06-29 · via Search Security Resources and Information from TechTarget

Traditional network boundaries have all but disappeared. Enterprises must find new ways to protect their digital assets in a world where SaaS and multi-cloud deployments dominate.

The traditional network perimeter has effectively disappeared, creating a major data security problem for CISOs and their teams.

Organizations today operate across on-premises, multi-cloud, API and edge systems with no fixed boundaries. Data traverses SaaS platforms and cloud services, remote user systems, APIs and partner ecosystems, changing the data security game. SaaS sprawl, shadow IT and API-driven integrations only make the data security challenge more difficult.

Simply put, data protection has moved from perimeter security to distributed, lifecycle-based controls. Organizations must unify governance, encryption, tokenization and policy-based access into a single operating model to protect the organization's data, maintain resilience, meet compliance obligations and retain the performance that employees and customers expect.

The focus must shift from infrastructure security to data-centric protection, where identity and context -- not location -- determine access decisions. This requires applying consistent controls where data is created, stored, shared or processed.

Governance, visibility and data lifecycle control

Effective data protection begins with governance. Organizations need clear data ownership models. Define responsibility for classifying data, approving access and managing protection policies across business units, cloud platforms and SaaS applications. Without accountability, security controls become fragmented and inconsistent.

Visibility is equally crucial. Continuously discover and monitor sensitive data across cloud, SaaS, databases, endpoints and edge environments. Data classification enables appropriate protections based on business value, sensitivity and regulatory requirements.

Establish data lifecycle controls to protect data from creation and active use to sharing, retention, archival and deletion. Lifecycle-based policies keep controls consistent and comprehensive as data moves among systems, platforms and users. Data lineage and audit trails provide the transparency needed for compliance and incident investigations. Use automated monitoring to identify policy drift and emerging risks before they become security incidents.

Core protection model: Encryption, tokenization and policy enforcement

The core data-centric protection model supports safe, scalable data use across diverse systems. It relies on encryption, tokenization and policy-based access controls.

  • Encryption is applied to data at rest, in transit and in use.
  • Tokenization replaces sensitive data with placeholder values, aka tokens, in analytics, SaaS tools and operational systems.
  • Policy-based access control enables dynamic enforcement based on identity, device, location and data sensitivity.

These capabilities extend beyond the traditional infrastructure into APIs, microservices and third-party integrations. Consistency is critical -- fragmented policies create bypass paths and compliance gaps. Controls must also minimize friction for engineering teams while maintaining strict enforcement.

Key management and cryptographic control

Key management a critical component of data protection, providing security and resilience while ensuring regulatory compliance. Establish centralized governance over key policies while permitting distributed enforcement where operationally necessary, such as SaaS systems, edge environments and cloud platforms.

Effective key management spans secure key generation, storage, rotation, revocation and auditing. Automate these processes to reduce operational complexity and minimize human error. Use hardware security modules, which safeguard keys in tamper-resistant hardware, for additional protection for highly sensitive workloads.

Multi-cloud environments create unique key management challenges, including key portability, policy consistency and potential vendor lock-in. Clear separation of duties, comprehensive audit trails and continuous monitoring help ensure that only authorized users and systems can access protected data.

Performance, automation and risk-based architecture

Protecting data at scale requires balancing strong security with operational efficiency. Encryption and tokenization can introduce latency and computational overhead, particularly in high-volume cloud environments and resource-constrained edge deployments. Classification enables organizations to adopt a risk-based approach that applies the strongest protections to the most sensitive and business-critical data while enabling efficient automated management.

Automation keeps controls consistent across multi-cloud, SaaS and edge environments. Policy-as-code and continuous integration/continuous delivery pipeline integration enforce security requirements automatically throughout the data lifecycle. Automated monitoring and real-time policy enforcement also reduce the risk of configuration errors, avoid control gaps and enhance visibility.

From an architectural perspective, organizations should limit the impact of breaches through segmentation, isolation and zero-trust policies. The goal extends beyond preventing unauthorized access to include containing incidents, reducing exposure and maintaining business continuity when security events occur.

Resilience, incident response and business continuity

Modern data protection strategies assume breaches are inevitable. Establishing data-centric incident response enables rapid containment through:

  • Encryption key revocation and invalidation to address encryption-based incidents.
  • Immutable backups and encrypted recovery systems to support operational continuity.
  • Automated responses to reduce dwell time and limit exposure.
  • Incident planning aligned with regulatory obligations and business uptime requirements to ensure availability.

With effective governance and planning in place, data resilience becomes a competitive advantage, not just a compliance requirement.

Regulatory alignment and business value

Strong data protection supports trust, continuity and enterprise scalability across diverse, distributed environments. Regulatory alignment ensures data protection controls map to frameworks, such as GDPR, HIPAA and industry-specific requirements, through consistent, auditable enforcement. Automated classification, encryption and access logging reduce compliance burden and operational overhead while improving accuracy and traceability.

From a business perspective, evaluate data protection in terms of risk reduction, operational continuity and breach-impact mitigation, not just cost. Strong controls support customer trust, market expansion and reduced financial exposure.

The perimeter is gone. The question is no longer whether data will be exposed, but how quickly security teams can detect, contain and recover when it is. Organizations that succeed will be those that treat data as a continuously governed asset, not an infrastructure byproduct.

Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to Informa TechTarget, The New Stack and CompTIA Blogs.

Dig Deeper on Data security and privacy