Data is everything for the modern enterprise. But companies walk a tricky line between making it available to the right people to foster innovation or improve service levels, and ensuring it's not exposed or seized by bad actors.
Achieving the correct balance of protection and access has become even more pressing recently, as AI and other modern systems rely on vast amounts of data and accelerate its analysis and distribution.
But it's becoming increasingly clear that identity security policies and data access strategies haven't kept pace. Some form of identify compromise is now involved in the majority of cyber-attacks, and lax data protection strategies can leave companies terribly exposed.
This paper puts these issues in context, showing how traditional tools were already failing to cope, even before large language models, generative AI, and AI-powered digital assistants raised the risks around overly permissive data access strategies.