Today’s reality is tomorrow’s risk. Unstructured data—documents, emails, messages, images, logs, and AI-generated content—is growing exponentially and spreading across every environment organizations depend on. It now represents the majority of the data enterprises create and store, including their most sensitive information.
Unlike structured data, unstructured data is highly distributed, constantly changing, and difficult to systematically classify and govern. As a result, sensitive information frequently ends up in places it shouldn’t be shared too broadly, stored in cloud platforms without adequate controls, or unintentionally exposed through misconfigurations. What begins as everyday data sprawl quickly becomes a widening exposure gap that traditional security models struggle to manage.
Attackers understand this shift. They no longer focus solely on databases; instead, they target documents, file shares, inboxes, and collaboration platforms where sensitive content, business logic, and personal data are less protected. These exposed assets can be exploited for extortion, fraud, credential abuse, or long-term infiltration.
Read the CSA Report: The Rise in Unstructured Data and AI Security Risks
Today, sensitive enterprise data is increasingly commingled with ungoverned and high-risk content (aka “toxic” data) across file shares and platforms, creating material exposure that automation and AI can unintentionally amplify.
When sensitive or regulated data (e.g., PII, PHI, PCI, export-controlled data) is exposed, misclassified, or uncontrolled beyond defined thresholds, the incident triggers breach response protocols, resulting in a time-consuming, enterprise-level incident—not a localized technical issue.
AI is both an accelerator and a risk multiplier
AI is now both a force multiplier and a risk amplifier, and its value depends on the strength of the foundations beneath it. While AI promises improved detection and automation, deploying it without baseline visibility and scanning can amplify existing blind spots.
As the report underscores, organizations must address these foundational pillars first to ensure AI enhances data protection rather than magnifying existing exposure.
Organizations view AI as both a top future threat (47%) and a core security capability (40%) for unstructured data. While many said they plan to rely on AI for detection, classification, and automation, foundational gaps remain. Only 9% of organizations reported having real-time scanning capabilities, and 23% cannot scan at all, raising concerns that AI may amplify existing blind spots rather than improving security outcomes.
Business risk increases as AI systems act on incomplete data, potentially accelerating data exposure, misclassification, or unauthorized access faster than organizations can respond. Deploying AI atop incomplete inventories and delayed detection will amplify blind spots. AI delivers value only when discovery, classification, and governance are strong.
Use 3 keys for a future-forward data security strategy
1. A DSPM moves the needle with integrated capabilities and comprehensive encryption.
Organizations must adopt a more comprehensive, holistic security strategy. Data security posture management (DSPM) is a great first step as the foundation of a broader approach. Equally essential capabilities, such as advanced analytics, encryption, access management, event reporting, and incident response, can be integrated into DSPM to more effectively safeguard data.
Omdia’s Decision Maker Survey stresses that as part of a DSPM, encryption is a must-have tool, mandated by most regulations, and an essential best practice for any sound data security practice. Most organizations encrypt on-premises data, but the colossal movement of data to the cloud has created a new and growing gap.
According to the Omdia findings, 47% of data in the cloud is deemed “sensitive,” warranting protective measures. However, Omdia respondents show that cloud data encryption rates are dangerously low; less than 10% of enterprises claim to have encrypted 80% or more of their cloud data. Organizations must adopt the encryption of their cloud-based data as a standard and ongoing best practice.
2. Embrace the strong shift toward unification with a platform-based approach.
In today’s intense cyber threat landscape, hastily acquired or internally developed stop-gap security measures can be problematic. These approaches can elevate vulnerabilities, increase management costs, and cause difficulties in discerning real threats.
Driven by the need to reduce complexity, streamline operations, and achieve a single interface, organizations are seeking a unified, platform-based, data-first security approach. Integrated security platforms manage data security across cloud, SaaS, and on-premises environments. Further, they centralize security management and provide a single view of security across the full data estate and the entire organization, streamlining and improving an organization’s data security posture.
Omdia’s Decision Maker Survey reveals data security is emerging as one of the leading areas, with 59% of respondents planning to adopt an integrated security platform in the near future. In comparison, the remaining 41% have not ruled out a platform-based approach as part of their future strategy.
Omdia underscores that organizations should validate that integration is part of all-encompassing platforms. An integrated platform is not a collection of point products but rather a united set of components that function together within a single data security platform.
3. Leverage AI with the proper safeguards to reduce workloads and detect security threats.
With the skyrocketing th of unstructured data—estimated by IDC to be 80% of all data, or 175 zettabytes of data (175 with 21 zeros) by 2025—the use of automation and AI/ML capabilities is vital to reduce workloads and improve detection. These tools are essential to manage the growing volume and complexity of the data landscape.
For instance, using AI/ML tools to constantly monitor real-time data access and use by individuals can streamline operations and improve threat detection, threat response, and security analytics and insights, thereby increasing the effectiveness of risk identification and mitigation. Further, as Omdia states, “AI-driven analytics can be used to predict potential security incidents before they occur, providing a proactive layer of protection that complements DSPM.”
At the same time, the rapid rise and adoption of generative AI introduce new requirements. For organizations, the proper safeguards—such as controls or restrictions—must be put in place. Omdia points out that, fundamentally, “critical business intellectual property and sensitive personally identifiable information must not be exposed to the generative AI domain.”
The current state of data security, as outlined in the Omdia study, is an urgent call to action for organizations across industries and of all sizes. No one is exempt from the threat and reach of cybercrime, which is growing and morphing at a swift pace. Organizations can bolster their data security posture by focusing on three above areas, the keys to a future-forward data security approach.