Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
Data Sprawl to Drive 2022 IT Security Trends
By James Mignacca, CEO & Founder at Cavelo
The amount of data living on company networks proliferates every day. If you’re an IT, security or compliance professional that fact won’t come as a surprise. As a result, managing and tracking the data that collects on your organization’s devices, applications, computers and servers is becoming harder for teams to handle. An ongoing shift to distributed systems has fueled a data sprawl problem across organizations of all sizes that will only get worse over time. Expect the issue of data sprawl to drive four key data management, security and technology trends next year:
Prediction #1: Governance will underpin IT security strategy.
Data security and data privacy compliance aren’t optional practices – they are mandatory requirements and companies failing to comply will be fined. Governance will continue to link data management and IT security practices but expect it will show up at the board level too, as it falls within the realm of fiduciary responsibility. Boards have no choice but to take it seriously from a liability perspective and will cascade formal governance requirements through the organization as a result.
Prediction #2: As-a-service will rule.
Midsized enterprises and SMBs are adopting enterprise-grade tools as they work to strengthen cybersecurity defenses. But teams are discovering that those tools are expensive and noisy. The growing number of tools teams use to serve separate functions multiplies the number of vendors that teams have to manage. As-a-service options are an important alternative, but teams need to exercise caution in onboarding too many. While all as-a-service tools serve an important purpose, they lack an intersection point, making it harder to get a clear picture of the overall health of the business’s security posture. That lack of cohesion makes it tough to action as-a-service outputs, leading to a potential increase in risk.
Prediction #3: Teams will lean into automation to streamline processes.
We know that most breaches happen as a result of human error and unfortunately that’s because many teams continue to rely on manual processes when it comes to controls processes, systems configurations and data management. Even as IT and cybersecurity spend increases, many of the teams we talk to struggle to streamline processes and resource their teams appropriately. The good news is that midsized enterprises are getting behind process automation. Overall data security is a top motivator, but these organizations are also aiming for efficiency that will free up resources to focus on strategic work, instead of getting buried in the weeds.
Prediction #4: Data stewardship will become a priority function.
This one directly correlates to governance. Data privacy regulations boil down to understanding the custody of data and determining who’s the owner, and who’s the custodian. Knowing the difference between the two fundamentally changes the way we think about data. For years, personally identifiable information (PII) has been used as a blanket term to describe personal data. But the reality is that under that umbrella, there are many different types of PII, and varying degrees of sensitivity associated with each type. Having the ability to classify data by type is important not only when it comes to completing audits, but also for data protection. By knowing what types of data your organization has, you can properly rank and prioritize them according to risk.
Just like governance, expect to see greater conversation and pressure emerge around data stewardship. While critically important, successfully assigning and managing data stewardship is tough; businesses have data everywhere, most still rely on some level of manual data management processes and many haven’t formalized governance programs. Coincidentally, companies will have to lean into prediction #2 (as-a-service) and #3 (automation) to support data stewardship.
##
ABOUT THE AUTHOR
James Mignacca is a serial entrepreneur and life-long technology enthusiast with more than 20 years’ experience in the cybersecurity industry. He’s a champion of data protection and data privacy, and supports midsized enterprises as they navigate digital transformation, cybersecurity and regulatory compliance requirements.






