Data Security Posture & DLP

Almost every company knows it has "secret data" — customer lists, card numbers, secret recipes, source code. But ask where exactly it lives and who can get to it, and the answer is usually silence. That's because the data is scattered everywhere: a cloud bucket everyone forgot about, copies in someone's personal Google Drive, a test database full of real data, and lately — in the ChatGPT prompt box employees paste into every day. This node is the two-layer technology that fixes this: DSPM goes out and finds and classifies the secret data in every nook and cranny, and shows who can touch it; DLP then keeps it from leaking out.

Theme index · base 100 · USD total return

Why is Data Security Posture & DLP moving?

Latest
▲3

Breaches, AI-agent security demand and fresh capital lift data security posture theme

  • Breaches at Carnival and the FBI keep proving posture and DLP gaps Texas opened an investigation into Carnival's April breach exposing 6 million people, and the ShinyHunters group claims it stole FBI personnel and applicant data. Each fresh breach shows sensitive data is still poorly protected, pushing regulators and enterprises to spend more on tools that find, classify and control data.

    New breach and regulatory-enforcement events directly drive demand for the theme.

  • Cyera's $400M raise funds the data-security cohort Cyera raised a $400 million extension to its Series G from Goldman Sachs, valuing it above $12 billion, to build a platform governing access for humans, machines and AI agents, and to expand into federal and overseas markets. Big money backing a pure-play data security posture vendor validates and funds the whole theme.

    New capital into a leading DSPM player shows investor conviction and funds competition.

  • Fortinet and Commvault extend DLP and posture into endpoints and Azure Fortinet added AI visibility, governance and data-loss-prevention to FortiEndpoint and posted 33% billings growth, while Commvault became a native Azure service with identity-resilience and recovery. These moves push data security posture and DLP into mainstream endpoint and cloud platforms, widening the theme's addressable market.

    New product and partnership news expands where DLP and posture tools are sold.

  • Varonis sale talks and China app crackdown reshape the field Varonis is weighing a sale to private-equity firms after its shares fell about 30% on AI-lab and platform competition, which could bundle its posture tools into bigger suites. Separately, China cited 72 apps, including brokerages, for illegal personal-data collection, showing regulatory pressure that both hurts and helps posture vendors.

    New ownership uncertainty and foreign regulation change competitive and demand dynamics.

Q3 2026
▲3

AI data fears and breaches lift data security demand

  • AI vendors offer zero-retention, boosting DSPM/DLP adoption AI vendors like Anthropic now offer zero-retention and customer-controlled data, which eases fears about AI training on sensitive information and encourages more companies to adopt data security posture management and data loss prevention tools.

    This is a new positive force driving demand for data security posture and DLP.

  • New products protect AI agents and non-human identities BeyondTrust, Cohesity, AvePoint, and Akamai launched products that extend data protection to AI agents and non-human identities, a new area of risk as companies use more automation and machine accounts.

    This is a new product development expanding the market for data security posture and DLP.

  • Varonis posts 52% SaaS ARR growth; Cyera raises $400M Varonis reported 52% growth in SaaS annual recurring revenue, and Cyera raised $400 million at a valuation above $12 billion, showing strong demand and investor confidence in data security posture management.

    These are new financial and funding events that signal robust demand and capital flow into the sector.

  • Breaches persist; Varonis shares fall on competition Major breaches at Craneware, Thailand's TSD, Carnival, and the FBI, plus warrantless data sharing, show ongoing posture failures. Varonis shares fell about 30% amid AI-lab and platform competition, prompting sale talks that could bundle its tools into larger suites.

    This captures the key counterweight: persistent breaches and competitive pressures that temper the positive demand story.

News & notes moving Data Security Posture & DLP
United StatesNetherlands
Data Security Posture & DLP▲

Revyz Launches Bitbucket Cloud Data Protection, Names Justin Leader Head of Partnerships

Revyz, a Spin.ai company, announced Revyz Command Center for Bitbucket, extending its enterprise data protection platform from Jira and Confluence to source code and pipelines in Bitbucket Cloud, alongside the appointment of Justin Leader as Head of Partnerships, Atlassian Ecosystem. The launch, announced ahead of Atlassian Team '26 Europe in Amsterdam on October 6-8, adds granular recovery of specific repositories, branches, pipelines, or issues, run-to-run diff visibility, and AI code protection. Revyz, acquired by Spin.ai in April 2026, is a Platinum Atlassian Marketplace Partner whose platform is SOC 2 Type II compliant. Justin Leader founded HyperVelocity Consulting in 2014, growing it to $24M in revenue before its acquisition by Isos Technology in 2023, where he served as VP of Product, and brings 15 years of SaaS experience to overseeing global Atlassian ecosystem partner strategy. Revyz Command Center for Bitbucket is available today, with solution partners able to access the app and co-selling support through the updated Revyz Partner Program.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cloud & Digital Infrastructure › Observability & DevOps ▲Technology
Revyz · Technology · Positive Revyz launched Command Center for Bitbucket, extending its data protection platform to source code and pipelines with granular recovery and AI code protection.
Revyz · Capital · Positive Revyz named Justin Leader as Head of Partnerships, Atlassian Ecosystem, to oversee global partner strategy.
TEAM · Demand · Positive Revyz extends its Atlassian data protection platform to Bitbucket Cloud, deepening the Atlassian ecosystem product offering and partner co-selling around Atlassian Team '26.
Spin.ai · Technology · Positive As Revyz's parent, Spin.ai gains from the launch of Revyz Command Center for Bitbucket extending its enterprise data protection platform.
Read original ↗
Business Wire·3dRead more →
FranceJapan
Data Security Posture & DLP▲

Thales Launches CipherTrust Data Security Posture Management Platform

Thales announced CipherTrust Data Security Posture Management, which the company describes as the first purpose-built DSPM offering that lets organizations protect sensitive data directly through encryption, masking or tokenization natively within the platform. The unified as-a-service platform combines sensitive-data discovery and classification with posture, access, activity and behavioral context to prioritize material risks, and it provides discovery and risk visibility for both structured and unstructured data across cloud, on-premises and hybrid sources. Todd Moore, Vice President of Data Security Products at Thales, said organizations need to understand which sensitive data is truly at risk and take direct action to reduce it, adding that CipherTrust DSPM connects risks to protections such as encryption and tokenization rather than relying on permissions alone. The approach builds on more than 30 years of Thales expertise in data discovery, protection, key management, access control and activity analysis. Hiroji Sugito, Principal Data Security Engineer at Tokyo Electron Device, said the platform's ease of deployment and the accuracy of its data classification enable customers to quickly understand where their sensitive data is, who or what can access it, and how to protect it without slowing AI adoption.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cybersecurity & Digital Trust › Post-Quantum & Cryptographic Trust Technology
HO.PA · Technology · Positive Thales launched its CipherTrust Data Security Posture Management platform, a new product offering.
Read original ↗
Business Wire·3dRead more →
United States
Data Security Posture & DLP▲

Bedrock Data Extends Agent DLP to NVIDIA OpenShell for Data-Aware Agent Policy Enforcement

Bedrock Data announced it has extended Agent DLP, its runtime data loss prevention for AI agents, to NVIDIA OpenShell, the open source agent runtime that is part of the NVIDIA Open Safety Platform. The integration adds a policy evaluation layer in which Bedrock Data evaluates a request payload once OpenShell authorizes the request, checking it against an enterprise's data policies and returning the decision OpenShell enforces at runtime. Bedrock Data supplies the data context and the decision through OpenShell's Supervisor Middleware, drawing on its Metadata Lake enterprise knowledge graph, which classifies data in place across cloud, SaaS, AI and on-premises environments at petabyte scale. The company said the integration lets restrictions travel with data across tables, tools and handoffs between agents, so actions that permissions allow can still be stopped when the data involved may not go where it is headed. Bedrock Data Agent DLP for NVIDIA OpenShell is available today to Bedrock Data customers as an OpenShell supervisor middleware service, and teams can run it first in observe-only mode before turning on enforcement.
About megatrends
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Bedrock Data · Technology · Positive Bedrock Data announced its Agent DLP now integrates with NVIDIA OpenShell, available today to its customers as an OpenShell supervisor middleware service.
NVDA · Technology · Positive Bedrock Data extended its Agent DLP to NVIDIA OpenShell, part of the NVIDIA Open Safety Platform, adding a security integration for NVIDIA's agent runtime.
Read original ↗
Business Wire·6dRead more →
United States
Data Security Posture & DLP

Jamf Unveils AI Governance and Automation Platform at JNUC 2026

Jamf announced a slate of new platform innovations at its 17th annual Jamf Nation User Conference in Kansas City, aimed at governing AI usage, making Apple management more programmable and automating routine endpoint work. The company, which supports more than 35 million devices across over 78,000 organizations, said its AI Governance capabilities are available today, letting organizations discover AI tools running across managed Macs, enforce usage policies and generate audit-ready reporting, with deeper AI activity insights, AI usage and cost insights, browser-based governance, on-device AI enablement and mobile AI governance all targeted for general availability in Q4 2026. On the programmability side, Jamf launched a new Platform API Gateway and a Terraform provider, both generally available today, while a Jamf-hosted automation engine for Routines with more than 1,500 integrations is targeted for general availability in Q1 2027. For autonomous endpoint management, Jamf introduced automated app lifecycle management through Blueprints, Apple-native endpoint data loss prevention and expanded App Insights, all targeted for Q4 2026, alongside AI-powered self-service diagnostics, device health insights and automated Ring Deployments, each targeted for public beta in Q1 2027. Jamf also said Jamf Tap and Jamf Device Checker are new frontline offerings, with Device Checker available today and Tap in public beta targeted for Q1 2027, and that JNUC 2027 will be held in Anaheim, California, from October 26 through 28, 2027, marking the company's 25th year.
About megatrends
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › AI Applications & Copilots Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
Cybersecurity & Digital Trust › Endpoint Detection & Response (EDR/XDR) Competition
Jamf Holding Corp. · Technology · Positive Jamf unveiled new AI governance, API/Terraform programmability, and autonomous endpoint management products at JNUC 2026.
Read original ↗
Business Wire·11dRead more →
United States
Data Security Posture & DLP▼impact 4

ShinyHunters Claims It Breached FBI Systems, Leaking Staff and Job Applicant Data

The cyber extortion hacking group ShinyHunters claimed on Tuesday, September 22, that it had breached the systems of the U.S. Federal Bureau of Investigation, or FBI, and stolen a massive trove of data on both former and current personnel as well as job applicants. The FBI acknowledged it was aware of claims of an unauthorized intrusion affecting the FBIjobs.gov recruitment website and said it was investigating urgently. ShinyHunters said in an online chat with Reuters that the attack was retaliation for a public warning issued by the FBI in May 2026 that exposed the group's attack methods and urged victims not to pay ransoms. The hacking group claimed it stole data on nearly all FBI special agents along with people who had previously submitted job applications, and released a sample of records on about 5,000 personnel, including names, addresses, Social Security numbers, assigned duties, and the names of family members of some agents. A preliminary Reuters review comparing the data against credit bureau databases and leak histories recorded by dark web cyber threat intelligence firm District 4 Labs found at least 10 matching records, including data on Kash Patel, the FBI director, and sources close to the matter said the job details in the dataset matched reality in some cases.
About megatrends
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) ▼Demand
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Demand
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Demand
Cybersecurity & Digital Trust › Identity & Access Management ▼Demand
Read original ↗
InfoQuest·11dRead more →
United States
Data Security Posture & DLP▲impact 4

Fortinet Hits 52-Week High as AI Security Platform Demand Lifts Q2 Billings 33%

Fortinet shares climbed to a fresh 52-week high of $175.23 on Sept. 21, 2026, before closing at $172.78, up roughly 3% on the session, extending a rally built on accelerating demand for its unified security platform. The company rolled out FortiSOC, a cloud-delivered security operations center embedding agentic AI across SIEM, SOAR, threat intelligence and identity-detection functions, and extended FortiEndpoint with AI visibility, governance and data-loss-prevention capabilities, while deepening its FortiAIGate integration with NVIDIA's accelerated computing stack. In the second quarter of 2026, billings rose 33% year over year to $2.37 billion, revenues grew 26% to $2.05 billion, and product revenues surged 52% to $773 million, with non-GAAP operating margin hitting a second-quarter record of 38% and free cash flow more than tripling to $966 million. Management raised full-year 2026 guidance to $8.02-$8.18 billion for revenues, $9.35-$9.55 billion for billings, and $3.41-$3.47 for non-GAAP EPS, with third-quarter guidance calling for revenues of $2.01-$2.10 billion. Fortinet shares have gained 120.7% year to date, and the Zacks Consensus Estimate for 2026 earnings is $3.42 per share, implying year-over-year growth of 23.91%.
About megatrends
Cybersecurity & Digital Trust › Network Security & SASE ▲Demand
Cybersecurity & Digital Trust › Security Operations (SIEM/SOAR/XDR/MDR) ▲Technology
Cybersecurity & Digital Trust › Endpoint Detection & Response (EDR/XDR) ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
FTNT · Demand · Positive Q2 billings rose 33% and product revenue surged 52% on accelerating demand for its unified security platform.
Read original ↗
Zacks Investment Research·12dRead more →
United States
Data Security Posture & DLP▲

Cyera Raises $400 Million Goldman Sachs Extension to Series G

Cyera announced a $400 million extension from Growth Equity at Goldman Sachs Alternatives to its Series G round, which was led by Evolution Equity, to accelerate its mission of building a unified platform that governs access for every human, machine, and AI agent across the enterprise. The new investment will continue to support new capabilities across Cyera's AI Security product roadmap, fuel deeper expansion in the federal market, and drive continued international growth across EMEA and APAC. Cyera has secured the data layer since day one and this year extended that control to agents acting on it, with Agent Guardian and Cyera Endpoint giving enterprises visibility and accountability across AI agents, tracking tool calls, database queries, and actions from the cloud to endpoint devices where local agents such as Claude Code and Cursor increasingly perform sensitive work. The acquisition of Oasis Security brings that visibility together with non-human identity management in a single system, connecting where sensitive data lives with who or what can actually reach it. Cyera, valued at over $12 billion, is backed by investors including Accel, Blackstone, Cyberstarts, Georgian, Lightspeed, and Sequoia, and its customers include Paramount, Chipotle, and Valvoline.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Capital
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows ▲Technology
Cybersecurity & Digital Trust › Identity & Access Management Competition
Cyera · Capital · Positive Cyera raised a $400M extension to its Series G, funding its AI Security roadmap, federal expansion, and international growth.
GS · Capital · Positive Goldman Sachs Alternatives' Growth Equity provides a $400M extension to Cyera's Series G, a financing event for the bank's investment arm.
Oasis Security · Capital · Neutral Oasis Security is only mentioned as an acquisition by Cyera, with no independent development affecting it.
Read original ↗
Business Wire·12dRead more →
United States
Data Security Posture & DLP▲

Varonis Systems Launches Data Lifecycle Management Capability

Varonis Systems, Inc. launched Varonis Data Lifecycle Management, a new capability that automatically identifies and remediates redundant, obsolete, and trivial data across enterprise environments using its existing Data Security Platform. The launch ties data cleanup directly to sensitivity, access, and activity context, aiming to reduce storage waste, improve AI output quality, and help organizations address compliance exposures from scattered sensitive information. The DLM tool stacks on top of Varonis Atlas, the AI security platform that went generally available in March 2026, which targets discovery, posture management, and runtime protection for AI workloads. Together, Atlas and DLM broaden Varonis' role from guarding unstructured data to governing how that data is stored, used, cleaned up, and exposed across Snowflake, Claude, Cursor, and other cloud and AI partnerships. Varonis Systems' narrative projects $1.1 billion revenue and $120.7 million earnings by 2029, yielding a $50.68 fair value, an 8% upside to its current price, while the most pessimistic analysts were already modeling about US$1.0 billion of 2029 revenue.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Artificial Intelligence › AI Tooling, Data & MLOps ▲Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
VRNS · Technology · Positive Varonis launched Data Lifecycle Management, a new product capability extending its Data Security Platform.
Read original ↗
Simply Wall St·17dRead more →
United States
Data Security Posture & DLP▲2

Cohesity Launches Agent Resilience to Protect and Recover AI Agent Infrastructure

Cohesity introduced Cohesity Agent Resilience, a new Cohesity Data Cloud capability that will discover, protect, and recover the infrastructure behind enterprise AI agents. The capability is available now to select customers, with general availability targeted for the end of 2026, and launches with support for Amazon Bedrock AgentCore and Amazon Bedrock Agents, while Microsoft and Google agent platforms are on the roadmap. Cohesity also outlined its vision for Autonomous Cyber Resilience, which uses agentic workflows to automate its five-step cyber resilience framework, and introduced the Cohesity AI Resilience Academy, beginning with a free, self-paced Foundations of AI Resilience with Cohesity course that Catalyst attendees will get early access to immediately after the event. The company cited new research from the fifth annual Cohesity Global Cyber Resilience Report showing that 56% of organizations said they were not well prepared to detect or contain unintended actions by AI agents and automated workflows, while 58% were not very confident in their ability to verify the integrity of AI models and related data following a cyberattack. Cohesity also said customers with Cohesity Data Cloud Enterprise Edition and Cohesity DSPM can now automate the protection of newly discovered sensitive data that is not already protected.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Cohesity · Technology · Positive Cohesity launches Agent Resilience to discover, protect, and recover AI agent infrastructure, plus Autonomous Cyber Resilience vision and AI Resilience Academy.
AMZN · Demand · Positive Cohesity Agent Resilience launches with support for Amazon Bedrock AgentCore and Amazon Bedrock Agents, tying into AWS's AI agent platform.
Read original ↗
Business Wire·18dRead more →
United States
Data Security Posture & DLP▲3impact 4

Palantir, Nvidia, Booz Allen Restrict Anthropic and OpenAI Models Over Data Protections

Palantir Technologies, Nvidia, and Booz Allen Hamilton are restricting or threatening to drop advanced AI models from Anthropic and OpenAI unless the labs provide stronger data protections, according to Reuters. Palantir has pressed Anthropic to guarantee zero data retention before making its models available through Palantir's software, while Nvidia limits Anthropic's models to less sensitive internal tasks and prefers its own Nemotron models for proprietary work, and Booz Allen has forbidden staff from running Anthropic's commercial model on cybersecurity projects touching proprietary data. The pushback intensified after Anthropic introduced a 30-day data retention policy in June tied to the rollout of its Fable 5 model, saying it needed usage logs to detect sophisticated attacks that unfold across multiple sessions, though the company said it would not use the retained data to train its models. Anthropic responded by announcing Enterprise Frontier Safeguards, which lets enterprise customers store activity data in their own cloud infrastructure, including Amazon S3, Azure Blob Storage, or Google Cloud Storage, under their own encryption keys, with automated safety monitoring but no human review by Anthropic employees; the system is rolling out in phases, with broader availability targeted for later this fall. Last week, Palantir and Nvidia unveiled a platform pairing Palantir's software with Nvidia's open Nemotron models to let organizations run AI on their own data without exposing it to outside model providers, and Nvidia shares dropped roughly 3% on Monday as AI-related stocks broadly retreated.
About megatrends
Artificial Intelligence › Closed / Frontier Labs ▼Competition
Artificial Intelligence › Open-Weight Model Developers ▲Competition
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Demand
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Demand
Artificial Intelligence › Agentic AI & Autonomous Workflows Competition
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cloud & Digital Infrastructure › Hyperscale Cloud (IaaS / PaaS) Demand
Artificial Intelligence › AI Applications & Copilots Competition
Anthropic · Technology · Neutral Anthropic faces customer pushback over its 30-day data retention policy but responded with Enterprise Frontier Safeguards letting enterprises store activity data in their own cloud infrastructure.
PLTR · Technology · Positive Palantir pressed Anthropic for zero data retention and launched a platform with Nvidia's Nemotron models letting organizations run AI on their own data without exposing it to outside providers.
NVDA · Technology · Neutral Nvidia limits Anthropic's models to less sensitive internal tasks and prefers its own Nemotron models, while also unveiling a Palantir-Nvidia platform for running AI on private data.
BAH · Technology · Negative Booz Allen forbids staff from running Anthropic's commercial model on cybersecurity projects touching proprietary data, restricting its AI tooling over data-protection concerns.
OpenAI · Technology · Negative OpenAI's models are among those being restricted or threatened with being dropped by Palantir, Nvidia, and Booz Allen over data-protection concerns.
Read original ↗
Reuters·20dRead more →
IndiaUnited States
Data Security Posture & DLP

Socify.ai Hits 300 Clients, Accelerating Toward 10,000 by 2030

TAC InfoSec Limited's Socify.ai, an AI-powered SOC 2 compliance platform, has crossed 300 customers, with the latest 100 added in just two months, following six months for the first 100 and three months for the second 100. The company, listed on NSE as TAC, aims to reach 10,000 clients by 2030 as part of its broader goal of $100 million in annual recurring revenue. Founder and CEO Trishneet Arora highlighted the accelerating adoption, noting that each 100-customer milestone is being achieved faster than the previous one. The customer base spans AI, cybersecurity, enterprise software, and other sectors, including NETGEAR, Peloton Interactive, Globant, and several AI-first startups. Socify aims to make SOC 2 compliance accessible to thousands of businesses globally through automation and aggressive pricing.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
TAC Infosec Limited · Demand · Positive Socify.ai crossed 300 customers with accelerating adoption, targeting 10,000 clients by 2030.
Read original ↗
Business Wire·27dRead more →
United States
Data Security Posture & DLPimpact 4

Varonis surges on Proofpoint acquisition talks

Varonis Systems shares jumped 13% Wednesday afternoon following a Bloomberg report that Proofpoint, backed by private equity firm Thoma Bravo, is in talks to acquire the cybersecurity company. People familiar with the matter said a transaction could be announced in the coming weeks, though no final decision has been made and talks could still fall apart or another bidder could emerge. Before the report surfaced, Varonis had a market value of approximately $4.7 billion. Representatives for Thoma Bravo, Proofpoint and Varonis did not immediately respond to requests for comment, according to the Bloomberg report. Varonis provides cybersecurity solutions that help companies monitor and control access to sensitive information across cloud systems.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
VRNS · Capital · Positive Bloomberg reports Proofpoint in talks to acquire Varonis, sending shares up 13%.
Proofpoint · Capital · Neutral Proofpoint is the potential acquirer in talks to buy Varonis, but no deal finalized.
Read original ↗
Investing.com·32dRead more →
United States
Data Security Posture & DLP2

Akamai Technologies Launches Workforce Protector AI Security Product

Akamai Technologies announced the launch of its Workforce Protector product, which integrates AI governance tools with real-time data loss prevention for enterprise users. The company also released new security research detailing emerging AI-driven threats that target enterprise environments and exploit browser-based vulnerabilities. The twin updates highlight rising risks tied to employee use of AI tools at work and frame Akamai's response with additional controls for data access and monitoring. The launch extends Akamai's security platform, which already covers applications, APIs, and infrastructure, to the browser and desktop AI apps where employees interact with data. Investors will watch for future disclosure on Workforce Protector adoption, customer counts, or its role in security revenue, especially after the latest quarter where sales were US$1,099.68 million and net income was US$79.4 million.
About megatrends
Cybersecurity & Digital Trust › AI Security & Agent Guardrails Competition
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) Competition
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
AKAM · Technology · Positive Launch of new AI security product extends platform and addresses emerging threats.
Read original ↗
Simply Wall St·50dRead more →
United States
Data Security Posture & DLP

AvePoint Unveils Kinetic Classification for Cloud Data Protection

AvePoint introduced Kinetic Classification, a new data sensitivity and recovery solution for Microsoft 365, Google Workspace, and other business apps. The product uses AI to continuously assess data sensitivity and adjust protection policies across connected cloud services, integrating automated recovery tools aimed at improving incident response for security and data governance teams. AvePoint, with a market cap of $2.7 billion, targets enterprises standardizing on major collaboration platforms and positions Kinetic Classification as part of its broader bet on becoming an essential data governance layer as enterprises roll out AI tools.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Technology
Artificial Intelligence › AI Tooling, Data & MLOps ▲Technology
AVPT · Technology · Positive AvePoint launches new AI-powered data classification product, enhancing its data governance offering.
Read original ↗
Simply Wall St·53dRead more →
Data Security Posture & DLP▲

BeyondTrust Unveils First Native Pathfinder Capabilities for Every Identity at Black Hat USA 2026

BeyondTrust announced the first wave of native capabilities built on its Pathfinder platform at Black Hat USA 2026, extending privilege management to every identity that can hold or exercise privileged access. The four new capabilities—PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and Workload Credentials—combine visibility, intelligence, and protection to help organizations discover, prioritize, govern, and protect privileged access across human, machine, workload, and AI identities. PathfinderAI enables natural-language investigation of identity risk, while the MCP Server allows AI agents like Microsoft Copilot and OpenAI to securely connect to BeyondTrust’s identity intelligence. AI Agent Security enforces real-time controls on what AI coworkers and autonomous agents can do on endpoints, and NHI Governance extends privileged access management to service accounts, API keys, and other non-human identities that often outnumber employees. Workload Credentials replaces static secrets with short-lived, auto-expiring credentials for CI/CD pipelines, Kubernetes services, and AI agents, eliminating the risk of leaked secrets. PathfinderAI, the MCP Server, AI Agent Security, and NHI Governance are available now through the Early Access program, with Workload Credentials early access opening soon.
About megatrends
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Privileged Access Management (PAM) ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Artificial Intelligence › AI Applications & Copilots ▲Technology
BeyondTrust · Technology · Positive BeyondTrust unveils new native Pathfinder capabilities for AI and non-human identity security at Black Hat.
Read original ↗
GlobeNewswire·62dRead more →
Data Security Posture & DLP▼4

PDPC orders Ministry of Public Health and TSD to submit in-depth evidence on Mor Prom and TSD Investor Portal data leaks

The Office of the Personal Data Protection Committee, or PDPC, has ordered the Ministry of Public Health and Thailand Securities Depository Company Limited, or TSD, to submit additional information and evidence in two major personal data leak cases. The first case involves the Mor Prom system, where over 30 complaints have been filed. The second concerns the leak of TSD Investor Portal user data affecting more than 200,000 records out of approximately 5 million accounts in the system. The PDPC requires in-depth details on the causes, scope of impact, and public notification measures before considering legal action. Police Colonel Surapong Plengkam, Secretary-General of the PDPC, stated that although TSD has issued a press release and notified affected individuals, technical evidence and traceable documents must still be examined to assess whether the organization had appropriate security measures in place and whether it fulfilled its post-incident duties fully and promptly. He stressed that a data leak does not automatically mean the organization is at fault, but if deficiencies are found, the PDPC will exercise its authority, ranging from ordering corrective actions to pursuing legal proceedings.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Thailand Securities Depository Co., Ltd. · Regulation · Negative PDPC orders TSD to submit evidence on data leak, may face legal action if deficiencies found.
Read original ↗
สำนักข่าวอีไฟแนนซ์ไทย·66dRead more →
Data Security Posture & DLP▼27

TSD reveals additional personal data accessed in TSD Investor Portal incident

Thailand Securities Depository Company Limited, or TSD, has provided further clarification that after coordinating with the Technology Crime Investigation Division on 27 July 2026, additional personal data affected by the unauthorised access to the TSD Investor Portal system on 25 July 2026 has been identified. This includes full name, date of birth, national ID number, address, phone number, email, securities company name, securities trading account number, bank name, and bank account number. However, TSD confirms that no securities holding data or securities trading transaction data has been found to be affected. It also warns users to be cautious of fraudulent contacts, change passwords regularly, and verify that emails from TSD come only from SETContactCenter@set.or.th and contain no attached links.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Read original ↗
Share2Trade·66dRead more →
Data Security Posture & DLP▲3

Varonis Q2 earnings beat estimates, revenue rises to $180 million

Varonis Systems reported second-quarter 2026 non-GAAP earnings of 4 cents per share, beating the Zacks Consensus Estimate of 1 cent. Revenues reached $180 million, up from $152.2 million a year earlier and surpassing the consensus by 1.7%. The performance was driven by continued SaaS momentum, with SaaS revenues jumping to $171.7 million from $105.9 million, while legacy term license and maintenance revenues declined as customers migrated. The company returned to non-GAAP operating profit of $3.7 million, compared with a loss of $1.9 million in the prior-year quarter, and raised its full-year revenue outlook to between $735 million and $739 million, implying 18-19% year-over-year growth.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Demand
VRNS · Capital · Positive Q2 earnings beat estimates, revenue up 18.3% YoY, raised full-year outlook
Read original ↗
Zacks Investment Research·67dRead more →
Data Security Posture & DLP▲2

Health100 Earns CARIN Code of Conduct Accreditation from DirectTrust

Health100, a CVS Health subsidiary, has earned the CARIN Code of Conduct for Consumer-Facing Applications Accreditation from DirectTrust for its mobile app. The accreditation followed a comprehensive independent third-party review that examined the app's transparency, consent, security, and other criteria to ensure trusted access and exchange of personal health information. DirectTrust President and CEO Scott Stuewe said the achievement gives health care stakeholders full confidence in exchanging private health information via an application that voluntarily sought verification. Tony Ambrozie, Senior Vice President and Chief Digital & Technology Officer at CVS Health and Health100, called the accreditation a milestone reinforcing the company's commitment to data privacy, security, and transparency.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Regulation
CVS · Technology · Positive Health100, a CVS Health subsidiary, earned CARIN accreditation for its mobile app, enhancing trust in data privacy and security.
Read original ↗
PR Newswire·67dRead more →
Data Security Posture & DLP▲4

Stock Exchange of Thailand reports TSD data leak affecting 200,000 accounts, rushes to deploy AI for enterprise-wide source code scanning

Mr. Asadej Kongsiri, Director and Manager of the Stock Exchange of Thailand, issued a formal apology regarding the leak of shareholder data from Thailand Securities Depository Company Limited, or TSD, affecting approximately 200,000 individuals out of a total shareholder base of around 5 million. He confirmed that stock portfolios, back-end systems, and the wiset application remain secure. The leaked data includes full names, dates of birth, national ID numbers, addresses, phone numbers, emails, securities company names, securities trading account numbers, bank names, and bank account numbers, but does not include securities holdings, share quantities, portfolio values, or passwords. The Stock Exchange of Thailand has already closed all vulnerabilities and is deploying artificial intelligence technology to scan source code across the entire organization to enhance security. Investors are warned never to click on suspicious links. Meanwhile, cyber police are working with ThaiCERT to pursue the perpetrators across borders.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Thailand Securities Depository Co., Ltd. · Regulation · Negative Data leak affecting 200,000 accounts, leading to regulatory and reputational damage.
Read original ↗
HoonSmart·68dRead more →
Data Security Posture & DLP▼impact 4

ICE accesses credit card data without a warrant through a $125 million Thomson Reuters deal

U.S. Immigration and Customs Enforcement can access personal data from credit card applications without a warrant through a $125 million Department of Homeland Security contract with Thomson Reuters. An investigation by 404 Media found that when consumers open a credit card or update account information, credit card companies share names, Social Security numbers, phone numbers, addresses, and email addresses with credit bureaus, which then provide the data to Thomson Reuters for its CLEAR investigative product. ICE uses CLEAR to search this information, and the platform is integrated with a tool the agency uses to determine which neighborhoods to raid. The five-year DHS contract is worth $25 million annually, and procurement documents state that Thomson Reuters Special Services is the only contractor able to provide continuous monitoring and alert services for millions of individuals. Senator Ron Wyden called the practice an outrageous privacy violation with no opt-out for Americans.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Digital Finance & Tokenization › Payments Modernization & Rails ▼Regulation
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
TRI · Demand · Positive The article reports a $125 million DHS contract for Thomson Reuters' CLEAR product, indicating strong government demand for its data services.
Read original ↗
Moneywise.com under the title·70dRead more →
Data Security Posture & DLP

Darrow Launches Privacy Radar on Microsoft Marketplace

Darrow has made its Privacy Radar solution available in the Microsoft Marketplace. Privacy, compliance, and security teams can now discover and deploy the autonomous AI agent tool, which surfaces gaps between a company's privacy posture and its actual public digital behavior, returning a severity-scored, dollar-quantified exposure report with remediation steps. The listing provides unified integration across Microsoft Azure and other Microsoft products. Darrow's legal exposure detection engine already powers a majority of U.S. trial firms, and its intelligence platform has identified over $22 billion in actionable legal risk to date.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
Darrow Inc. · Demand · Positive Darrow launches its Privacy Radar on Microsoft Marketplace, expanding distribution and customer reach.
MSFT · Demand · Positive Darrow's Privacy Radar listing on Microsoft Marketplace may drive Azure adoption and ecosystem stickiness.
Read original ↗
GlobeNewswire·73dRead more →
Data Security Posture & DLP▲

Synology Says ISO 27001 Becomes Foundation for Cyber Resilience in the AI Era

Synology has revealed that the ISO 27001 standard is shifting from being merely a compliance certificate to a crucial foundation for enterprise risk management, building cyber resilience in an era of intensifying cyber threats. Mr. Rahat Boontanjin, Country Manager for Thailand, stated that 72 percent of organizations worldwide see cyber risk as significantly increasing, and 71 percent of risk executives expect threats to severely impact business operations. He pointed out that the rise of agentic AI is creating new forms of risk, so organizations should use ISO 27001 as a control framework across four key areas: role-based data access permissions, data accuracy governance, rollback systems for AI errors, and continuous security measure improvements. Although a 2025 OpenText survey indicates that 52 percent of global organizations plan to increase investment in backup technology, many still face real-world system recovery failures. Synology has therefore launched the ActiveProtect Appliance, a solution designed to support cyber resilience approaches and the new era of ISO 27001, integrating immutable backup, logical air-gap, and automated backup verification technologies to close recovery gaps and help Thai organizations tackle cyber threats in the AI age.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Demand
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Regulation
Cybersecurity & Digital Trust › AI Security & Agent Guardrails Technology
Synology Inc. · Technology · Positive Synology launches ActiveProtect Appliance with immutable backup, logical air-gap, and automated backup verification, positioning it as a key solution for cyber resilience in the AI era.
Read original ↗
Money & Banking·73dRead more →
Data Security Posture & DLP▲2

US and European Banks Sharing Loan Details and Customer Data With Third Parties Without Valid Consent

New research from Jscrambler reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms without valid consent. The analysis of 14 financial institutions across Europe and the US found that tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce. Examples include a Spanish bank's mortgage process sending a customer's hashed email and phone number to TikTok's pixel endpoint, a Portuguese bank's account-opening flow sending email, name, age, and national tax number to Salesforce, and two other Portuguese institutions sharing full loan simulation details including a €27,000 loan with repayment terms to Google Analytics. The research also documented consent failures such as tags firing before cookie banner action, tags continuing after users rejected all, and consent choices not carrying into iframes or subdomains. Jscrambler recommends continuous runtime monitoring, enforcement controls to block unauthorized data exfiltration, and consent enforcement that extends across iframes and subdomains.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Digital Finance & Tokenization › Payments Modernization & Rails ▼Regulation
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Demand
ADBE · Regulation · Negative Adobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
CRM · Regulation · Negative Salesforce is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
GOOG · Regulation · Negative Google (Alphabet) is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
META · Regulation · Negative Meta is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
PINS · Regulation · Negative Pinterest is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
ByteDance · Regulation · Negative Article highlights that banking websites send data to TikTok's pixel without valid consent, potentially leading to regulatory scrutiny or restrictions on data collection practices.
Read original ↗
PR Newswire·74dRead more →
Data Security Posture & DLP

AvePoint adds first-to-market Copilot Studio agent backup and expands governance across Salesforce, Azure, and ServiceNow

AvePoint announced new capabilities for its Confidence Platform that extend governance, security, and backup to agentic AI, enterprise applications, and multicloud infrastructure. The platform now offers backup and recoverability for Microsoft Copilot Studio agents, a first-to-market development that lets organizations restore an agent's configuration, logic, prompts, and flows to a known-good state. Governance controls have been broadened to include discovery and observability of Salesforce Agentforce agents, alongside new policy-driven guardrails for assigning ownership and enforcing data sensitivity context. Data protection coverage has been expanded with new sources including ServiceNow, AWS S3 storage, Azure Kubernetes, and Entra External ID, while the Elements Edition for managed service providers gains multi-tenant baseline deployment, expanded Azure security assessments, and centralized application lifecycle management.
About megatrends
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails Technology
Cloud & Digital Infrastructure › Horizontal SaaS Competition
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery Technology
Artificial Intelligence › AI Applications & Copilots Competition
Cybersecurity & Digital Trust › Data Security Posture & DLP Technology
Cloud & Digital Infrastructure › Data Platforms & Analytics Technology
Cybersecurity & Digital Trust › Cloud & Workload Security Technology
AVPT · Technology · Positive AvePoint announces first-to-market backup for Microsoft Copilot Studio agents and expands governance across multiple platforms.
Read original ↗
GlobeNewswire·75dRead more →
Data Security Posture & DLP▼

AutoRABIT Urges Salesforce Teams to Review Six Security Areas After Breach Claims

AutoRABIT issued guidance for organizations to review controls governing Salesforce data access, exposure, monitoring, governance, and recovery, following recent high-profile breach claims including those linked to the ShinyHunters group. The company recommends that Salesforce teams immediately review guest-user access, permissions and least privilege, configuration risk, secure code and custom logic, monitoring and audit visibility, and recovery readiness. AutoRABIT CISO Jason Lord stated that risk lives across access, configuration, custom code, connected apps, release activity, and recovery readiness, and that enterprise leaders need precise security controls to govern that complexity. Deputy CISO Justin Hazard added that teams should actively verify guest access, tighten permissions, review configurations, scan custom code, confirm monitoring, and test recovery readiness now, rather than waiting for a breach.
About megatrends
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) ▼Regulation
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
Cybersecurity & Digital Trust › Identity Governance & Administration (IGA) ▼Regulation
AutoRABIT · Demand · Positive AutoRABIT issues security guidance, positioning itself as a solution provider for Salesforce security, potentially driving demand for its services.
CRM · Regulation · Neutral Article discusses security guidance for Salesforce teams, implying potential regulatory scrutiny but no direct impact on Salesforce.
Read original ↗
PR Newswire·75dRead more →
Data Security Posture & DLP▲

DATAMYTE earns ISO/IEC 27001:2022 certification for its Digital Clipboard platform

DATAMYTE has achieved ISO/IEC 27001:2022 certification for the information security management system supporting Digital Clipboard, its cloud-based, no-code manufacturing workflow platform. The certification, awarded by an independent body, validates that the ISMS meets the international standard, reinforcing the company's commitment to protecting operational, production, quality, and compliance data for over 1000 manufacturers including Ford, Boston Scientific, Northrop Grumman, CS Wind, Stellantis, Boeing, Tesla, Gillette, Borg Warner, Cabinetworks Group, Foxconn, Pepsico, and GM. CEO Joel Ronning stated that the certification provides independent confirmation of rigorous data protection standards, scaling with the platform and clients' evolving needs. Digital Clipboard enables organizations to digitize production workflows, inspections, audits, electronic work instructions, and other shop floor processes within a secure cloud environment, addressing the growing importance of cloud data security as manufacturers move away from paper-based quality processes.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Regulation
Cloud & Digital Infrastructure › Horizontal SaaS Competition
Read original ↗
PR Newswire·76dRead more →
Data Security Posture & DLP▼impact 4

Craneware says hackers stole significant volume of customer data

U.K.-based healthcare billing software maker Craneware disclosed that hackers stole a significant volume of customer data from its systems. The company said the attackers appear to have been expelled, but its investigation is ongoing. Craneware's flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States, and the company handles large amounts of medical records and patient data. The breach is the latest in a series of cyberattacks targeting tech companies that supply the U.S. healthcare sector, following incidents at TriZetto, CareCloud, Episource, and Change Healthcare.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
CRW.LSE · Regulation · Negative Craneware disclosed a significant customer data breach, which may lead to regulatory penalties, legal liability, and reputational damage.
Read original ↗
TechCrunch·76dRead more →
Data Security Posture & DLP▲

Boundeal launches controlled-disclosure data room for financial-sector M&A

Boundeal announced a controlled-disclosure data room configured for financial-sector mergers and acquisitions, responding to a rebound in dealmaking that saw global buyout-backed exit value rise 47 percent to $717 billion in 2025 and global M&A volume surge about 40 percent to roughly $4 trillion. The environment uses permission groups to separate strategic buyers, financial sponsors, lenders, legal advisers, and clean teams, with staged disclosure that expands access as a bidder advances and granular least-privilege controls at the folder and document level. Time-stamped audit trails, mandatory confidentiality agreements, and purpose-based access aim to prevent uncontrolled disclosure of fund economics, asset-level valuations, regulatory correspondence, and other sensitive data that can expose sellers to competitive harm, legal privilege loss, or supervisory risk. Boundeal is a virtual data room provider for M&A, due diligence, IPOs, fundraising, private credit, and restructurings, serving advisers, financial sponsors, corporate teams, and regulated institutions.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Competition
Cloud & Digital Infrastructure › Horizontal SaaS Competition
Boundeal · Demand · Positive Boundeal launches a new product tailored to financial-sector M&A, capitalizing on a rebound in global M&A volume and buyout activity.
Read original ↗
GlobeNewswire·76dRead more →
Data Security Posture & DLP

Teleskope Launches Native Slack Integration for Automated Data Remediation

Teleskope has launched a native integration on the Slack App Marketplace that discovers, classifies, and remediates sensitive data across messages, files, canvases, and lists in real time. The integration, called Teleskope for Slack, applies the same automated remediation the platform provides elsewhere, including tombstoning content or requiring business justification before release, all within Slack itself. It also scans historical content that existed before installation, and guarantees detection and remediation in under two seconds. The company, founded in 2022 by former Airbnb data security engineer Elizabeth Nammour, raised a $25 million Series A in 2026 and counts Ramp, Chevron Phillips, and Notion among its customers.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Competition
Teleskope · Technology · Positive Teleskope launched a new Slack integration, expanding its product capabilities.
Read original ↗
GlobeNewswire·81dRead more →
Data Security Posture & DLP▼

Flush, China Great Wall Securities, Ping An Securities among those named for illegal personal data collection

The National Cybersecurity Notification Center has reported that testing by the National Computer Virus Emergency Response Center found 72 mobile apps illegally collecting and using personal information. Securities apps including Flush, China Great Wall Securities, and Ping An Securities were among those listed. The Flush stock WeChat mini program and the China Great Wall Securities WeChat mini program were cited for issues such as failing to clearly present privacy policies, default consent to privacy policies, and privacy policies that are difficult to access. Flush was also found to have provided personal information to third parties without informing users of the recipients or obtaining separate consent, while China Great Wall Securities failed to offer a way to withdraw consent. The Ping An Securities WeChat mini program was cited for not listing the purposes, methods, and scope of personal information collection and use one by one in its privacy policy. A reporter from Blue Whale News called the relevant companies. The board secretary offices of Flush and China Great Wall Securities said they were not yet aware of the specifics, while Ping An Securities customer service stated they would verify and respond.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
002939.CS · Regulation · Negative Named for illegal personal data collection in WeChat mini program, failing to offer consent withdrawal.
300033.CS · Regulation · Negative Named for illegal personal data collection, including providing data to third parties without consent.
平安证券股份有限公司 (Ping An Securities Co., Ltd.) · Regulation · Negative Named for illegal personal data collection, not listing purposes and scope in privacy policy.
Read original ↗
蓝鲸财经·86dRead more →