Organizations Overestimate Data Security Confidence, Says AvePoint Research
A recent study conducted by AvePoint reveals a troubling disconnect between organizations’ confidence in their data security measures and their actual experiences with unauthorized access incidents involving artificial intelligence (AI). The findings, reported in AvePoint’s third annual State of AI Report, indicate that an impressive 82.7% of surveyed organizations expressed being "very" or "extremely" confident in their ability to prevent unauthorized AI data access. However, a striking 72% of these confident entities reported already facing an AI-related unauthorized access incident within the last year. This contradiction suggests that many organizations may not be as prepared as they believe when it comes to safeguarding sensitive data.
To delve deeper into these insights, Dana Simberkoff, AvePoint’s Chief Risk, Privacy, and Information Security Officer, shared her thoughts in an interview at the Black Hat conference. During their conversation, they explored the stark gap between perceived security and reality, as well as the company’s newly launched product, Kinetic Classification.
Understanding the Core Issue
Simberkoff attributed the overarching problem not to negligence among security teams, but rather to a long-standing neglect of fundamental data hygiene practices. For two decades, the proper tagging and classification of information has been significantly underfunded. Consequently, both human users and automated tools have historically struggled to classify data effectively. Users often find themselves either underclassifying sensitive information to circumvent security measures or overclassifying everything to simplify their workflows.
In response to this persistent issue, AvePoint developed Kinetic Classification, a product designed to continuously reassess data sensitivity as it evolves. Departing from traditional one-time labeling systems that quickly become outdated, Kinetic Classification stands out by adapting to changes in data, thereby providing timely updates on what should remain confidential. Simberkoff emphasized the importance of this dynamic approach, particularly in an AI-centric environment, where the pertinent question shifts from merely determining whether a document is confidential to whether an AI should have access to it at all. "You can build rules for agents around what they can and can’t access based on those types of boundaries," she explained.
Unique Positioning in the Market
In a landscape crowded with vendors emphasizing asset management, Simberkoff delineated AvePoint’s distinct focus. “A lot of vendors here are looking at asset management, looking at the bones, the skeleton,” she noted. “What AvePoint is looking at is the blood, what keeps you alive.” This metaphor highlights how security is not solely about the procedures but also the contextual understanding of content and access. According to her, an effective security strategy requires a layered approach that comprehensively addresses context, content, and access.
Prioritizing Recovery After Breach
In addition to classification, Simberkoff discussed AvePoint’s significant upgrades to its Rapid Recovery system. These updates focus on what organizations should do after a security breach has occurred. The improvements include intelligence recommendations that identify the most critical data to restore first, a wizard feature that allows teams to pre-build and sequence a recovery plan ahead of time, and Express Recovery for Entra ID, which extends prioritized restoration efforts to the identity layer. The objective of these enhancements is to streamline the recovery process, minimizing the manual triage that traditionally follows an incident. This, in turn, enables teams to execute a prepared recovery plan swiftly, even under pressure.
Evidence Through Internal Practices
Simberkoff was adamant that AvePoint’s credibility lies in its own utilization of its products. When the company rolled out Copilot internally, her team employed their classification technology to meticulously prepare for its deployment. This process involved thorough content clean-up and tagging across platforms like SharePoint and OneDrive before allowing AI agents access. The insights gained from this internal process directly informed the product’s ongoing development. Additionally, AvePoint maintains customer advisory boards for continual feedback, and its impressive 25-year track record reinforces its reliability in the industry.
Looking Ahead
Simberkoff’s insights resonate deeply with the evolving narrative in cybersecurity. Her advice for Chief Information Security Officers (CISOs) distills to a powerful reminder: “Metadata is a love note to the future.” This phrase encapsulates the significance of robust classification systems as crucial barriers against unregulated AI access. With AI behaving much like a ceaseless consumer, it is imperative to build structural barriers that delineate permissible data access, and classification plays a crucial role in constructing those defenses.
Despite the risks inherent in an industry often steeped in uncertainty, Simberkoff concluded on an optimistic note. She sees real promise in the potential of AI for predicting and preventing security breaches, indicating that there are considerable opportunities for innovation in this complex landscape. It is indeed an exciting time to be involved in cybersecurity, with the potential for transformative advancements on the horizon.

