In this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, aboutIn this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, about

Visibility Isn’t Control: Kiteworks on Why 2026 Will Be the Year Data Security Gets Enforced

2026/01/07 17:16
6분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

In this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, about Kiteworks’ newly released Data Security and Compliance Risk: 2026 Forecast Report and why many organizations are entering a critical inflection point. Based on a global survey of security, IT, compliance, and risk leaders, the report argues that enterprises are moving faster than their ability to control sensitive data—especially as AI-driven workflows become autonomous. Freestone and Spencer explain why visibility alone is no longer enough, how enforcement gaps are widening, and what leaders must do now to avoid costly failures in the year ahead.

Q: What’s the clearest signal that 2026 will feel different from “normal” cyber risk?

Tim Freestone: Agentic AI is the signal—not because it’s flashy, but because it fundamentally changes the pace of risk. We’re moving from tools that suggest actions to systems that actually take them. That compresses the time between a mistake and real-world impact, especially when those systems interact with sensitive data or downstream workflows. The risk isn’t just that AI might leak data. It’s that AI is being embedded into everyday business processes—routing, summarizing, extracting, and making decisions—where even small policy gaps can turn into large incidents. Many organizations are adopting these systems to gain speed and productivity, while governance is expected to catch up later. In 2026, teams that treat agentic AI like a standard SaaS rollout will learn quickly that autonomy doesn’t wait for quarterly control reviews.

Q: Your report suggests data security posture management (DSPM) is becoming table stakes. Why isn’t that enough?

Patrick Spencer: Because visibility is not the same as control, and too many organizations stop at visibility. DSPM can show you where sensitive data lives and how it moves, but if you can’t consistently enforce classification and tagging across channels, you’re still making decisions with incomplete authority. That’s how sensitive information drifts into unmanaged workflows, poorly governed shares, or partner exchanges that don’t apply the same controls. It’s also why incident response slows down—teams spend the first day or two debating what the data actually was and where it went instead of containing the problem. Some organizations buy monitoring to feel more confident, when what they really need is enforcement to be safer.

Q: Why does the report emphasize centralized AI data gateways so strongly?

Tim Freestone: Because AI control sprawl is already happening, and sprawl is where accountability breaks down. When each team deploys its own AI tools and point controls, you end up with inconsistent policies, uneven logging, and unclear responsibility when something goes wrong. A centralized AI data gateway provides a control plane—a single place to apply policies consistently across copilots, agents, APIs, and integrations as they scale. It also forces discipline around questions many organizations postpone: what data can be used, for what purpose, with what retention, and with what evidence trail. Centralization doesn’t remove risk, but it prevents hundreds of quiet exceptions from becoming the operating model. In 2026, patchwork AI governance won’t scale—it will fail precisely where leaders assume they’re covered.

Q: If you had to identify one missing control that will hurt teams first, what would it be?

Patrick Spencer: Containment. Containment is what protects you when the “unlikely scenario” becomes a routine incident. Monitoring and human review matter, but they’re upstream controls. Containment is what you rely on when something moves too fast or behaves unexpectedly. Many organizations talk about responsible AI while lacking practical safeguards like purpose limitation or the ability to immediately isolate or terminate a misbehaving agent. When sensitive data is involved, that’s not a theoretical gap—it’s an operational and financial one. If an agent pulls too much data or routes it incorrectly, you don’t want deliberation; you want a hard stop that works instantly. In 2026, the difference between observing risk and stopping it will define outcomes.

Q: You describe evidence-quality audit trails as a “keystone.” Why are they so critical?

Tim Freestone: Because governance without evidence is just an opinion—and auditors, regulators, and customers don’t accept opinions. Evidence-quality audit trails let organizations answer fundamental questions quickly and defensibly: who accessed the data, what happened to it, where it went, what controls applied, and what the result was. When sensitive data moves across multiple channels with uneven logging, you don’t have a coherent narrative—you have fragments. That’s why incident response drags on and communication breaks down. Strong audit trails also influence internal behavior because actions are provable, not just “logged somewhere.” In 2026, “show me the proof” will be the default expectation, which makes building for proof no longer optional.

Q: What’s the most underestimated aspect of third-party risk heading into 2026?

Patrick Spencer: The coordination gap. Many organizations still treat third-party risk as a documentation exercise—questionnaires and attestations—while real risk shows up during an incident that requires partners to act together under pressure. Without shared response playbooks and aligned controls, the first true collaboration often happens during a breach. AI complicates this further because data can be transformed, summarized, or retained in ways traditional controls weren’t designed to capture. If you don’t understand how partners handle your data inside AI systems, you’re accepting risk you can’t measure or explain later. You can outsource work, but you can’t outsource accountability.

Q: If you could mandate one board-level discussion in early 2026, what would it be?

Tim Freestone: Accountability for AI governance—who owns it, how it’s measured, and what “good” actually looks like in plain language. Boards don’t need to debate model architectures, but they should demand enforceable controls, defensible evidence, and clear escalation paths when AI-driven processes fail. The most important question isn’t “Are we using AI?” It’s “Can we prove we’re controlling it everywhere sensitive data moves?” When regulators, customers, or partners ask for proof, you either have it or you don’t—and that moment usually arrives under stress. Boards that treat AI governance as a strategic risk will drive investment in enforcement and evidence. Those that don’t will be surprised by outcomes they can’t explain. In 2026, ambiguity isn’t a strategy—it’s a liability.

For a deeper dive into these findings and what they mean for enterprise security leaders, explore Kiteworks’ Data Security and Compliance Risk: 2026 Forecast Report.

Comments
시장 기회
스레숄드 로고
스레숄드 가격(T)
$0.006086
$0.006086$0.006086
-2.05%
USD
스레숄드 (T) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

추천 콘텐츠

German Hacker Arrested in Bangkok Over Crypto Extortion, Faces 74 Cyber Crime Charges

German Hacker Arrested in Bangkok Over Crypto Extortion, Faces 74 Cyber Crime Charges

The post German Hacker Arrested in Bangkok Over Crypto Extortion, Faces 74 Cyber Crime Charges appeared on BitcoinEthereumNews.com. Thai police arrested a 27-year
공유하기
BitcoinEthereumNews2026/04/12 17:01
Arthur Hayes injects $1.1M more into HYPE as Bitwise pushes Hyperliquid ETF

Arthur Hayes injects $1.1M more into HYPE as Bitwise pushes Hyperliquid ETF

In a new on-chain move, the trader arthur hayes expanded his exposure to the HYPE token while the market tracks developments around Hyperliquid products. New $1
공유하기
The Cryptonomist2026/04/12 15:53
Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference

Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference

The post Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference appeared on BitcoinEthereumNews.com. Key Takeaways Ethereum’s new roadmap was presented by Vitalik Buterin at the Japan Dev Conference. Short-term priorities include Layer 1 scaling and raising gas limits to enhance transaction throughput. Vitalik Buterin presented Ethereum’s development roadmap at the Japan Dev Conference today, outlining the blockchain platform’s priorities across multiple timeframes. The short-term goals focus on scaling solutions and increasing Layer 1 gas limits to improve transaction capacity. Mid-term objectives target enhanced cross-Layer 2 interoperability and faster network responsiveness to create a more seamless user experience across different scaling solutions. The long-term vision emphasizes building a secure, simple, quantum-resistant, and formally verified minimalist Ethereum network. This approach aims to future-proof the platform against emerging technological threats while maintaining its core functionality. The roadmap presentation comes as Ethereum continues to compete with other blockchain platforms for market share in the smart contract and decentralized application space. Source: https://cryptobriefing.com/ethereum-roadmap-scaling-interoperability-security-japan/
공유하기
BitcoinEthereumNews2025/09/18 00:25

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!