
Source: Arif Riyanto/Work, Business & Work via Unsplash.
Data security is the most diffuse of disciplines within the overall information security industry. More than other security disciplines, data security can enable benefits and introduce new barriers to downstream users, their applications and systems overall. The stakeholders and their perspectives are diverse, ownership is difficult to pin down, and capturing and quantifying the scope, intent and results are a challenge. This blog post highlights key findings from studies conducted by 451 Research by S&P Global which ask organizations’ end users about these pain points.
The Take
Effective data security goes beyond the absence of failure; it is a strategic enabler, allowing the uninhibited storage, flow and leverage of data resources within an organization. Achieving it requires a shift in perspective from isolated security controls managed by security personnel to a holistic view of organizational dynamics and the interplay of different stakeholders, including data owners, with different goals. Success hinges on establishing fulcrum accountability — a framework for balancing the responsibilities of these different stakeholders and understanding that strict accountability cannot be “owned” by either. Progress is validated through triangulation — a method of cross-validating questions to ensure all parties develop a shared understanding and alignment in goals. This approach transforms data security into a proactive, strategic function.
Everyone’s intention
Data security research has cross-referenced virtually every other research channel. Data security manifests itself in many adjacencies; both attitudes and mandates are driven by consumer sentiment, public policy and public safety. Previous research has discussed how diffuse data security is, how developers are affected and the subtleties of market sizing. 451 Research studies organizations and individual consumers on occasion, gauging their data security concerns.
Every individual and organization wants to secure the data they have or have been entrusted with. Yet absent of other forcing factors, the intentions fall short because outcomes often matter the most. Organizations actively invest to sustain and grow their businesses. Governments serve their citizens, educators serve their students and individuals serve themselves. While there are legal or contractual obligations to data security or privacy, risk management is not the organization’s primary goal. Risk management is a means to an end. Successfully achieving data security is characterized by the absence of failure.
We regularly see this tension between intent and action. In a recent study conducted by 451 Research, 48% of e-commerce and retail technology respondents or personas said improving data security was the most important initiative. Curiously, the same personas, when asked what they would increase investment for in the next 12 months, ranked data security ninth, behind CRM, customer engagement channels and agentic AI platforms. A separate study conducted by 451 Research, which includes analyzing organizations and individuals, regularly ask non-security personas about their attitudes and actions around data security. Understanding these different personas requires understanding the balances in accountability.

Fulcrum accountability
To strategically progress data security means aligning knowledge and personas. The below image presents four question types to two personas. Within a large organization, multiple personas and disciplines will be involved, but the below image keeps it simple with just two personas. While organizations intend to prioritize data security, there remains a disconnect between data owners and security owners. In some cases, data owners may bear the brunt of data security responsibility. In other cases, security owners may be united with data owners in a single team with shared goals. In the worst-case scenario, there may be some responsible for data and others responsible for security, but no one is responsible for data security.

More subtleties exist among these two personas. In some cases, certain technologies, including security controls, are furnished by a security team. A public key infrastructure (PKI) team may be responsible for generating or signing certificates, but it is up to different operational teams to employ them properly. This may be by design if the PKI team acts more like a third-party vendor that wishes to absolve itself of any subsequent operational risk. The most restrictive government intelligence agencies have the strictest separation-of-duty requirements, with high levels of mandatory access controls.
Triangulation is a critical requirement to progress strategic data security initiatives, and as the above image illustrates, asking question types (1) and (2) are critical for laying the groundwork for any data security program. If data owners are unaware of the technologies or processes they use, or if their plans to leverage data are unclear, then the likelihood of success in data security will be zero. Similarly, asking security-capability questions to security practitioners is essential. Requiring security teams to monitor potential data losses when there is limited data monitoring or activity detection capability will be effectively impossible. Question types (3) and (4) begin the triangulation journey, as different teams validate their awareness and importance to each other. A security team will always be reactive if they do not know the plans for data owners. Data owners that are willing and able to define and implement security represent a lost opportunity for security teams. As the first image illustrates, there are data owners who are willing to address data security concerns, but there is a lost opportunity to help them operationalize controls to remediate those issues.
Triangulation is one way to understand overall accountability while considering multiple intents. When designing a data security program, there are multiple dimensions to triangulation that must be considered. Substitute the general “data owner” persona with more specific owners responsible for trust, development, analytics, legal, cloud, IoT or AI owners, and there are many avenues to triangulate within an organization. Understanding these other vantage points contextualizes risk and reward. Security may be characterized as the absence of failure, but does data security need to be limited in this way? Understanding the proof and progress ahead for organizations better contextualizes risk and reward together.
Proof and progress
Within each triangulation path, understanding how progress is measured and proof is delivered is also critical. Before undertaking any new or additional data security initiative, it is important to understand why an organization needs to change and why it needs to do so now. The different triangulation avenues go some ways toward building the path forward, but how progress is proved is another matter.
Many organizations and their personas have good intentions about data security, but their positive and negative motivations more clearly determine how they will progress. Regulations and frameworks like PCI-DSS, FedRAMP and AICPA SOC 2 have clear rewards. A Level 1 merchant can secure lower interchange rates in payment networks. A contractor has the authority to operate for a particular government customer. SOC 2 becomes table stakes for organizations that license their products, services or subscriptions electronically; provable security questionnaires enable revenue recognition. Asking what happens to an organization if it succeeds in its data security initiative is one way to clarify how progress is achieved; asking what happens if it fails is another.
Organizations must also determine how to weigh sentiment, awareness, actions and results together in order to prove their progress over time. While data is an organization’s most durable asset, AI agents will create more dynamic systems of delivery to use data in new ways, opening up new risks and rewards. Data security is much more than data loss prevention, data security posture management, compliance automation, AI security, digital rights management, tokenization or encryption products. It is the adaptation to the process to help organizations progress. Given the intentions and the balanced accountability, the goal is to uncover key pain points in data security and the initiatives they are driving, the organizational maturity of programs and how they are measured, and where practitioners see risks increasing the most.
Want insights on Infosec trends delivered to your inbox? Join the 451 Alliance.

