As organizations accelerate their cloud adoption, embrace hybrid work models, and struggle with data privacy regulations, securing sensitive information has never been more complex. The threat landscape is evolving, with cybercriminals leveraging AI-driven attacks, insider threats becoming more sophisticated, and data breaches continuing to rise in both frequency and impact.
To stay ahead, enterprises need more than traditional security tools. They require comprehensive Data Security Platforms (DSPs) that provide visibility, control, and protection across structured and unstructured data, whether on-premises, in the cloud, or within SaaS applications. But with a crowded market, how do you determine which solution aligns with your organization’s needs?
Alexei Balaganski, Lead Analyst and CTO at KuppingerCole, will unpack the findings of KuppingerCole’s latest Leadership Compass on Data Security Platforms. He will highlight product and market leaders, explore key trends driving innovation, and provide actionable insights to help you navigate the shifting data security landscape.
As CEO of TrustLogix, a leading innovator in data security, Ganesh Kirti brings unique insights into how modern organizations can secure sensitive data across cloud environments. In this session, he will share practical strategies and real-world examples on building scalable, policy-driven data security platforms that enable governance without slowing down innovation.
Whether you’re a security leader, compliance officer, or IT decision-maker, this session will equip you with the knowledge needed to enhance your data protection strategy in 2025 and beyond. Don’t miss this opportunity to gain expert guidance in securing your organization’s most critical asset—its data.
Well, hello and welcome to another KuppingerCole webinar. Our topic for today is Navigating the Data Security Landscape. My name is Alexei Balaganski, I'm the Lead Analyst at KuppingerCole Analysts, and if you have ever attended our previous Leadership Compass focused webinars, you would expect me to make this one alone as well, but today we are testing a new exciting format, and this is why I have a distinguished guest, Ganesh Kirti of Trustlogix.
Welcome, Ganesh, it's great to have you on board as well. Thank you, Alexei, it's great to be with you. Looking forward to this conversation.
Right, so this is not your typical sponsored webinar, there will be no sales speeches or anything like that, we're just going to discuss the findings of our recently published Leadership Compass on data security platforms, and along that discussion we will basically talk about challenges, use cases, solutions, issues, and other things. And again, today you have an opportunity to hear two different opinions from the different corners of the cyber security industry, if you will. But before we begin, a few housekeeping rules. Everyone is muted, you don't have to worry about your microphones.
We will be doing a couple of polls in this webinar, and you will have some time to give your answer, and we will discuss them later. You can submit your questions at any time, especially today because, again, we are expecting a very interactive presentation. You should use the questions tool on the Livestorm interface, usually on the right of your screen. This whole webinar is being recorded, and the slides and the video will be available on our website probably tomorrow, and we will inform you when it's available.
So again, we have two speakers today, me and Ganesh Ketty. There isn't actually a strict separation between our parts.
Again, we will be discussing the same topic together, but we will have a Q&A session as usual in the end of this webinar. And before we begin, just a quick one question poll. So how familiar are you with the concept of data security platforms? It would be great to hear, to see your responses, ranging from no idea at all to tried it, got tired of it, and looking for something else. So can I please have our poll?
Okay, so Ganesh, what's your feeling toward this term, data security platform? Do you hear it a lot? Do you feel it resonates with the customers?
Yeah, I know it is. With the data landscape that is getting complicated, the traditional solutions no longer fulfill the complexity that is given today. It is becoming very clear and evident that many companies that we work with, enterprises, looking for a modern security concerning solutions with a unified approach.
So yes, we do hear that, and it is increasingly, we're getting inbound requests from our prospects looking to understand this space. Right, well, obviously, the key word here is a platform, a unified single thing you only deploy once and hopefully control and have the complete visibility across the mind-bogglingly complicated hybrid deployments modern companies usually have nowadays.
So yeah, data security platform is an interesting thing. However, not 100% of our attendees are even familiar with that thing, like almost 20%. I have never heard about that before.
Well, great to have you on board in this webinar. Hopefully, you will leave it enlightened and we will be asking about that in the end of the webinar.
Okay, so can I please close the poll now? Maybe give out, okay.
Okay, so as we have seen, the majority of people are actually at least vaguely familiar with the concept and they are here to understand more about their capabilities, but some people have never heard about them before. Again, we have you covered, just keep watching. So let's start our webinar or our discussion with a slide I like to use a lot in my presentations because what a time to be alive. Something's happening all the time, so many challenges to address, so little money to invest into that. So the complexity is growing everywhere.
We have multi-cloud, we have mobile workforces, we have the proliferation of software as a service solution, solutions and collaboration tools running in the cloud or in the clouds, if you will. And of course, we have the elephant in the room, generative AI, which is basically has taken the entire society, the entire IT industry overnight and well, everybody wants to have it everywhere. And finally, we have the challenges with privacy and compliance because, well, you still have to play by the rules, even if you really want to avoid that.
And of course, the business does not care a lot about technical details, but they know what keeps them awake during the night. Those are the biggest business concerns that must be managed by the IT and cybersecurity. Compliance failures are extremely expensive, data breaches are even more horrible, but the worst thing is, of course, a failure of your business continuity, such as a ransomware attack, for example, because the modern digital business simply cannot function if it goes down for an hour, maybe even a few minutes for some industries.
Basically, data and the cloud infrastructures and everything around it, its livelihood is the blood of the modern digital business. But again, how do we actually tackle all these complicated issues? We also should not forget about the hybrid multi-cloud amplifier.
Nowadays, we know that almost every company, big or small, is usually not content with running just one cloud infrastructure, because different cloud providers offer different services. Some have better presence in a specific geography, some are simply only supported by a third-party provider and you have to basically stick to that specific cloud. In the end, you end up with a zoo, with a complicated landscape of barely connected, disjointed silos, both containing your data, applications, and third-party services.
Somehow, you have to juggle all those different security, compliance, privacy, and technical issues, multiple disjointed tools, and you have to basically figure out how to live in this cloud tower of Babel, because this is where we live now. And by the way, Ganesh, I know that your company also focuses a lot on cloud-native data security. What's your statistics? Do you see a lot of customers struggling with multi-cloud, with data spread across multiple clouds?
Yeah, yeah, so totally. So multi-cloud, the way we see it, it is given. The companies that every day, they're building data lakes, data warehouses, data analytics. Now with AI workloads coming in, that's even getting complicated. So the data sprawl is given. That's kind of how businesses are dealing with data and security people have to support that and enable them. Not only the data sprawl happening across environments like databases and snowflake-like systems and data breaks, we also see on-prem databases.
Companies still have databases sitting on-prem, and they're looking for a unified solution. They want to have a single data security control plane that they can have a control across the data sprawl that's happening in environments.
Yeah, though our architecture is unique, we do that cloud-native integrations, but we support that same cloud-native architecture across multiple data clouds and data platforms. Absolutely, yeah, we see this.
Yeah, this is a great slide that kind of captures some of the complexity that's happening right now. And by the way, one thing that this slide does not reflect is, of course, the recent interesting political developments from certain countries of the world and from certain politicians. Because if they have it their way, the cloud complexity, the multi-cloud complexity explosion will be inevitable. Because now you can still probably survive dealing with two or three global cloud providers like AWS, Google, or Azure.
If we will be forced to, basically, like we in the European Union will be forced to only work with the EU-based cloud services, and other countries around the world will have their own sovereign locations, if you will. It would only mean a dramatic increase, dramatic further increase in cloud complexity.
So yeah, if you remember 20 years ago, we were promised that cloud is the solution, is the easy way out. Well, look where we have ended up instead.
Yeah, just to add into that, in addition to the multi-cloud and multi-data platforms, if you're a global company, it's also given that there's a multi-regions. You've got some data centers running in Europe, some in the US, some in the Asia-Pacific. And now you've got that data across multiple regions, then you've got to have a geographic, jurisdictional laws that you had to apply. And then if you're a telecom, if you're a healthcare, if you're a financial, depends on which compliance you belong, right? It gets much complicated.
Well, let's not kind of get a little bit ahead of ourselves. Our first task is to kind of explain to our attendees how deep their problems are, and then we will show them the potential solutions. That's what we are here to demonstrate today. So when we are talking, like when we analysts are talking to customers, and I have emphasized it explicitly that our customers are not the same breed of people as the customers who go directly to a security vendor like TrustLogix. If a company knows what kind of solutions they're looking for, they might go directly to a vendor.
If they don't, if they don't have a profound understanding of all the potential complexities and issues and so on, they would usually come to us and ask us for their advice. And it's always interesting to hear that from the business perspective, if you will, their problems are always the same. They have tons of digital data, but they have no easy and meaningful way to derive value from the data. And this data to value gap is perhaps the single most complicated issue that businesses are facing now. All of the other things I listed on this slide are basically consequences of that.
Data sprawl, yeah, you just have so much data in various formats across different clouds and systems and formats, structured or unstructured, you don't even know how much data you have to say nothing about deriving value from it. And of course, as soon as you start figuring out, okay, how can I actually start earning money with that data, you have to deal with friction.
Data friction is basically the amount of time you need to get from a business-relevant request, okay, I need this specific piece of data to make an urgent report for the board tomorrow, to the actual point in time when you get access to the data. And unfortunately, sometimes it doesn't happen fast. It might take days or even weeks if there are a lot of humans involved in that process. And of course, one of the primary solutions, the primary challenges for a data security solution is to also not to introduce additional data friction.
Ideally, a data security platform should remove that friction from automation or other interesting solutions, but here we are. So data to value gap, data sprawl and data friction are the biggest challenges we are looking to address. Unfortunately, a lot of time when you hear about sensitive data, everybody is talking about the same thing, the crown jewels. As if the only, the most valuable thing your company has in the area of digital data is like your secret Coca-Cola recipe.
Well, usually it's not the case. Usually your data is something which flows in all the time in massive amounts, like through huge tubes, if you will. And you have to somehow not just be able to accept all the data, but to filter it, to figure out where to direct the flow within your internal architectures and infrastructures, how to secure those data flows, how to ensure that only the people who need access and who have the right to have access to a specific kind of data actually receive it.
And to filter out the toxic kinds, if you will, because every time you're talking about sensitive data, there is always more than one possibility that having too much of the data will kill your business completely. It can be through non-compliance with GDPR or other privacy regulations, but for financial, healthcare and other highly regulated industries, there are too many scenarios to imagine where you would rather not have a specific kind of data or at least so completely secure that you can finally sleep during the night.
So no, I firmly believe that crown jewels are a myth. And instead, when we are talking about data, I would love to introduce the concept that data is our new air. Because basically, if you cannot get enough air, you will suffocate. If you are, for example, diving like me on the photo and you have enough air, you are a happy and content diver. If you don't have enough air, like oxygen, if you are like this poor fish, well, you die. And the same applies to modern digital businesses. As soon as you have too much data friction, you are gasping for air.
If you don't get enough air in time, well, your business processes start to crumble, your operations start to grind to a halt. And well, unless you risk and try to bypass some critical controls and face attacks, miscompliance, and other issues, well, again, your business's livelihood critically depends on the availability of that data air.
Ganesh, what's your view on this? Would you rather treat data as diamonds or as air?
No, I agree with you. Data is the foundation now. Every company, they are under pressure to do more with the data they already have.
Today, the companies have siloed environments and data is spread all over the place. And the companies are not able to use that information to make their decisions and to become intelligent. So they have to become that. They have to get the data out to the right places so that they can get insights and make decisions.
Yeah, absolutely. If you are not doing that already, you're going to be losing this information that you already have, intelligence you already have.
Yeah, if you don't use it, if you don't have proper quality on the data, if you don't have proper preparation on the data, it's going to become the same thing. Your output is also like what your data quality is. So there are a lot of things we can talk about.
Yeah, you also talked about the friction. The way data is used today is no longer the same that it used to be 10 years ago, just the SQL queries.
Right now, data is used by SQL, Spark, SQL, workflows, and so many ways the cloud vendors like Snowflakes and AWS are creating, making it easy for consumers to use data. And one element in the room, of course, is generative AI. That's right. When ChatGPT was released a couple of years ago, I mean, I don't even remember. Time flies so quickly now. My feeling was it has undone overnight years of our efforts of educating the businesses about risks for dealing with sensitive data. Everybody just completely forgot about GDPR, other sensitive data regulations.
Why bother when you can just paste your customer list or your financial transactions directly into a chat and it will give you a report, saving you hours of time of your valuable working hours. Awesome. But the fact that it will actually cause a massive data breach or allow your competitors to spy on your valuable IP and so on.
Oh, it has been forgotten because, again, whenever you have this dichotomy between convenience and efficiency versus security and compliance, convenience beats security 100% of the time, which is sad. And this is exactly why we are talking about solutions who address this dichotomy by removing it completely. And one thing we have to mention again and again is that data doesn't exist in banking. Data only generates value, that is money, when it's being processed. And nowadays data processing means a lot of complicated data flows, transformations, exports, transformation slots.
AI is just one thing. It's probably like the most interesting one, but let's not forget you still have your processing systems and you still have traditional machine learning, you have business intelligence, you have different real-time systems which rely on data flying fast and unobstructed between different systems. It's especially relevant in the financial industry, for example. Data is moving around a lot through different systems, clouds and whatnot. And everything I try to kind of put together on this slide, in theory, belongs to the field of data protection.
So an ideal data security platform should do basically anything from data encryption to API protection to privileged access management to user behavior analytics to whatnot. Of course, in reality, it usually doesn't happen because you probably already have some of those tools in place. But then again, a platform is not just a combination of tools. This is a solution that works as a single unit with centralized visibility and vulnerability and management and policies and whatnot. And this is what we are going to discuss today.
One other additional dimension you have to not forget as well is that data changes in time. Data has its own life cycle. This is why we are talking about the notion of information protection life cycle. As soon as you acquire data, whether you create it yourself or acquire it from a partner, the life cycle begins and you have to ensure that it's already being protected from the first second, if you will.
Then you have to follow the data lineage and transformation and movement throughout this whole life cycle and apply a broad set of controls for monitoring, encryption, analytics, and so on to ensure that it stays protected throughout its active use life cycle. And even after the data is no longer needed, it has to be properly disposed of. And everything in this picture, again, is a direct responsibility of a data security platform. It feels somehow that kind of a data security platform should be like a jack of all trades.
It should be able to do everything and replace hundreds of other security tools. But is it really so? What's your opinion on that, Ganesh?
Yeah, I know it is complex. There are so many use cases. As you were talking about the slide before, there are so many segments and it's important that companies understand their specific use case. And look for what's optimized for their use case. It is difficult to get everything in one platform. And then adding into that is the structured and unstructured data. So you've got data complexities even going there.
I would definitely look for a platform solution that is built with the right architecture in place, with the right security and monitoring and access, all the building blocks that you're talking about here. Having the right architecture, right platforms does make sense to start with, and then you build it up on top of it. Right. And by the way, one thing we almost completely forgot about, not really, but let's pretend that security isn't just performed by tools.
I mean, it's still the responsibility of people. And the biggest question that always arises when we are talking about introducing a new security platform is who is going to pay for it? Who is going to own it and operate it? And the issue is that a data security platform, again, data security as a discipline is so broad that it overlaps with responsibilities of multiple stakeholders within the organization, multiple teams, multiple C-level officers, and so on. Should the developers take care of securing their test data? Should it be the data analysts and scientists?
Should it be the hardcore security people? Should it be specialized like DBAs and people operating the actual databases? Somebody else?
Well, the problem is everybody should be involved somehow, but in reality, it doesn't often work. The problem is we have conflict of interest. We have different people looking for different capabilities, different parts to own and operate, and we end up with blind spots and security gaps.
And again, kind of ideally, in an ideal scenario, you should have a kind of a data security fabric, if you will. Even if you have multiple tools from different vendors, they should operate in accord, talking to each other, exchanging insights, working with standardized risk models, and so on. We are not quite there yet, but again, this is at least something which we are definitely looking for when we approach data security platforms in our analysis. One specific part of that discussion about ownership is who is responsible for data?
Is it your CISO, the information security officer, or is it your chief data officer? I mean, it's data, but it's also security. Should they fight for it, or should they fight for who is not going to do it, because it's the other guy's responsibility?
Kanish, what do you think about it? Yeah, I know. As you said, this is what we see all the time. Who owns the data? I would rather look at it from an angle of how can we enable data workers, as the slide says here, these data scientists, data analysts, AI, LLM models that are looking to get access to data. How can you enable them? That's really the question. How fast can we get them going?
If you really look at that angle, then it becomes very clear that both security and business people need to collaborate and make sure that while getting the data out to the data workers is important, and do that in a secure and compliant fashion is also important. So it really has to be, they have to work together, both security and business people, and it doesn't have to be very complicated. And there are solutions out there one can look at that allows them for this collaboration.
I do believe that this is very, very important, the CISO-CIROS collaboration, and having tools that help them collaborate can really enable businesses to move much faster, especially the world that we are living in. It's very important that the collaboration has to be part of the organization. But it is also very important to emphasize that this collaboration can only work in reality if it's supported by really sophisticated tools, because if it's just a discussion about who is paying for it, it doesn't really move you forward at all.
Because if you still have this kind of old-school mentality of security means putting your data into a safe, obviously this approach doesn't work, simply because you cannot just put your entire business into a huge multi-cloud safe. But as soon as you make any concessions and say no, okay, we have to remove certain security controls to make sure that this tiny part of our system works fast enough, you have a totally different kind of problem. Only when both CISO and CDO are actually kind of sort of fighting, they're kind of collaborating and kind of thinking into the same direction.
It's not about security versus convenience, it's about security and convenience through a common platform to remove the data friction and to actually start working. Absolutely. So the security cannot be isolation, it cannot work in isolation. The way it is, it has to be built in into ground up infrastructure level in operational side. It has to be built in and it has to be corporate-wide strategy to enable this data ecosystem.
So 100%, it has to be collaborated, it has to be part of the system. And the tools are to support that, absolutely.
Well, there is one thing that people nowadays are always bringing into any discussion, but especially when it comes to cyber security. Will AI help? Will AI even replace human security analysts in the end, completely?
Well, the problem is AI is not a solution. It's actually like, if you will, it's the biggest problem of data security. As I mentioned earlier, now everybody wants to feed their AI systems with all the data they have, because the more data you can use to train your AI, the better, supposedly, it would work at the inference phase. And we have observed how those AI systems have quickly evolved from a standalone LLM a few years ago, which was basically a thing in its own, being able to answer simple questions. That was obviously not enough.
Without knowing anything about your business, your operations, an LLM on its own doesn't work. This is why those retrieval-augmented generation systems, REGs, came into play. Now you would have to, every time you ask a question, you have to feed the LLM with your data, and it's sensitive data. You cannot just copy and paste it to a deep-seek console or change a PT, because there is a lot of people out there waiting to steal that sensitive data.
Nowadays, of course, agentic AI systems are all the rage, and they are going even further, meaning that each agentic system has its own data store, short-term and long-term memory. It can operate various controls within your organization as if it were human, meaning that it can potentially have access to much more data, even things which were originally reserved to only high-privileged humans, like admins or your CFO, perhaps, or somebody, or having access to that secret coke recipe.
Nowadays, it can be an agent and you never know what that agent is going to do with that sensitive data. Again, we have a massive explosion in complexity, and in the end, a massive explosion in amount of sensitive data flows. So artificial intelligence is a problem we have to address, and you have to think about it in this way. AI security is all about data. Unfortunately, we hear quite a lot that securing AI is like a discipline on its own, and it requires more AI, basically.
In the end, you would end up with this overly complicated, partially completely non-deterministic and unpredictable solution, which claims to be like a guard for your AI system. But can you trust it? Who watches the watchman? Because in the end, AI systems, they run on the same infrastructure and protocols and data. You cannot just say, hey, all the quote-unquote old-school traditional cybersecurity no longer matters. It still does. You still need data protection and encryption. You still need API security. You still need discovery and classification.
Again, it's all about data. Ganesh, do you agree with me on that?
Yeah, it is all about data. I do agree that securing AI with another security layer, you've got to be careful there. We're talking about the B2B system, especially in the B2B case. You're talking about business-sensitive data. For these agents to make decisions, they need to have access to this business data. That's a foundational thing. You've got to make sure that you start there, making sure that your LLMs and your models and your agents have access to what they're allowed to do on behalf of the users.
That's the complexity that you're talking about, where we were securing the users and access controls on the users, but now agents that are making decisions on behalf of users, they're acting like super high-privileged user accounts. How do you proxy those users and how do you secure those users from data perspective? You've got to secure data first and then start building it up.
Yes, this completely makes sense to me. Right, so if you remember, the concept of data-centric security isn't new. It's probably over a decade, at least over a decade, or maybe even more. The problem, of course, is that we always thought that it's kind of an abstract thing. Data has to secure itself somehow, as if it has a mind of its own. Maybe this is why people now think, okay, we now have AI, maybe AI will secure my data.
No, it's still kind of responsibility of tools operated by humans, at least humans taking important decisions. And of course, those decisions can be and should be automated and supported by AI, but in the end, it's all about finding and implementing proper data security platform. This is where we come to our leadership compass. We've been following the developments of data protection market for over a decade now. We publish leadership compasses on Emirates about every 18 months under different titles.
It used to be database security, then it used to be big data security, now we call data security platforms. The goal is still the same. We are looking out for solutions which ensure that you can maintain confidentiality, integrity, and availability of the digital information across your business that would implement regulatory compliance.
And of course, it would be delivered as a platform that could encompass all your existing data silos and systems and applications and services across multiple clouds and on-prem, across different data formats, structured or unstructured, and models, and consumers, and so on. So this is why we believe the data security platform is the right term for such solutions, especially now with the emergence of new trends like generative AI and multi-clouds.
However, we also observe that the market comes up with additional alternative tools like, for example, the popular data security posture management, the SPM, and we will talk about them in a moment. So let's just kind of move directly to capabilities. One of the things, one of the kind of primary philosophies of copying a core research has always been stop looking at labels, start looking at capabilities. It doesn't matter whether a tool is called a DSP, or DSPM, or DLP, or something else. We expect it to fulfill certain functional criteria.
And for this specific leadership compass, I have defined eight major functional areas which we expect a data security platform should perform. It doesn't mean that all solutions in this leadership compass can do all of those things, but those who do are obviously rated higher. So the first thing it has to do is vulnerability assessment, understanding the underlying infrastructure, databases themselves, clouds, networks, identify risks, and manage those risks.
Second, it has to be able to discover and classify data sources. Again, it's no longer just databases, or at least not just SQL databases, it could be NoSQL ones, vector databases, object storages, file servers, nowadays perhaps maybe even AI systems. It has to be able to understand what kind of data is stored in that system and define the appropriate security policy. Then we expect them to be able to apply multiple controls to enforce those policies.
Those include encryption, masking, tokenization, and of course more sophisticated things like data protection in transit and in use, like homomorphic encryption for example. This is where the fancy things like post-quantum encryption also falls under, and so on. On top of that, we should be able to always stay informed what's actually going on with my data. So those data security platforms should monitor all the activities around databases and data flows and be able to understand if something suspicious or malicious is going on. Of course they should be able to protect against those attacks.
The next one, number six, is probably the most important for non-security people, is ensuring access management, meaning that only the people who have the right to access some data can actually access it. Because this is where the biggest risk of non-compliance is coming from. Whether it's a data breach or some kind of a different leak or compliance, it's all about access management. Should we mention the Magic Word Zero Trust?
The next one is obviously like the consequence of ensuring proper access management, and it's having an audit trail of all those activities and being able to tell the auditor later that yes, everything we've done during the last six months was actually according to those rules and there were no violations, everything is under strict control and protection.
And finally, those solutions are expected to be deployable everywhere across multiple clouds, on-prem, for all those modern sophisticated microservice-based architectures and LLMs and anything, without actually introducing a lot of overhead and providing high availability. These are eight major things we expect proper full-featured data security platform to be implemented.
Ganesh, do you think we have forgotten anything? No, I think this looks really comprehensive list and it covers both data, structured, semi-structured, unstructured, with these capabilities.
I mean, obviously, as you were saying, not every platform has all these capabilities. Now companies have to look at which ones is important. It'll be good to have your recommendation also like which one should users look at first and where do they start. I think that's the type of questions we get also from in our discussions. Where do we start? Is it complicated? Do I have a budget? Do I need 10 people? When do I do this? These are other questions we get.
But yeah, it looks like this is a good list you have to start with. And this is, by the way, where we come to my pet peeve, the DSPM label.
So yeah, it's an extremely popular term nowadays, like XSPM, something something security posture management. I've seen cloud security posture management, data security posture management, application security posture management, and we'll probably see AI security posture management pretty soon. Is it a good thing? Is it a useful thing? Of course it is. So security posture management basically means understanding how secure you currently are, is there any drift from an expected situation, and what to do to bring your system back to normal. The question is, is DSPM functionally equal to a DSP?
And what about DLP? It sounds similar too.
Well, I tried to create kind of a diagram showing the differences, the way I as an analyst see those. So here are again those eight capabilities of our DSPs. And this is approximately where a DSPM, data security posture management solution, as defined by Gartner, usually falls under.
Yes, it can provide you with a vulnerability assessment, it's discovering classification, and with some kind of a layer of compliance and reporting on that. So yes, you always know what kind of data you have and how safe it's supposed to be. And this is where it ends.
Yes, a lot of other vendors, even those who directly call themselves a DSPM vendor, can do more than that. That's exactly where I say stop looking at labels, understand the differences of those offers.
Should, for example, access management be part of a DSPM? I would argue it's not in the original definition. Who knows? What about DLP?
Well, DLP essentially does like the same to an extent. It also discovers and classifies your existing data sources, but it also monitors all the activities around them. And it at least tries to apply certain data protection controls to prevent authorized data leaks.
But again, does it cover access management? To a certain degree, it should, but because how does it know what access is authorized and which is not? But it probably would never be fully comparable to a specialized data access management solution like TrustLogic Office, for example.
So yeah, those are the things which are definitely missing, at least in the traditional scope of those solutions. And then again, I want to emphasize that in our computer codes definition of a data security platform, we expect all those eight pivots to be covered equally.
Ganesh, would you say that TrustLogic offers a DSPM solution, or is it something else? As you're saying, you know, TrustLogic's perspective, the way we have taken is more like a solution approach. Our core mission is to get the data out to the right people in a much faster, you know, in a secure and compliant fashion. That's really the core of what we do. And how fast can we get there? How less friction, right?
You know, we created the solution and then get the collaboration going between the CSOs and CEOs. That's really the core foundation of what we do. As part of that, we do definitely the DSPM, some capabilities.
We do, you know, data security platform, as you talk about access monitoring and compliance and performance is important security-wise, architecture-wise. Yeah, it's an evolving space. The way I look at it is DLP vendors, you know, do certain things, and DSPM, as you correctly said, is giving you the risk visibility. It's kind of the precursor. I guess it's a subset of functionality, you know, that allows for access management, like some of the solutions to take that intelligence and then, you know, secure the data.
Now, the way I see is from the customer perspective, they need DSPM capability, they need, you know, DSP capabilities like access and some of the other things that we list out. We thought it's not one or the other.
I mean, you know, the vendors are evolving, you know, including TestLogix, ourselves as well. But I think our approach has been more like combine the DSPM and some of the other capabilities we talk about access and controls, monitoring that to, you know, data activity monitoring, combine them into a single platform. That's the approach we have taken.
Yeah, kind of DSPM is a great start, but you should never stop there. It's just the first step towards comprehensive data security.
Okay, moving on. These are the vendors we have covered in our leadership compass. As you can see, it's a healthy mix of large companies like Oracle and TELUS, for example, and OpenText and IBM, as well as really kind of lesser known and smaller companies like TrustLogix, for example, or SecuPy, or even like really tiny startups. Why?
Like, why aren't we comparing apples to oranges in this our methodology is kind of split into several different areas which overlap only partially. So yes, of course, we name our leaders as a combination of all the capabilities and ratings we have measured. And you can see that, for example, TELUS, which used to be in second place in our last year's rating, through a strategic acquisition of Imperva, who was also a leader in the previous year's leadership compass, now has managed to secure the first position in the overall rating.
And as you can see, among the leaders, you really can find companies which offer completely different approaches towards security. Again, kind of Oracle, for example.
Well, if your entire ecosystem runs on Oracle, you are very secure with just using their own built-in security capabilities. But if you are not, you might be more interested in deploying a real platform in the sense that it can support multiple database engines, like TELUS does, for example, or IBM. But if you're actually, for example, focusing on cloud-native databases, or a specific subset of platforms, like really popular data warehouses and analytics platforms, or maybe TrustLogix is your solution, because this is exactly what it does.
And it does it through orchestrating their native capabilities. So you do not need to deploy any proxies or agents or anything like that.
Well, there is always a perfect solution for different usage scenarios. And you cannot just trust the overall leadership, you have to go deeper. So this is why we rank product capabilities, innovation capabilities, and market capabilities separately.
Of course, we won't stop and discuss every vendor on every graph now, but you can see that there are some companies who offer really broad functional capabilities, meaning they cover a lot of bases, a lot of those pillars. There are some who focus on smaller areas, there are even companies which would only address one of those capabilities. For example, Plain ID only does access management, but it does it so well that it almost made it into the product leaders category.
It's the opposite of check of all trades, so maybe if that's your challenge, you might be interested in looking into that kind of solution instead. Innovation leaders are those who offer things which are unexpectedly new, which nobody else does. And you can immediately see that the order changes dramatically. The company which was like really down below like DataCrypto, for example, is now among the innovation leaders as well, because they offer a homomorphic kind of technology for encrypting data in use.
You can see TrustLogix is also among the innovation leaders, because of their orchestration and AI-powered capabilities for applying security policies across cloud-native data platforms. And finally, market leaders are those who are just selling big, who have massive presence in the market, large partner networks, and a lot of customers.
Again, the list changes, and it's up to you to decide what's more important for you, the financial stability of your vendor over the next 10-20 years, or a really solid specific functional capability. And finally, for each vendor, we offer a write-up for about one to two pages explaining what are the capabilities offered by the product, what are the ratings across those eight different pillars. You can see this is kind of a spider chart showing what this specific vendor offers in terms of discovery classification, or monitoring, or access management, and so on.
And of course, a short list of strengths and challenges. Again, let's not stop too much on those details. You will find these write-ups for each vendor in the leadership compass, which I highly recommend to read fully. And finally, it all depends on the usage scenarios. What exactly is your largest problem or risk? Are you looking to establish sovereignty of your data? For example, if you are bound by Indian regulations, so all of your Indian customers have their data stored within India. Or are you looking for a supply chain risk management solution?
It might actually be pretty high on your list nowadays, because the entire cloud providers are at the risk of being completely prohibited or severely limited in operations in the European Union, for example. Are you looking specifically for protecting your sensitive data from ransomware and breaches? Do you want to introduce zero-trust policy management across your entire data environment? All of those use cases are, of course, somewhat related, but they place different emphasis on different pillars. Your priorities change. Where do you think your solution fits the best?
What's your primary focus? Yeah, from a statistics perspective, the data sovereignty, we work with large healthcare, financials, and telecom companies. They are global companies. We do go in there and then address the complexities that they are dealing with. The data sovereignty, the geofencing of data, which is very, very important. While the data is located in different places, different regions, making the data available to the right solutions, right AI models, right analytics is important, the right users.
At the same time, applying the SLAs that the businesses have contracts with their customers, and those customers have contracts that indicate that who can access their data, right? Including their competitors, the data, right? Which employee within a company can access. While they have access to this customer, the same employee should not have access to their competitor data. These are all business SLAs on top of the privacy and other regulations. So we do address sovereignty, and then the data sharing collaboration and securing data for AI, ML, compliance stuff.
So we kind of play multiple use cases here, and we keep building it out, and as a complexity, we solve for customers. So we're going to take in a more like a partnership approach with our customers, and kind of building it out part of their journey. And by the way, if somebody would ask me probably like, so where is data friction reduction? Why it's not in the list here as a use case?
Well, data friction is not the use case, it's the consequence of using the right tool for fixing your use cases, if you will. So of course, it should be high on your priority list, but it's the consequence of finding the best fitting tool. If you manage to find the right tool, data friction reduction is basically automatic. And if you instead decide for the wrong kind of tool, you will only increase it.
So again, it's something which you have to keep in the back of your mind at all times. It's an architectural foundation, right? Like you got to look for a solution that does with frictionless approach. And with that, we have reached the time where I wanted to ask you the second question. So how did this webinar change your view on data security platforms? Do you still not believe it and looking for something, rather be looking for something else? Are you scary of high cost of implementing it? Or are you ready to just go and vote with your phone? But you don't have to wait.
We can actually continue. We still have some time left for an occasional question. I don't believe we have any open questions at the moment. But of course, we are open to being contacted after this webinar. And it only remains to me to give you a few hints. So the data security platform Fluttershop Compass is already published. It's available for our viewers and it will be linked in the slide deck as well. You will find it on the Kutynia.co website. I also giving you a list, a couple of additional links to kind of further understand the scope of data security.
If you are looking forward to Kutynia.co's other future events, you are very welcome to join us in September in Munich or November in Frankfurt at our upcoming Impact Days where we'll be focusing on identity and cybersecurity related topics. And of course, how are we doing with the phone?
Oh, really nice. And of course, we do offer additional services like events and webinars and research papers and advisory. So we are very welcome and open to your inquiries. And of course, you can also contact Ganesh and even meet him directly at the Snowflake Summit. When is it going to be happening? It's in the June first week.
Okay, very nice. So looking forward to seeing you at some of our future events or any other opportunities to network. How are we doing on the poll?
Actually, 50% are telling us shut up and take my money. Well, this is great. It's exactly what I have expected from this webinar. I think we've done a fairly decent job explaining you the scope and functional capabilities and the risks and the challenges of modern data security platforms. Thank you very much and have a nice day. Thank you.
Thanks, Alexei.
See All Locations
See All Locations