<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title><![CDATA[Top of MIND Blog | RSS ]]></title>
        <description><![CDATA[Top of MIND, blogs sharing our perspectives on AI-driven cyber security, data loss prevention (DLP) and insider risk management (IRM)]]></description>
        <link>https://mind.io</link>
        <image>
            <url>https://mind.io/favicon/favicon.svg</url>
            <title>Top of MIND Blog | RSS </title>
            <link>https://mind.io</link>
        </image>
        <generator>RSS for Node</generator>
        <lastBuildDate>Wed, 08 Jul 2026 15:00:32 GMT</lastBuildDate>
        <atom:link href="https://mind.io/rss.xml" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 08 Jul 2026 15:00:32 GMT</pubDate>
        <copyright><![CDATA[All rights reserved 2026]]></copyright>
        <item>
            <title><![CDATA[What are the minimum viable security controls for AI?]]></title>
            <description><![CDATA[<p><em>This is Blog 8 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong>What are the minimum viable security controls for AI?</strong></li></ol><p>CISOs have a short list of conditions AI must meet before it gets anywhere near enterprise data.</p><p>Ninety percent of enterprises are already running generative AI at scale. Most of the security leaders sitting next to those deployments aren&#x27;t sure they can stop AI from reaching the wrong data. <a href="https://mind.io/content/[object Object]">{children}</a>, 65% of CISOs said they were not confident or only somewhat confident in their AI data security controls. One in five AI projects fail to meet their intended goals. So security leaders have started doing something practical. They&#x27;ve drawn a line. Before a new AI system touches enterprise data, it has to clear a short set of conditions first.</p><p>We asked 124 CISOs and 20 senior practitioners what those conditions are. Their answers converged on a baseline that&#x27;s worth writing down.</p><h3>Why do CISOs gate AI before it touches enterprise data?</h3><p>The gate isn&#x27;t there to slow anyone down. It exists so security keeps visibility and control while the business moves fast.</p><p>The pressure is real. Business leaders are driving AI adoption at a pace security wasn&#x27;t designed to match, and the old assumptions no longer hold. Frameworks built for human actors don&#x27;t account for agents that inherit broad permissions and act without human judgment. Data estates that sat quietly in SharePoint for years, unclassified and loosely governed, suddenly become reachable the moment an AI tool is pointed at them.</p><p>CISOs in this research weren&#x27;t trying to block any of that. They were trying to make sure that when an AI initiative launches, it lands inside an environment where someone can still see what it&#x27;s doing and shut it down if it drifts. That&#x27;s the whole point of a baseline. It turns governance into something repeatable instead of something you reconstruct after every new project.</p><h3>What are the minimum viable security controls for AI?</h3><p>When we asked security leaders what has to be true before they&#x27;ll approve an AI initiative, the same six requirements came up again and again. None of them are ideal-state. They&#x27;re the practical gates CISOs are already applying today.</p><ul><li><strong>Enterprise deployment.</strong> The AI tool runs under an enterprise license, not a consumer account, so administrators keep visibility and activity stays auditable.</li><li><strong>Vendor data usage clarity.</strong> The organization confirms how the vendor uses its data and whether that usage can be turned off.</li><li><strong>Data retention and hosting transparency.</strong> Retention policies, hosting location and environment type are defined clearly, not assumed.</li><li><strong>Identity integration.</strong> People access the tool through SSO and existing identity governance. The AI system itself carries a unique, trackable identity.</li><li><strong>Scoped data access.</strong> The system reaches only the data its use case requires and stays walled off from everything that isn&#x27;t core to its function.</li><li><strong>Defined business KPIs.</strong> Success metrics are set before deployment, so the program measures outcomes instead of activity.</li></ul><p>Read together, they describe the conditions that let an AI initiative scale without quietly introducing data exposure no one chose to accept.</p><h3>Why is scoped data access the hardest control to get right?</h3><p>Of the six, scoped data access is where most organizations have the furthest to go. The principle is simple. A system should reach only the data its use case requires and stay walled off from everything else. Holding to it is where teams struggle, because most AI tools don&#x27;t arrive scoped. They arrive with the access of whoever turned them on.</p><p>That&#x27;s the gap that turns AI into a present risk rather than a future one. An agent that inherits a human&#x27;s permissions operates at the full scope of what that human can reach, not what the task actually needs. </p><img src="https://cdn.sanity.io/images/3l9nidp2/production/8043765cd90f27c5871fe563f8ed0ff561b53199-2176x612.png?w=500" /><p>Scoping access to the task is the control that does the quiet work behind every other one on the list. A system that can only reach what it needs can only ever expose what it needs. That&#x27;s also why scoping is hard. You can&#x27;t restrict access to data you haven&#x27;t found and classified, and most enterprises have years of unclassified files sitting in collaboration tools and cloud stores that no one has mapped. Until that data is visible, scoped access is a policy on paper rather than a boundary the AI system actually runs inside.</p><h3>How can security teams enforce these controls at AI speed?</h3><p>A baseline only helps if you can hold the line in real time. This is where most teams feel the strain, because the controls assume something many organizations don&#x27;t yet have: a clear, current picture of where sensitive data lives and who, or what, is touching it.</p><p>That picture is what MIND is built to give you. We discover and classify sensitive data across the unstructured estate, file stores, collaboration platforms and cloud repositories, so the boundary you drew at intake is one the AI system can actually be held to. We&#x27;re not just flagging where data sits. We&#x27;re minding the connection between that data and every identity reaching for it, human or agent, so the gate you set at intake stays enforced after the project goes live.</p><p>When security joins at project intake and the controls are already in place, governance becomes the thing that lets AI move faster, not the thing teams route around.</p><h3>What changes when these controls are in place?</h3><p>The organizations adopting AI fastest in this research share one pattern. They treat data trust as a prerequisite, not a cleanup task. They keep visibility into what their systems can access, they extend governance to non-human identities and they decide what success looks like before the first query runs.</p><p>From that footing, AI stops being a risk to manage cautiously and becomes a capability you can direct with confidence. Think of the six controls as a floor rather than a finish line. They make everything you build above them safe. Most teams already have the pieces. What&#x27;s been missing is the visibility and enforcement to make them hold at AI speed.</p><p><a href="https://mind.io/content/[object Object]">{children}</a>.</p><p>If your organization is moving on AI and you want to see what scoped access and real-time enforcement look like against your own data, <a href="https://mind.io/[object Object]">{children}</a>.</p>]]></description>
            <link>https://mind.io/blog/what-are-the-minimum-viable-security-controls-for-ai</link>
            <guid isPermaLink="true">https://mind.io/blog/what-are-the-minimum-viable-security-controls-for-ai</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 24 Jun 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/0a23b56706701119bbcd5cc53550194049d81083-5326x3551.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[NSPM-12: Why secure systems start with data visibility]]></title>
            <description><![CDATA[<h2>Washington just put data visibility on a deadline. Every security leader is already on the same clock.</h2><p>Recently, a National Security Presidential Memorandum (<a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-12/">NSPM-12</a>) was signed that overhauls how the federal government secures its most sensitive military, intelligence and classified systems. It re-establishes the Committee on National Security Systems for the first time in over 35 years, names the director of the NSA as the national manager for those systems and sets what one former agency security chief called &quot;aggressive&quot; timelines for getting the work done. Strip away the federal language and the message lands close to home. The work starts with knowing exactly what data you hold and where it sits, and the clock is running faster than it used to.</p><h3>What does the NSPM-12 cyber memo actually require?</h3><p>The memo, <a href="https://federalnewsnetwork.com/cybersecurity/2026/06/trump-memo-sets-aggressive-timelines-to-secure-sensitive-systems/">reported in detail by Federal News Network</a>, gives the reconstituted committee power to set baseline cybersecurity requirements for every national security system and to issue emergency directives when threats emerge. It mandates that those systems meet or exceed NIST standards. It also rescinds two foundational directives from 1990 and 2022 and folds their authority into a single accountable structure.</p><p>The deadlines are the part worth noticing. Agencies have 60 days to produce a roadmap and 90 days to review and update their policies. Another 90-day clock covers guidance on secure hosting of sensitive systems in the cloud, and a separate 60-day clock covers new incident reporting standards. Agencies also have to make an inventory of their information systems available to the NSA. That last requirement reads like housekeeping. It&#x27;s actually the foundation everything else rests on.</p><h3>Why are AI-driven adversaries behind the aggressive timelines?</h3><p>The urgency isn&#x27;t abstract. The memo follows an <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">AI security executive order</a> signed June 2 and <a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/">NSPM-11</a> on June 5, both aimed at how artificial intelligence is reshaping national security. Bob Ackerman of DataTribe framed the new memo as a direct response to foreign adversaries using AI to speed up and scale their cyber campaigns against sensitive U.S. systems.</p><p>That pattern is familiar to anyone defending a private network. Attackers now move at machine speed. They probe and adapt faster than human review can keep up with, and they go looking for the data that&#x27;s easiest to reach. The federal answer is to shorten its own timelines to match the threat. Security leaders outside government face the same acceleration, just without a presidential memo telling them when to act.</p><h3>Why does protecting sensitive data start with finding it?</h3><p>Notice what the memo asks for first. Before new standards, before cloud guidance, before incident reporting, it asks agencies to inventory their systems. Hemant Baidwan, the former DHS security chief quoted by Federal News Network, said the point is to stop agencies from approaching national security systems through separate, disconnected channels.</p><p>That instinct is right, and it scales down to every organization. Most data risk doesn&#x27;t come from the systems you&#x27;re already watching. It comes from the sensitive data you&#x27;ve lost track of, copied into a SaaS app or sitting in a cloud bucket nobody owns anymore. A baseline requirement only covers the data you&#x27;ve actually located and classified. Without that groundwork, a new policy is just words with nothing underneath them.</p><h3>How does data visibility turn a mandate into momentum?</h3><p>This is where the work gets practical. You can&#x27;t put sensitive data under policy until you know what it is and where it sits. MIND starts there. The platform discovers and classifies sensitive data wherever it moves, across SaaS, cloud and GenAI tools, and reads both the content and the context around it. So a security number flagged in a finance system looks different from the same string buried in a public share, and your team can tell which one matters.</p><p>MIND isn&#x27;t just scanning for matches. It&#x27;s minding where your most sensitive data lives and how it&#x27;s moving, so your people can spend their attention on real exposure instead of false positives. When a mandate arrives with a 60-day clock, the teams that already have that visibility don&#x27;t scramble. They already know what they&#x27;re protecting, and they can prove it.</p><p>The federal memo is a deadline for agencies. For everyone else, it&#x27;s a preview. AI is compressing the time you have to find and protect sensitive data, with or without a directive forcing the issue. The first move is the same one Washington made. Know what you have. </p><p><a href="https://mind.io/[object Object]">{children}</a>.</p><h3>Sources</h3><ul><li><a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-12/">National Security Presidential Memorandum/NSPM-12, The White House</a></li><li><a href="https://federalnewsnetwork.com/cybersecurity/2026/06/trump-memo-sets-aggressive-timelines-to-secure-sensitive-systems/">Trump memo sets &#x27;aggressive&#x27; timelines to secure sensitive systems, Federal News Network</a></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">Promoting Advanced Artificial Intelligence Innovation and Security, The White House</a></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/">National Security Presidential Memorandum/NSPM-11, The White House</a></li></ul>]]></description>
            <link>https://mind.io/blog/nspm-12-data-visibility</link>
            <guid isPermaLink="true">https://mind.io/blog/nspm-12-data-visibility</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Thu, 18 Jun 2026 18:27:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/d86c9a5e70f4ca1450f3f8b12cd5c0c114e28a31-4928x3264.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[How high data trust speeds up AI]]></title>
            <description><![CDATA[<h2>High data trust is becoming the quiet difference between AI programs that scale and ones that stall.</h2><p><em>This is Blog 7 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong>How high data trust speeds up AI</strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>There&#x27;s a finding in MIND&#x27;s research that&#x27;s easy to lose under all the risk numbers. The security leaders who described the most confident path forward with AI weren&#x27;t the most cautious ones. They were the fastest. In a study of 124 security leaders run with CISO Executive Network, alongside 20 in-depth CISO interviews, one profile kept repeating. Teams that had classified their data and governed who could reach it were scaling AI while their peers were still arguing about whether it was safe to begin. <a href="https://mind.io/content/[object Object]">{children}</a> gives that profile a name. It calls high data trust a competitive accelerant, and the advantage it creates is already widening.</p><p><strong>What matters: </strong>When your data is classified and access is governed, moving fast with AI stops being a gamble. That foundation is the real source of the speed advantage.</p><h3>Why are some organizations moving faster with AI than others?</h3><p>The honest answer isn&#x27;t appetite for risk. Ninety percent of the organizations in the research are already running enterprise GenAI, so almost everyone has started. The difference shows up in what happens next. Only about one in five of those AI initiatives are meeting the KPIs they were meant to hit, and nearly two thirds of security leaders say they aren&#x27;t confident in their AI data security controls.</p><p>The teams pulling ahead removed the friction before it could stall them. When data is classified and access is governed, an AI use case starts from a known position instead of a guess. Outcomes get defined up front. Agents work inside boundaries someone actually set. Security shows up as a design partner rather than a gate at the end. That&#x27;s what lets a program move from idea to production without a six-week detour to work out what the model can see.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/b6cf50ff7dee7b4cc123b2b0f5d0950dc98f0097-1088x248.png?w=500" /><h3>What does high data trust actually look like inside an organization?</h3><p>It&#x27;s less abstract than it sounds. The CISOs who described operational confidence, not aspiration, shared a recognizable setup. They had visibility into their data estate, so they knew what existed and what shape it was in. Their identity framework had been extended to cover non-human actors, which meant an AI agent carried a trackable identity instead of borrowed human permissions. Enforcement ran at the same speed as the AI touching the data, or there was a clear plan to get it there.</p><p>From that position, AI stops being a risk to manage and becomes a capability to direct. The report is blunt about the distinction. Governance without enforcement is intention without effect. Data trust is what closes that gap, and it behaves like an operating condition rather than a policy document.</p><h3>Why is the gap between AI leaders and laggards widening?</h3><p>Because data trust compounds. Every well-scoped AI project an organization ships makes the next one easier, since the classification and identity work is already done. Clean data invites broader experimentation. Governed identities let new agents deploy with defined scope instead of inherited risk.</p><p>For organizations still carrying data debt, the same dynamic runs in reverse. Every new initiative launched on an unclassified estate adds exposure. Every agent deployed without proper identity governance inherits permissions it was never meant to have, at machine scale. The research found the divide is already measurable in the confidence numbers, and AI is being adopted faster than most teams can close that gap by reacting to it. The foundation that removes the risk turns out to be the same one that creates the speed.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/3888524121c7ba01253fd81436fdd06c49a4c240-2176x556.png?w=500" /><h3>How does data trust turn security into a speed advantage?</h3><p>This is where the security team&#x27;s role changes. Once you can see your data and govern who and what reaches it, enforcement becomes the thing that lets the business say yes quickly instead of the thing that says no slowly.</p><p>That&#x27;s the work MIND focuses on. MIND <a href="https://mind.io/product/data-discovery">{children}</a> sensitive data across your environment, then watches how it moves to GenAI tools and <a href="https://mind.io/solutions/[object Object]">{children}</a> in real time. We aren&#x27;t just inventorying what AI can reach. We&#x27;re minding the boundary between the data your AI should use and the data it should never touch, so your team can approve new initiatives with the visibility to back the decision.</p><p>With that foundation in place, the security team becomes the group that makes fast AI adoption defensible, instead of the group asked to clean up after it.</p><h3>Where should you start building data trust?</h3><p>Start with visibility. You can&#x27;t enforce policy on data you haven&#x27;t classified or govern an agent reaching an estate you haven&#x27;t mapped. Everything else in the research, from identity governance for non-human actors to outcome measurement, depends on knowing what data you have and where it lives.</p><p>The full report, <a href="https://mind.io/registration/[object Object]">{children}</a>, walks through all seven insights, including what the organizations getting this right are doing differently. If your team is being asked to move faster with AI, it&#x27;s worth seeing where data trust is already separating the leaders from everyone catching up.</p><p>Let&#x27;s mind what matters.</p>]]></description>
            <link>https://mind.io/blog/how-high-data-trust-speeds-up-ai</link>
            <guid isPermaLink="true">https://mind.io/blog/how-high-data-trust-speeds-up-ai</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 17 Jun 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/7f8b796c4add3c1af948cd66c4a90d542500fc50-4912x3264.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[What the Fable 5 suspension means for AI data security]]></title>
            <description><![CDATA[<h2>When a model can vanish overnight, the real question is what it was touching.</h2><p>On the evening of June 12, a single letter took two of the most capable AI models on the market offline for every user in the world. Anthropic received an export-control directive from the US government at 5:21 PM Eastern. Within hours, Claude Fable 5 and Mythos 5 stopped responding for everyone. Other Claude models kept running. The two newest ones, including a model that had been public for three days, went dark. If you lead a security team, the practical headline is how fast something your organization depends on can disappear, along with the question of what that system could see while it ran.</p><h3>What actually happened with the Fable 5 suspension?</h3><p>The directive itself was narrower than the shutdown that followed. Citing national security authorities, the US government <a href="https://www.anthropic.com/news/fable-mythos-access">ordered Anthropic</a> to block access to Fable 5 and Mythos 5 for any foreign national, inside or outside the United States. That included Anthropic&#x27;s own foreign-national staff. There&#x27;s no reliable way to check the nationality of every person behind an API key across a user base in the hundreds of millions. On same-day notice, it&#x27;s impossible. So the only compliant move was to turn both models off for everyone. Anthropic <a href="https://simonwillison.net/2026/Jun/13/us-government-directive-to-suspend-access/">said as much</a> when access started failing that night, returning a flat &quot;not available&quot; to anyone who called the model.</p><h3>Why is an AI jailbreak a data exposure problem?</h3><p>The stated reason was a reported jailbreak. By Anthropic&#x27;s account, the evidence was verbal and fairly narrow. The technique amounted to asking the model to read a codebase and fix the flaws it found. Anthropic said other widely available models can do the same thing. Defenders use the capability every day. <a href="https://techcrunch.com/2026/06/12/anthropics-safety-warnings-may-have-just-backfired-the-government-has-pulled-the-plug-on-its-most-powerful-ai/">TechCrunch reported on the response that followed</a>.</p><p>Set the threat question aside, because there&#x27;s a quieter point underneath it. The risk in a capable model is rarely the model itself. It&#x27;s the data the model can see and the actions it can take on that data. A system that reads your code and surfaces its weaknesses is, in plain terms, a system with deep access to sensitive material. The jailbreak debate is a data-access debate wearing different clothes. That&#x27;s the lens a security team should bring to every AI tool it adopts, long before a regulator gets involved.</p><h3>What happens when an AI dependency disappears overnight?</h3><p>Here&#x27;s the operational lesson. A product serving hundreds of millions of people went offline in hours, on a decision its own vendor couldn&#x27;t override. Anyone who had wired Fable 5 into a workflow lost it without warning.</p><p>Builders reacting in real time landed on the obvious takeaway. As Snyk <a href="https://snyk.io/blog/fable-mythos-suspension-security-takeaways/">put it in their analysis</a>, model redundancy has become a resilience requirement rather than a performance footnote. Treating a single hosted model as a hard dependency creates a single point of failure. That&#x27;s a security problem whether the cause is an outage or a US government letter. The cause changes. The exposure doesn&#x27;t.</p><h3>Can you govern AI you can't see touching your data?</h3><p>Most organizations can&#x27;t answer a simple pair of questions about any given model. </p><ol><li>Which workflows depend on it. </li><li>What sensitive data passes through it on the way. </li></ol><p>The dependency stays invisible until it breaks. The data flow stays invisible until it leaks.</p><p>You can&#x27;t plan for the loss of something you never mapped. You can&#x27;t contain the exposure of data you can&#x27;t watch moving. The Fable 5 suspension made both gaps visible at once, for free, with no breach attached. The teams that came through it calmly were the ones who already knew where their AI tools reached into their data.</p><h3>How do security teams build data trust before AI outruns them?</h3><p>The fix isn&#x27;t predicting the next directive. No one can. The better goal is knowing your own environment well enough that a surprise stays a surprise instead of becoming an incident. That starts with seeing where sensitive data actually moves, including the moments it flows into AI and GenAI tools that nobody formally approved.</p><p>This is the work MIND does. We discover and classify sensitive data wherever it lives, then watch it in motion across SaaS and GenAI apps with controls that read content and context together. We don&#x27;t stop at flagging another alert. We mind where your most sensitive data meets the AI tools your teams have already adopted, so adoption never outpaces what you can see and govern. Here, data trust is the working foundation that lets you say yes to AI without losing track of what it can reach.</p><p>The Fable 5 suspension exposed a visibility gap that every security team can close now. <a href="https://mind.io/[object Object]">{children}</a>. Find out where your sensitive data is already meeting AI.</p><h3>Sources</h3><p><a href="https://www.anthropic.com/news/fable-mythos-access">Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (Anthropic)</a></p><p><a href="https://simonwillison.net/2026/Jun/13/us-government-directive-to-suspend-access/">Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (Simon Willison&#x27;s Weblog)</a></p><p><a href="https://www.bloomberg.com/news/articles/2026-06-13/anthropic-says-us-limits-foreign-access-to-fable-5-mythos-5">Anthropic Says US Orders Halt to Foreign Access for Fable 5, Mythos 5 AI Models (Bloomberg)</a></p><p><a href="https://techcrunch.com/2026/06/12/anthropics-safety-warnings-may-have-just-backfired-the-government-has-pulled-the-plug-on-its-most-powerful-ai/">Anthropic&#x27;s safety warnings may have just backfired (TechCrunch)</a></p><p><a href="https://snyk.io/blog/fable-mythos-suspension-security-takeaways/">When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams (Snyk)</a></p>]]></description>
            <link>https://mind.io/blog/what-the-fable-5-suspension-means-for-ai-data-security</link>
            <guid isPermaLink="true">https://mind.io/blog/what-the-fable-5-suspension-means-for-ai-data-security</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ed22a806f0303d1e96fc47ce98acf7b4192c7b52-1096x720.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[ServiceNow API setting left customer data open]]></title>
            <description><![CDATA[<h2>Shared responsibility looks different when the vendor's side of the deal quietly fails.</h2><p>On June 5, ServiceNow patched a bug that had let unauthenticated users pull data from customer instances over the open internet. No phishing campaign and no stolen credentials. An internet-facing REST endpoint shipped with authentication switched off, and anyone who found it could query a customer&#x27;s instance directly. Customers learned about it through <a href="https://support.servicenow.com/kb?id=kb_article_view&amp;sysparm_article=KB3067321">a knowledge base article</a> locked behind ServiceNow&#x27;s support portal, then through <a href="https://www.reddit.com/r/servicenow/comments/1u0c45c/potential_servicenow_breach/">Reddit threads</a> where admins compared logs and traded indicators. <a href="https://techcrunch.com/2026/06/10/servicenow-tells-customers-a-bug-left-some-of-their-data-exposed-to-the-internet/">TechCrunch</a> and <a href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/">BleepingComputer</a> picked the story up from there. If you run ServiceNow, this one deserves your attention.</p><h3>What happened with the ServiceNow API exposure?</h3><p>Administrators discussing the incident traced the issue to a REST endpoint at /api/now/related_list_edit/create that was configured with requires_authentication set to false, <a href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/">according to BleepingComputer</a>. That one setting meant requests didn&#x27;t need a password or token to reach instance data. ServiceNow&#x27;s bulletin says the issue &quot;could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended,&quot; and the company confirmed evidence of successful queries against instance tables for a subset of customers. In <a href="https://trust.servicenow.com/notifications/1205429e-fea3-4cbf-b37b-8cd3a4e07aef">a public advisory published June 10</a>, ServiceNow said it believes the activity was likely tied to security researchers or customer-led bug bounty testing rather than a malicious actor. That&#x27;s plausible. It&#x27;s also unverifiable from the outside, and hope isn&#x27;t a control.</p><h3>Who's affected by the ServiceNow security incident?</h3><p>ServiceNow says the issue pertains to customers on the Australia platform release, plus customers on earlier releases who made certain configuration changes. The boundary looks softer in practice. <a href="https://techcrunch.com/2026/06/10/servicenow-tells-customers-a-bug-left-some-of-their-data-exposed-to-the-internet/">TechCrunch reports</a> that several admins outside Australia found evidence of external access to their instances. ServiceNow has opened support cases with every customer it believes was affected. If you haven&#x27;t received one, the company&#x27;s position is that you weren&#x27;t impacted. Verify that yourself anyway. The vulnerable endpoint was reachable on any unpatched instance, and your own logs will tell you more than a vendor&#x27;s probability estimate will.</p><h3>What data could someone reach inside a ServiceNow instance?</h3><p>ServiceNow hasn&#x27;t disclosed what was accessed or taken. The exposure surface is the worrying part. Instances commonly hold support tickets, employee records, asset inventories and configuration details for corporate systems, <a href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/">as BleepingComputer notes</a>. Support tickets deserve particular attention because people paste secrets into them. Passwords and API tokens shared during troubleshooting live on in ticket history, which is why support platforms keep ending up in attackers&#x27; crosshairs. The <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/">Salesloft Drift attacks</a> followed the same logic against Salesforce customers last year.</p><h3>Why does the ServiceNow disclosure timeline matter?</h3><p>ServiceNow&#x27;s own advisory acknowledges it received a confidential bug bounty submission describing a similar issue on April 22. <a href="https://thehackernews.com/2026/06/servicenow-flaw-exploited-to-gain.html">The Hacker News reports</a> a Reddit claim that the company had tracked the problem internally since early April and classified it as non-urgent, with remediation planned for a future release. The patch landed June 5, after anomalous activity had already begun. The first customer notice sat behind a login wall. None of that is unusual for a large vendor, and that&#x27;s the problem. The window between a vendor knowing and a customer knowing is where your risk lives, and you don&#x27;t get to set its length.</p><h3>What should security teams do about the ServiceNow bug right now?</h3><p>Start with your logs. Review requests to /api/now/related_list_edit, and look specifically for traffic from 51.159.98.241, the IP address <a href="https://www.reddit.com/r/servicenow/comments/1u0c45c/comment/oqoo9wj/">admins shared</a> as an indicator of potential compromise. Rotate any credentials or tokens that passed through support workflows, and confirm API logging is enabled going forward. Then ask the harder question. Could you say, today, which records in your ServiceNow instance would actually hurt if a stranger read them? Most teams can&#x27;t, and that&#x27;s the gap this incident exposes.</p><h3>How do you prepare for the next SaaS vendor's bad default?</h3><p>You can&#x27;t control a vendor&#x27;s endpoint configuration. You can control how well you know the data sitting behind it. That knowledge is what turns a vendor advisory from a crisis into a checklist. MIND&#x27;s context-aware platform gives security teams that knowledge ahead of the incident, classifying sensitive data across SaaS apps by what it contains and how it moves. MIND isn&#x27;t just classifying files. It&#x27;s minding the places sensitive data quietly accumulates, including the ticket queues and workflow records nobody thinks of as a data store. When the next advisory lands, that&#x27;s the difference between answering &quot;what was exposed&quot; in minutes and digging for weeks.</p><p>If this week had you searching ServiceNow logs without knowing what you were protecting, that&#x27;s the gap worth closing. See what MIND looks like in your environment. Let&#x27;s mind what matters.</p><h6><a href="https://mind.io/[object Object]">{children}</a></h6>]]></description>
            <link>https://mind.io/blog/servicenow-data-exposure-api-bug</link>
            <guid isPermaLink="true">https://mind.io/blog/servicenow-data-exposure-api-bug</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ed22a806f0303d1e96fc47ce98acf7b4192c7b52-1096x720.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why AI is a stress test of your security fundamentals]]></title>
            <description><![CDATA[<h2>AI doesn't create new risk. It surfaces what you already carry, at machine speed.</h2><p><em>This is Blog 6 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why AI is a stress test of your security fundamentals</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>AI doesn’t break your security. It finds where your security was already broken. Every CISO we spoke with in <a href="https://mind.io/content/[object Object]">{children}</a> described some version of the same moment. An AI tool got pointed at a data estate, and within days it surfaced something that had been sitting there exposed for years. Nobody planted a new flaw. The flaw was already there. AI just reached it faster than anyone could react.</p><p>That reframes the whole conversation. The question isn’t whether AI introduces danger. It’s whether your foundation can absorb the speed at which AI exposes the danger you already have.</p><p><strong>What matters:</strong> AI doesn’t introduce new vulnerabilities. It accelerates through the ones already there, faster than governance was ever built to respond.</p><h3>Does AI actually introduce new security risks?</h3><p>Mostly, no. AI accelerates through the gaps that already exist. The organizations that neglected data classification and identity governance are now meeting those deficits at machine speed instead of human speed.</p><p>Think about what changed. For years, weak fundamentals were survivable because no system went looking for everything at once. Unclassified files stayed quiet. Overshared folders stayed unnoticed. Then an AI tool connected to the same environment and read all of it without pausing to ask whether it should. The vulnerability didn’t appear. It got amplified.</p><p>This is why we describe AI as a stress test rather than a threat. A threat is external. A stress test measures whether what you already built can hold under load. AI is the load.</p><h3>Why does AI expose weak fundamentals at machine speed?</h3><p>Because every deficit compounds the moment velocity enters the picture. An organization that can’t enforce policy also can’t govern what AI does to its unclassified data. When the thing accessing that data moves at machine speed and applies no human judgment, both gaps widen at once and they keep widening.</p><p>We mapped this across the <a href="https://mind.io/blog/[object Object]">{children}</a>. The enforcement gap, the shaky data estate, the agent that <a href="https://mind.io/blog/[object Object]">{children}</a>. Each one was manageable on its own when work moved at human pace. Under AI velocity they stack. The result is exposure that surfaces faster than governance was ever designed to respond.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/334971678bb2eed4dec937b86d0336891651165d-2176x616.png?w=500" /><h3>Are only 20% of organizations ready to run AI safely?</h3><p>According to the CISOs in this study, few have the security maturity to run AI safely at scale. In fact almost 80% are lacking and the consequences run from stalled projects and regulatory exposure to, for smaller organizations, events serious enough to threaten the business itself.</p><p>That number lands hard when you set it against adoption. Ninety percent of the organizations surveyed are already running Enterprise GenAI, and 65% of their security leaders aren’t confident their controls can prevent unsafe AI data access. So the maturity gap and the deployment curve are pointed in opposite directions. Tools are live. Confidence is not.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/1f42f38ccfa753b538ce497b08727ce5dd1cae1d-2176x560.png?w=500" /><p>None of this is hypothetical. The conditions are already in place.</p><h3>What happens when AI inherits access no one scoped?</h3><p>It does exactly what it was told to do, and that’s the problem. At one research organization, a staff member used an enterprise AI tool to build a participant cohort. The tool ran under that person’s credentials and reached data sources that should never have been part of the query. The output contained records the researcher had no authorization to see.</p><p>No policy was technically violated. The tool performed the function it was built for. The access framework had simply never been extended to govern what an AI system could reach. That’s the quiet danger of agents inheriting broad human permissions without human judgment. They operate at the full scope of what they can touch, not the narrow scope of what they actually need.</p><p>This is the foundational debt of identity governance, surfacing as an AI incident. The permission was always too broad. AI just used all of it.</p><h3>How do you pass the audit AI is already running?</h3><p>You start by treating data trust as the foundation, not the afterthought. The CISOs describing the most confident path forward shared a clear profile. They had visibility into their data estate. They had extended identity governance to cover non-human actors. They had enforcement that runs at AI speed.</p><p>That’s where MIND fits as a guide. We aren’t just scanning files for patterns. We’re minding the integrity of your data estate so an AI tool can’t quietly reach what it was never meant to see. MIND discovers and classifies sensitive data wherever it lives, then enforces policy on data in motion as it flows toward GenAI and agents, at the speed those systems actually move.</p><p>The point was never to slow AI down. A strong foundation is what makes fast safe. When the fundamentals hold, AI stops being the audit you’re afraid of and becomes the accelerant you can direct.</p><h3>Where do we go from here?</h3><p>If you’re rolling out AI faster than you can govern it, that’s the gap to close first. See what MIND surfaces in your own environment, and find out what the audit would reveal before it reveals itself. That’s DLP at AI Speed, and it’s how you mind what matters most.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to see all seven insights, the CISO interviews behind them and what the organizations getting it right are doing differently.</p><h5><em>Data Trust + AI Success Blog Series</em></h5><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why AI is a stress test of your security fundamentals</em></strong></li></ol><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/why-ai-is-a-stress-test-of-your-security-fundamentals</link>
            <guid isPermaLink="true">https://mind.io/blog/why-ai-is-a-stress-test-of-your-security-fundamentals</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/3bc0b944df3f51e5b326bd22c93f7afa94bed1bf-3872x2581.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why CISOs need a seat at the AI design table]]></title>
            <description><![CDATA[<h2>CISOs support AI adoption. Getting involved before the decisions are made is a different problem.</h2><p><em>This is Blog 5 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why CISOs need a seat at the AI design table</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>There&#x27;s a framing problem that keeps showing up in boardrooms. The business deploys AI. The CISO finds out afterward. An incident surfaces. Everyone agrees that security should have been involved earlier. And then the same pattern repeats with the next initiative.</p><p>In MIND&#x27;s research, <a href="https://mind.io/content/[object Object]">{children}</a>, the CISOs we interviewed weren&#x27;t describing a conflict. They were describing a communication problem with real organizational consequences. They want AI to succeed. What they can&#x27;t always do is get the business to understand the risk landscape it&#x27;s walking into before the architecture is already set.</p><p><strong>What matters:</strong> CISOs want AI to succeed. The challenge is getting the business to make risk decisions explicitly, before the architecture is already set.</p><h3>Why is AI adoption outpacing security involvement?</h3><p>Business leaders are setting the pace. CEOs, COOs and business unit owners are driving AI adoption, and the urgency is real. AI offers competitive advantage and the organizations moving fastest are the ones capturing it.</p><p>That speed creates a structural problem for security. When a tool is vetted, purchased and deployed before security gets visibility, the best the CISO can do is assess exposure after the fact. Governance frameworks that were designed to be proactive end up operating reactively by default.</p><p>Our research found the same pattern at scale. Ninety percent of organizations are already running enterprise-grade GenAI. The majority of those deployments happened with security playing catch-up, not catch-before.</p><h3>Why is translating AI risk so difficult?</h3><p>Most risk conversations in the enterprise have a shared vocabulary. Regulatory exposure maps to compliance budgets. Breach costs map to cyber insurance. These framings aren&#x27;t perfect, but they&#x27;re legible to finance and legal and boards.</p><p>AI risk doesn&#x27;t reduce neatly. It lives in system behaviors, data flows and emergent outputs that most executives aren&#x27;t positioned to evaluate directly. When an AI agent inherits broad permissions and starts surfacing data at machine speed, the exposure doesn&#x27;t look like a line item. It looks like a tool that&#x27;s working exactly as designed.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/de897bcfa880fbb7db6c53b617601d975731a472-2176x496.png?w=500" /><p>The problem is that risk ownership requires risk literacy. And for AI specifically, that literacy is still being built at the executive level. When the translation succeeds, security earns a seat at the design table. When it doesn&#x27;t, the business proceeds and governance gaps widen by default.</p><h3>What happens when the CISO isn't at the design table?</h3><p>One organization in our research deployed a commercially available AI productivity tool after a standard vendor review. Within weeks, security started receiving alerts that looked like insider threat activity: a single account exfiltrating files at high volume across multiple drives. Investigation found the tool was using employee credentials to download and process files autonomously. No malicious actor. No policy violation. Just an AI tool doing exactly what it was built to do, on a data estate that was never scoped for that behavior.</p><p>That&#x27;s the real cost of late involvement. Governance gaps widen by default, quietly, while the business continues to accelerate. A failed project is visible. A governance gap that compounds over six months rarely gets named until something goes wrong.</p><p>When security isn&#x27;t at the design table, the decisions still get made. They just get made without the visibility that changes them.</p><h3>How do CISOs make the risk translation land?</h3><p>The CISOs in our research who describe the strongest relationships with business leadership share a recognizable approach. They don&#x27;t lead with what AI can&#x27;t do. They anchor the risk conversation to business consequences the executive team already understands: what a failed initiative costs, what regulatory exposure looks like in their specific industry, what competitive disadvantage compounds to over 18 months.</p><p>They also reframe the function itself. The CISOs who earn early involvement consistently describe security as the team that defines the conditions under which yes is possible, not the team that says no. That distinction matters. Organizations where security is perceived as a blocker are the ones where business units route around it entirely.</p><h3>What does early security involvement actually change?</h3><p>Getting security into AI program design before the architecture is set changes three things.</p><ol><li><strong>It changes the data access model</strong> <br/>When security is involved from the start, agents get scoped access to the data they need for their task. They don&#x27;t inherit the broadest available permissions simply because that was the default.</li><li><strong>It changes the outcome framework</strong> <br/>CISOs who earn early involvement are the ones who help define what success looks like before a single query is run. That measurement discipline is what makes failure visible while there&#x27;s still time to fix it.</li><li><strong>It changes the risk posture</strong> <br/>Governed AI programs move faster than ungoverned ones because the teams running them know what they&#x27;re working with. Speed and safety compound together rather than trade off.</li></ol><p>MIND isn&#x27;t just inventorying what data AI tools can reach. It&#x27;s minding the governance gaps that widen quietly when the business moves faster than the framework beneath it, so security teams have the visibility to earn and keep that seat at the table.</p><h3>Where do CISOs go from here?</h3><p>This is the fifth insight in a connected arc. The <a href="https://mind.io/registration/[object Object]">{children}</a> walks through all seven, including what high-performing security teams are doing to close the gap between AI adoption and data trust.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to see what the organizations getting this right are doing differently, and where the ones still catching up are losing ground.</p>]]></description>
            <link>https://mind.io/blog/why-cisos-need-a-seat-at-the-ai-design-table</link>
            <guid isPermaLink="true">https://mind.io/blog/why-cisos-need-a-seat-at-the-ai-design-table</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/7875ae2530cbc4f6225e55614bf013b74b9143a2-3000x2000.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[MIND joins Anthropic's Cyber Verification Program: A first in data security]]></title>
            <description><![CDATA[<h2>To stop data loss at AI speed, we need AI that can think like the attackers we're stopping.</h2><p>Attackers don&#x27;t operate with safety rails. They iterate on exfiltration techniques and study how insiders actually behave. They build threat models that exploit the gaps in conventional DLP. The AI systems defending against them, by default, can&#x27;t do any of that. Most foundation models include guardrails that limit dual-use cybersecurity work, which is exactly the work a modern data security platform needs to do well.</p><p>That gap matters. It&#x27;s the difference between a DLP system that recognizes risk patterns and one that anticipates them.</p><p>From the beginning, MIND has been built as an AI-native platform. Not AI-enhanced after the fact, but architected around the idea that modern data security requires systems that can reason through context, adapt to changing behaviors and operate at machine speed.</p><p><strong>Today, we&#x27;re extending that foundation.</strong></p><p>MIND has been accepted into Anthropic&#x27;s <a href="https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude">Cyber Verification Program</a>. We&#x27;re the first data security company verified. Not the first of several. The first.</p><p>The verification gives our platform access to the full range of Claude&#x27;s capabilities for defensive security research, without the default limitations that apply to general-purpose use.</p><h3>What is dual-use cybersecurity work?</h3><p>Some cybersecurity research is considered “dual-use,” meaning the same techniques can be applied defensively or offensively depending on intent.</p><p>Threat modeling, adversarial simulation and exfiltration analysis are good examples. Security teams use them to understand how attackers operate, identify weak points and strengthen defenses before incidents occur. Attackers use similar methods to find ways around controls.</p><p>Most foundation models apply broad safeguards around these topics by default, which makes sense for general-purpose use. But defensive security platforms still need the ability to study attacker behavior deeply and responsibly if they are going to protect modern environments effectively.</p><p>Anthropic&#x27;s Cyber Verification Program exists to create that distinction. Verified organizations can perform advanced defensive cybersecurity research within a structured and reviewed framework, rather than treating all dual-use work the same.</p><h3>Why does data loss prevention need unrestricted AI?</h3><p>Conventional DLP was built on static rules and predictable workflows. Sensitive data got tagged so policies could flag matches against it. That model assumed attackers and insiders behaved within predictable bounds, and it assumed sensitive data lived in predictable places. Neither assumption holds anymore.</p><p>Sensitive data now moves through GenAI prompts, agentic workflows and SaaS-to-SaaS integrations at speeds no human reviewer can match. Insider risk looks more like configuration drift than malicious exfiltration. The most useful way to find weaknesses in your own data perimeter is to model how an attacker would probe it.</p><p>Doing that work well takes AI cleared to go deep on attacker behavior. It has to study adversarial patterns and simulate how exfiltration actually happens. It also has to trace how insiders move inside the systems they target. Without that clearance, defensive tools see only the surface.</p><h3>What does Anthropic's Cyber Verification Program actually unlock?</h3><p>Anthropic&#x27;s Cyber Verification Program recognizes that some defensive security work requires unrestricted AI capabilities. Verified organizations can apply Claude to a wider range of dual-use cybersecurity tasks, including detailed threat modeling, exfiltration pattern analysis and adversarial simulation, provided that work is grounded in defensive objectives.</p><p>For MIND, that means our discovery and classification systems can train on a fuller picture of how sensitive data actually moves and how it&#x27;s actually targeted. Classification gets sharper because the model understands what attackers value and why. Detection gets more precise because the system can recognize exfiltration patterns it would otherwise be limited from studying.</p><p>The verification doesn&#x27;t loosen safety. Anthropic built it specifically because defensive security has different requirements than other AI use cases, and the program supports that work responsibly.</p><h3>How MIND is leading the way in safe and effective AI usage</h3><p>This isn&#x27;t an isolated milestone. It&#x27;s part of a broader pattern that reflects how MIND approaches AI.</p><p>Earlier this year, MIND became the first data security company to achieve <a href="https://mind.io/blog/mind-first-iso-42001-data-security">ISO/IEC 42001:2023 certification</a>, the international standard for responsible AI management. That certification governs how we build and operate AI systems. Anthropic&#x27;s Cyber Verification Program governs what advanced AI capabilities can be responsibly applied to in defensive cybersecurity.</p><p>Together, they validate two sides of the same equation: powerful AI systems require disciplined governance, and responsible governance should unlock more capable security outcomes. Two independent assessments, looking at different dimensions of MINDs AI maturity, arrived at the same conclusion about how MIND operates.</p><p>Together they represent the equilibrium we&#x27;ve been building toward: responsible governance on one side, advanced defensive capability on the other. That&#x27;s what it means to be AI-native in security. Not simply embedding AI into workflows, but building the operational discipline, governance and technical depth required to apply AI responsibly at scale.</p><p>MIND isn&#x27;t just running models. We&#x27;re minding the integrity of your data, with the rigor of certified AI governance behind the work and the depth of verified cyber capability inside it.</p><p>That pairing matters because both halves are necessary. Capability without governance is risky. Governance without capability is performative. Our customers deserve both.</p><h3>What does this mean for MIND customers?</h3><p>This means continued innovation at the front of what emerging AI models can bring. In practical terms, it will look like classification you can actually trust on challenging data and prevention that engages before a leak becomes an incident. The kind of foresight that turns DLP from a noisy alerting system into something a security team can run on autopilot.</p><figure><blockquote><p>“As an AI-native company, we operate at the cutting edge of what's possible. This verification lets us keep innovating to stay ahead and keep data safe at AI speed.”</p></blockquote><figcaption><cite>Eran Barak</cite> Co-Founder and CEO of MIND</figcaption></figure><p>For our customers, the work continues to feel the same: Stress-Free DLP that runs on autopilot. What changes is what we can do underneath and how confidently we can do it.</p><p>If you&#x27;re looking for an AI-native tool to help you secure your sensitive data, MIND seeks to be the most trustworthy option. </p><p>You can see for yourself <a href="https://mind.io/[object Object]">{children}</a>.</p>]]></description>
            <link>https://mind.io/blog/mind-joins-anthropic-s-cyber-verification-program-a-first-in-data-security</link>
            <guid isPermaLink="true">https://mind.io/blog/mind-joins-anthropic-s-cyber-verification-program-a-first-in-data-security</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 20 May 2026 13:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/b4589fcfec58da2da7455fb7be59abc2c068d0e6-7680x4320.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why most AI projects are failing]]></title>
            <description><![CDATA[<h2>Only 1 in 5 AI projects meet their KPIs. The model isn’t the reason.</h2><p><em>This is Blog 4 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why most AI projects are failing</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>One finding from MIND’s research, <a href="https://mind.io/content/[object Object]">{children}</a>, is hard to look past. Out of every five AI initiatives at the enterprises in the study, only one was meeting its KPIs. The other four were being re-architected, paused or quietly walked back.</p><p>When the CISOs in the research opened the hood on those failed projects, they kept finding the same thing underneath. It wasn’t the model. It was the data.</p><p><strong>What matters:</strong> AI projects rarely fail because the algorithms are flawed. They fail because the data feeding those algorithms was never classified or trusted in the first place.</p><h3>Why are 4 in 5 AI projects missing their KPIs?</h3><p>The same root cause kept surfacing. Data debt. Incomplete classification. Unscanned storage. Ungoverned access. The conditions that were survivable in a pre-AI world become the conditions that quietly break AI initiatives.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/b31f7fff479ff0aa7f35ef1b338f27c7c99037f7-2176x508.png?w=500" /><p>The survey data confirms what Igor described.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/c2f02e238c117d44bef8370d077623876343385b-2448x536.png?w=500" /><p>When the foundation is that shaky, the model on top of it doesn’t get a fair chance.</p><h3>What does this look like inside a real organization?</h3><p>One company in the research launched eleven AI initiatives over the past year. Two met their KPIs. The other nine were stalled or quietly walked back. In every one of those nine, data quality and known governance gaps were named as contributing factors.</p><p>That isn’t an AI problem, it has more to do with the data foundation.</p><p>The pattern is consistent. Teams scope a use case, connect the model to an existing data source and assume the data underneath is in a state that can support a reliable output. It usually isn’t. The repository was never fully classified. Access permissions were inherited from a SharePoint cleanup that never finished. The source data has duplicates, missing fields and rows nobody can vouch for. The model does exactly what it was asked to do, and the output is unusable.</p><h3>Why does the cause of failure stay hidden?</h3><p>The failures themselves aren’t invisible. A KPI that gets missed is a KPI that gets missed. What stays hidden is the cause.</p><p>When an AI initiative falls short, the post-mortem usually lands on the model. A bad prompt strategy. A hallucinating LLM. An agent that needs retraining. The data underneath rarely gets named, because most organizations aren’t measuring data trust. They’re measuring AI activity. Tokens processed. Prompts submitted. Lines of code generated. Those numbers describe how busy the system is, not whether the data feeding it can support a reliable output.</p><p>That’s how the visible failures get misattributed. It’s also how a different category of failure goes untracked entirely. An organization can report that an AI tool processed a million queries this quarter and call that a win. Inside those million queries, the same tool may be hallucinating answers, surfacing files to unauthorized users or producing insights that no one can trace back to a reliable source. None of that registers when the metric being tracked is usage.</p><p>The data debt keeps compounding. The project keeps reporting activity. The KPIs keep getting missed. Nobody connects the three.</p><h3>What does AI project success actually require?</h3><p>A different starting point. Before prompts, tokens or accuracy can be measured, security teams need to know what data the AI tool is reaching, whether that data has been classified and whether the access controls around it were built for the actor now using them.</p><p>This is where MIND focuses. MIND isn’t just inventorying data sources. It’s minding the foundation underneath every AI project the business is racing to ship, so the model on top of it has a chance of producing something the business can actually use. That means classifying what AI tools can reach, surfacing the ungoverned data that teams haven’t catalogued yet and giving security a clear line of sight from the data the model is consuming to the outputs it’s producing.</p><p>Organizations that treat data trust as a prerequisite for AI deployment approach the problem differently. They define the data quality standards their use case requires, measure whether those standards are being met and keep the visibility needed to connect a poor outcome to its actual cause. The result is an AI program where the failures show up early, while there’s still time to fix them, instead of late, when the budget is already gone.</p><h3>Where do CISOs go from here?</h3><p>This is one finding from a larger pattern in the research. The <a href="https://mind.io/registration/[object Object]">{children}</a> walks through all seven insights, with direct CISO quotes and a clear set of recommendations for security leaders trying to make AI projects succeed without giving up on governance.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to see why most AI projects are missing their KPIs and what the organizations getting it right are doing differently.</p><h5><em>Data Trust + AI Success Blog Series</em></h5><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why most AI projects are failing</em></strong></li></ol><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/why-most-ai-projects-are-failing</link>
            <guid isPermaLink="true">https://mind.io/blog/why-most-ai-projects-are-failing</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/1dd6fc7371b4d91f759c09d06a97329ff51bfc9d-4528x3019.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why AI doesn't behave like a human]]></title>
            <description><![CDATA[<h2>AI inherits human permissions but skips their judgment.</h2><p><em>This is Blog&nbsp; in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why AI doesn’t behave like a human</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>In most enterprise security programs, it’s quietly assumed that the actor on the other side of a control is human. A person who can be trained, who will hesitate and, even with broad permissions, will exercise some natural judgment about what to open, what to share and what to leave alone.</p><p>In MIND&#x27;s research, <a href="https://mind.io/content/[object Object]">{children}</a>, security leaders kept naming the same problem from different angles. The actor most of their controls were built for isn&#x27;t the actor that&#x27;s now moving through their data estate. AI doesn&#x27;t pause. AI doesn&#x27;t filter. AI doesn&#x27;t decide that something isn&#x27;t relevant before it surfaces it.</p><p><strong>What matters:</strong> AI inherits broad permissions without human judgment. Every data security control gap is now open to something that doesn&#x27;t hesitate.</p><h3>Why don't enterprise security controls work on AI?</h3><p>Every security control, policy and enforcement mechanism in the enterprise was designed with people in mind. Humans move at human speed. They can be trained, audited or held accountable. Even privileged users with broad permissions exercise some natural sense about what they share and when. A finance director with full access to compensation data still doesn&#x27;t open every file in the folder.</p><p>AI agents inherit the same permissions but behave differently. They don&#x27;t pause. They don&#x27;t filter. They don&#x27;t apply judgment to what they surface or use. When an agent connects to a data source, it finds everything within reach, not just what&#x27;s relevant.</p><p>The frameworks built around human behavior have no native language for what AI is doing. </p><img src="https://cdn.sanity.io/images/3l9nidp2/production/c8ee20d6397ef29a3790534287143d7b3aa5ed70-1088x224.png?w=500" /><h3>How widespread is the non-human actor problem?</h3><p>Wider than most security programs are prepared for. From MIND&#x27;s research:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/5f113d01600542560641ecfc82f77397ef6caa1e-1224x316.png?w=500" /><p>That last number is the one most CISOs in the research lingered on. A third of organizations already have agents inside their environment that nobody on the security team has inventoried. Those agents are reading, summarizing and acting against data using credentials inherited from and written for humans.</p><p>The exposure isn&#x27;t theoretical. It&#x27;s already running.</p><h3>What does this look like inside a real organization?</h3><p>One scenario from the research keeps coming up in CISO conversations. A team member submitted a set of internal documents to a consumer AI tool for analysis. The tool&#x27;s default settings permitted model training on submitted content. The data had left the building and no one knew where it went.</p><p>There&#x27;s no signature here. No alert pattern. No malicious actor to investigate. Just an employee using a tool that did exactly what it was supposed to do, against a policy framework that assumed the employee would be the one deciding what to share. The judgment layer was missing because the framework never expected it to be needed.</p><p>Data estates that were never fully classified become comprehensively and immediately exposed the moment an agent is pointed at them. The exposure isn&#x27;t created by AI. It was already there. AI is what makes it visible at machine speed, to systems that don&#x27;t apply human judgment about what they should or shouldn&#x27;t surface.</p><h3>What does data security at AI speed actually require?</h3><p>A different mental model for who you&#x27;re protecting against. The actor inside your data estate is no longer always a person. Sometimes it&#x27;s an inherited credential being driven by a model. Sometimes it&#x27;s an agent your IT team approved last quarter. Sometimes it&#x27;s a sanctioned LLM running against a SharePoint that was never classified.</p><p>This is where MIND focuses. MIND isn&#x27;t just enforcing the rules you already had on human users. It&#x27;s minding your data, whether or not the actors using it are human. That means classifying what your AI tools can reach, governing what they can do once they&#x27;re connected and surfacing the agent activity that&#x27;s already happening inside your environment so your team can act on what matters and leave the noise behind.</p><p>The work ahead is building a data foundation that can be governed at the speed of AI.</p><h3>Where do CISOs go from here?</h3><p>This is one finding from a larger pattern. The <a href="https://mind.io/registration/[object Object]">{children}</a> walks through all seven insights, with direct CISO quotes and a clear set of recommendations for security leaders trying to govern AI without slowing their business down.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to see how high-performing teams are designing data security for actors that don&#x27;t behave like humans.</p><h5><em>Data Trust + AI Success Blog Series</em></h5><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Why AI doesn’t behave like a human</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/why-ai-doesnt-behave-like-a-human</link>
            <guid isPermaLink="true">https://mind.io/blog/why-ai-doesnt-behave-like-a-human</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/f20f9567a45ba169434085c7e7e8dfd223d6891b-4104x2736.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The LexisNexis breach: a wake-up call for cloud data security]]></title>
            <description><![CDATA[<h2>The company that indexes the world's legal information couldn't index its own AWS environment. Here's what every security team should take from it.</h2><h3>The breach in one read</h3><p>On March 3, 2026, LexisNexis Legal &amp; Professional confirmed what the threat actor FulcrumSec had been claiming for days: attackers had walked out of its AWS environment with around 2.04 GB of structured data, including 53 plaintext secrets, 45 employee password hashes and the profiles of roughly 400,000 cloud users. Among them, 118 had .gov email addresses. Federal judges. DOJ attorneys. SEC staff. Probation officers. Federal court law clerks (<a href="https://www.rescana.com/post/lexisnexis-aws-data-breach-2026-react2shell-exploit-exposes-legacy-data-in-cloud-hack/">Rescana</a>, <a href="https://cybernews.com/security/lexisnexis-breach-400k-users-gov-accounts-aws/">Cybernews</a>).</p><p>For a company whose product is indexing other people&#x27;s information, this one stings differently.</p><h3>What actually happened inside LexisNexis's AWS environment?</h3><p>The attack chain was short and unspectacular, which is the part that should sit with you.</p><p>The attackers used React2Shell (CVE-2025-55182), a critical vulnerability that CISA had added to its Known Exploited Vulnerabilities catalog on December 5, 2025, with a one-week patch deadline. LexisNexis hadn&#x27;t applied the patch more than two months later (<a href="https://www.idstrong.com/sentinel/lexisnexis-data-breach/">IDStrong</a>).</p><p>Once inside an unpatched frontend, the attackers landed on an ECS task with a role that had read access to every secret in the AWS account. From there, the playbook ran itself: enumerate AWS Secrets Manager, pull 53 plaintext credentials, pivot to Redshift, walk 536 tables (<a href="https://www.rescana.com/post/lexisnexis-aws-data-breach-2026-react2shell-exploit-exposes-legacy-data-in-cloud-hack/">Rescana</a>). No exotic tooling. No zero-day. Just one unpatched app and one over-permissive role.</p><p>FulcrumSec went on to mock LexisNexis publicly for reusing the password “Lexis1234” five times across internal systems (<a href="https://www.thebreach.news/posts/lexisnexis-fulcrumsec-breach-2026">The Breach</a>).</p><h3>Why does this breach matter beyond LexisNexis?</h3><p>Because the conditions that made it possible are not unique to LexisNexis. They are the modal state of most large cloud environments.</p><p>Known CVEs that don&#x27;t get patched in time. Roles created in a hurry that quietly accumulate permissions nobody can fully describe. Secrets that were supposed to live in a vault but ended up plaintext in a config, an S3 bucket or a forgotten Redshift column. Legacy data from before 2020 that nobody owns and nobody remembered to remove.</p><p>The damage in this case was carried by the secrets, not the exploit. The React vulnerability got the attackers a foothold. The plaintext credentials and the over-permissive role gave them the entire environment.</p><p>That&#x27;s the real story of most modern breaches. The initial access is rarely the interesting part. What sits behind it is.</p><h3>How do you stop the same thing happening to you?</h3><p>Patching matters. Identity hygiene matters. But the deeper question is the one most security teams can&#x27;t confidently answer: where is our sensitive data, including the things that look like credentials and the things that look like forgotten exports, actually sitting right now?</p><p>If you can&#x27;t answer that with precision, your incident response plan is partly fiction. Every plaintext API key checked into a config, every database export sitting in an old S3 bucket, every dump of customer records nobody remembered to delete is a piece of your blast radius that you&#x27;ve already handed to the attacker, before they even arrive.</p><p>It doesn&#x27;t have to be this way. The work isn&#x27;t to bolt on another scanner. The work is to know your data the way a thoughtful person would know their own house.</p><h3>How does MIND help security teams mind what matters?</h3><p>MIND is a context-aware data security platform built around a simple discipline: see your data clearly, in motion and at rest, then apply the right control at the right moment.</p><p>We continuously discover and classify sensitive data across your environment. That includes the data nobody remembers anymore: legacy customer exports, forgotten cloud storage, support tickets full of contact details, internal documents drifting between SaaS apps. The data that breaches like this one quietly turn into 400,000-user leak sites.</p><p>We give security teams a real map of where sensitive data lives, who can reach it and where it&#x27;s drifting into places it shouldn&#x27;t be. That&#x27;s the difference between knowing your blast radius and guessing at it. MIND isn&#x27;t just processing alerts. It&#x27;s minding the integrity of your data perimeter, so when the next React2Shell lands in your environment, what sits behind that foothold isn&#x27;t a worst-case scenario you only learn about from the threat actor&#x27;s leak site.</p><p>The LexisNexis breach didn&#x27;t require a clever adversary. It required time, an unpatched app and a cloud environment that didn&#x27;t know itself. The first two are familiar problems. The third is the one worth fixing.</p><h3>See what your data actually looks like</h3><p>If you want to know what FulcrumSec would have found in your environment, MIND will show you. Connect your environment and we&#x27;ll surface where your sensitive data is sitting today and what your blast radius would look like if someone walked in tomorrow. Let&#x27;s mind what matters.</p>]]></description>
            <link>https://mind.io/blog/lexisnexis-breach-wake-up-call-cloud-data-security</link>
            <guid isPermaLink="true">https://mind.io/blog/lexisnexis-breach-wake-up-call-cloud-data-security</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ed22a806f0303d1e96fc47ce98acf7b4192c7b52-1096x720.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Canvas, ShinyHunters and the case for least privilege in SaaS]]></title>
            <description><![CDATA[<h2>When the front door is intact and the foundation gives way, the lesson stops being about phishing.</h2><p>Schools are <a href="https://www.npr.org/2026/05/08/nx-s1-5815956/canvas-data-breach-school-finals">pulling Canvas offline as finals week begins</a>. Not because of a phishing campaign. Not because someone clicked a bad link. Because ShinyHunters found a way through the <a href="https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/">’Free-For-Teacher’ tier of Instructure&#x27;s production infrastructure</a> and used it to reach data that should have been nowhere near it. The result, <a href="https://www.malwarebytes.com/blog/news/2026/05/millions-of-students-personal-data-stolen-in-major-education-cyberattack">according to ShinyHunters&#x27; own claims</a>, is 3.65 terabytes of data and around 275 million records pulled from nearly 9,000 institutions, including <a href="https://dukechronicle.com/article/duke-university-among-institutions-affected-by-canvas-cyberattack-shinyhunters-instructure-hack-data-leak-cybersecurity-20260507">Duke</a>, <a href="https://www.thedp.com/article/2026/05/penn-canvas-shinythunters-data-breach-hack-second">Penn</a> and <a href="https://www.thecrimson.com/article/2026/5/8/canvas-breach-down/">Harvard</a>.</p><p>This breach reads differently from almost everything else ShinyHunters has done in the last twelve months. It should change how security teams think about multi-tenant SaaS risk.</p><h3>Why is this Canvas breach different from typical ShinyHunters attacks?</h3><p>Most of the headline ShinyHunters campaigns in 2024 and 2025 leaned on social engineering: OAuth abuse, voice-phished session tokens, stolen credentials from Snowflake and Salesloft customers. All of them worked because identity was the soft target.</p><p>The Canvas incident appears to be something else. Early reporting from <a href="https://www.rescana.com/post/shinyhunters-launches-second-major-attack-on-instructure-canvas-lms-via-free-for-teacher-accounts-may-2026-breach-analys/">Rescana</a>, <a href="https://businessinsights.bitdefender.com/technical-advisory-shinyhunters-breach-instructure-canvas-lms">Bitdefender</a> and others points to an exploitation of the Free-For-Teacher account program, a low-friction signup tier that <a href="https://en.wikipedia.org/wiki/2026_Canvas_security_incident">ran on the same production Canvas infrastructure as paid enterprise tenants</a>. Instructure hasn&#x27;t published a technical postmortem yet, but the early picture is consistent: this was a platform-level entry point, not a phished employee. That makes it one of the rare ShinyHunters breaches where the attacker didn&#x27;t need to fool anyone. They just needed an architectural seam.</p><p>That distinction matters. Phishing breaches are stories about people. This one is a story about trust boundaries that weren&#x27;t drawn correctly in the first place.</p><h3>What does the blast radius say about lateral movement?</h3><p>The scope is staggering. <a href="https://hackread.com/shinyhunters-instructure-canvas-lms-vimeo-data-breach/">Names, email addresses, student IDs and private student-teacher messages were exposed</a>. Reporting suggests source code and internal records were in scope too. When a single foothold reaches code, records and message history across thousands of tenants, the isolation model itself has failed. Containment was never on the table.</p><p>The principle CISOs already know is the one being underlined here. Least privilege isn&#x27;t a checklist item. It&#x27;s a blast-radius calculator. The smaller the trust each identity, service or tenant carries, the fewer escalation paths an intruder finds when they&#x27;re already inside. The lateral movement through Canvas looks wide and sweeping for exactly the opposite reason: the privilege model assumed too much.</p><h3>What should institutions worry about after Canvas comes back online?</h3><p>Restoration won&#x27;t close this out. Recovery is a separate problem with its own clock.</p><p>Two things deserve disproportionate attention in recovery. First, the risk of bombs left behind. An attacker who held this level of access for a week likely planted persistence: dormant accounts, modified course content, altered grades, injected scripts or seeded backdoors that survive a patch cycle. Schools that <a href="https://www.infosecurity-magazine.com/news/shinyhunters-escalates-canvas/">flip Canvas back on without forensic review</a> are inheriting whatever the attacker left.</p><p>Second, data integrity. Confidentiality is the headline loss. Integrity is the quieter one. Did anyone modify records, transcripts or assignment data while they had the run of the platform? At the end of a term, that matters in ways that ripple for years.</p><p>And it goes without saying that Canvas should resolve the open issues that allowed a ‘free’ account to run on the same underlying infrastructure as the ‘enterprise’ tier and that more robust controls exist between tenants.</p><h3>How does this change the way security teams think about SaaS?</h3><p>For CISOs, the takeaway from the ShinyHunters Canvas breach is more uncomfortable than &quot;audit your Canvas tenant.&quot; Every SaaS platform you depend on has a free tier, a partner integration, a developer sandbox or a low-friction account type that runs on shared infrastructure with your production data. Each one is a candidate for the same failure mode.</p><p>The defense is foresight. Know where your sensitive data lives across SaaS and which identities and services can reach it. Watch what moves, when it moves and in what context. Perimeter thinking won&#x27;t cover this. The exposure now sits in the data layer.</p><p>This is where MIND comes in. We aren&#x27;t just classifying files or counting matches. We&#x27;re minding the data itself: where it sits, how it moves between SaaS apps and which context around a movement should make a security team pay attention. When the platform you trust breaks its own isolation model, the signal worth seeing lives in the data path, not at the login page.</p><p>If your institution is rebuilding from this breach or preparing for the next one, start with the question Canvas is answering the hard way: do you actually know what data was reachable and from where? See how MIND surfaces that picture in your own environment.</p><p><strong>Let&#x27;s mind what matters.</strong></p>]]></description>
            <link>https://mind.io/blog/canvas-shinyhunters-least-privilege-saas</link>
            <guid isPermaLink="true">https://mind.io/blog/canvas-shinyhunters-least-privilege-saas</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/01cade3a053d5d03d3e33ceb4206818ba6733a53-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Security by obscurity just died. AI killed it.]]></title>
            <description><![CDATA[<h2>Before AI, poor data governance used to be survivable.</h2><p><em>This is Blog 2 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Security by obscurity just died. AI killed it.</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>For years, you could get away with poor data governance. Files sat unclassified in SharePoint. Repositories got overshared. Data estates sprawled ungoverned. And nothing bad happened.</p><p>Why? Because no system went looking for everything. The unclassified files stayed hidden. The overshared repos went unnoticed. Years of accumulated data debt remained invisible behind a protective shield of obscurity.</p><p>AI just ripped that shield away.</p><h3>What was actually protecting you all this time?</h3><p>Security by obscurity kept you safe when your data catalog had gaps. If no tool could see all the data at once, the consequences of poor classification were limited. A human might stumble across something they shouldn&#x27;t see, but they couldn&#x27;t systematically surface every sensitive file across the entire estate.</p><p>AI eliminates that backstop entirely. The moment an AI tool connects to a data source, it finds everything at scale, without direction, without judgment, without the natural filters a human would apply.</p><p>According to our research with CISO ExecNet:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/46be65e500f05c6e3341cb64e149943d61a5a99f-1224x236.png?w=500" /><img src="https://cdn.sanity.io/images/3l9nidp2/production/3830cc78015db87d0fb3e464b9a32b3ec4b90829-1088x224.png?w=500" /><h3>What does this look like in practice?</h3><p>AI exposes years of data debt the moment it connects. Here&#x27;s what that means for real organizations.</p><p>At a large healthcare organization, three AI projects stalled during the pilot phase. In each case, the stated reason was incomplete data, inconsistent formatting and missing source lineage. The AI didn&#x27;t create these problems. It exposed them.</p><p>At a manufacturing company, executive compensation files had been stored in SharePoint for years with no classification or access controls. When an Enterprise AI tool was deployed, those files were suddenly broadly accessible to a wide internal audience. Nobody intended for this to happen, but the AI found what was there.</p><h3>Why can't you just fix this in a sprint?</h3><p>This isn&#x27;t a technical problem you can sprint away from. Years of accumulated data sprawl can&#x27;t be resolved in a single sprint. But the urgency is real.</p><p>Every day an AI tool operates against an unclassified, ungoverned data estate, it&#x27;s surfacing exposure that no one can see and no one is managing. And with 90% of enterprises now running Enterprise GenAI at scale, that exposure is multiplying faster than governance teams can respond.</p><h3>What does this mean for your organization?</h3><p>This isn&#x27;t about whether your organization will adopt AI. The data clearly shows you already have. The question is whether the foundation beneath it can be trusted.</p><p>The security by obscurity that protected organizations from their own data debt for years is gone. AI made everything visible. Now every unclassified file, every overshared repository, every piece of ungoverned data is accessible at machine speed to systems that don&#x27;t apply human judgment about what they should or shouldn&#x27;t surface.</p><h3>Where do you start?</h3><p>The winners in the AI era treat data trust as a prerequisite, not an afterthought. They&#x27;re investing in:</p><ul><li><strong>Comprehensive data classification.</strong> You can&#x27;t enforce policy on data you haven&#x27;t classified.</li><li><strong>Data discovery at scale.</strong> Building a complete inventory of what data exists and where it lives.</li><li><strong>Governance that covers AI.</strong> Extending existing frameworks to include non-human actors.</li><li><strong>Visibility into data flows.</strong> Understanding what data AI tools can actually access.</li></ul><img src="https://cdn.sanity.io/images/3l9nidp2/production/88fda5e213a09cfbe96d1124e8b3450667784169-1088x274.png?w=500" /><h3>The bottom line</h3><p>Security by obscurity is dead. AI killed it.</p><p>Now the question facing every organization is, <strong><em>“Will you build the data trust foundation that allows you to move fast with AI?”</em></strong> Or will you continue carrying years of data debt into an environment that makes every single piece of it visible?</p><p>The organizations making that investment now are building the only foundation that lets them adopt AI at scale with any real confidence. <a href="https://mind.io/content/[object Object]">{children}</a></p><h5><em>Data Trust + AI Success Blog Series</em></h5><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>Security by obscurity just died. AI killed it.</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/security-by-obscurity-just-died-ai-killed-it</link>
            <guid isPermaLink="true">https://mind.io/blog/security-by-obscurity-just-died-ai-killed-it</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/6342a9c450ecdd89f3b3faf44c398c421fa427e6-5184x3456.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why seeing AI risk isn't enough to protect you from it]]></title>
            <description><![CDATA[<h2>Visibility into AI risk is everywhere. Real time enforcement still isn't.</h2><p><em>This is Blog 1 in our <strong>Data Trust + AI Success</strong> Series</em></p><ol><li><strong><em>Why seeing AI risk isn’t enough to protect you from it</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>Most security teams know where AI is showing up. They&#x27;ve inventoried the tools and written acceptable-use policies. That&#x27;s real progress. It&#x27;s also given a lot of teams a false sense of control.</p><p>In MIND&#x27;s research, <a href="https://mind.io/content/[object Object]">{children}</a>, one insight kept surfacing across CISO interviews: there&#x27;s a consistent gap between visibility and enforcement. Teams know what&#x27;s happening. They can&#x27;t reliably control it at the moment it matters.</p><p><strong>What matters:</strong> Organizations can see AI risk. They can&#x27;t enforce policy at AI speed.</p><h3>Where does AI enforcement actually break down?</h3><p>The issue isn&#x27;t awareness. Security teams have already invested in governance, policy design and visibility across GenAI tools and agents. Most know what good looks like. </p><p>What breaks is execution. The real-time mechanisms to apply those rules don&#x27;t exist in most environments. As one CISO in our <a href="https://mind.io/content/[object Object]">{children}</a> put it, their team could clearly define acceptable AI use, but struggled to enforce those rules once real interactions began. </p><p>With good policies defined, the question becomes whether it can actually run at the speed AI moves.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/c2bfbfb336fc791f98ec56808e162d1a81e4989a-2448x432.png?w=500" /><h3>Why do traditional security controls fall short for AI?</h3><p>Most security controls were built for checkpoints. A user logs in, opens a file or makes a request. A control evaluates the action. There&#x27;s a clean moment to step in. </p><p>AI removes those moments. Once connected, it accesses and transforms data continuously. Decisions happen inside the flow, not at the edge. </p><p>The implication is uncomfortable. Data can be summarized, combined or exposed before any control has a chance to act. Visibility shows you what happened. It doesn&#x27;t stop it from happening.</p><h3>Can human-driven enforcement keep up with AI?</h3><p>When technology systems can&#x27;t enforce policy, people and process are asked to fill the gap. Training increases. Guidelines expand. Teams rely on users to make the right call in the moment. </p><p>That model struggles with AI. Interactions are faster, context is less visible and downstream impact is harder to spot. Even well-intentioned users can&#x27;t consistently apply policy they can&#x27;t see. </p><p>Several CISOs in the <a href="https://mind.io/content/[object Object]">{children}</a> called this &quot;policy by hope.&quot; It works until it doesn&#x27;t, and at AI speed, failure happens fast.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/9763a8cb9ef0fa926fed49dbe77cebbe2cc56e85-2176x556.png?w=500" /><h3>How often does this enforcement gap actually hit?</h3><p>This isn&#x27;t an edge case. According to MIND&#x27;s research report, <a href="https://mind.io/events/[object Object]">{children}</a>, 70% of organizations report difficulty enforcing policies on GenAI tools. That&#x27;s a broad operational reality, not a niche concern. </p><p>As AI becomes part of daily workflows, the gap moves from theoretical to constant. Data gets accessed more often, across more systems, without clear control points. Investigating incidents after the fact becomes a pattern many companies live with. </p><p>Security teams can explain what happened. What they can&#x27;t do is consistently prevent it in real time.</p><h3>What does data security at AI speed actually require?</h3><p>Closing this gap takes a different approach to enforcement. Access controls aren&#x27;t enough anymore. You have to govern data the moment it&#x27;s used, not after. </p><p>Enforcement has to run continuously and in context, without waiting for a human to decide. It has to operate at the speed of the systems it&#x27;s governing. </p><p>This is where MIND focuses. Stress-Free DLP doesn&#x27;t add more policy. It makes the policy you already have enforceable in real time, across endpoints, SaaS and AI. We aren&#x27;t just stopping violations. We&#x27;re minding the moments where AI quietly turns visibility into exposure, so your team can act on what matters and ignore what doesn&#x27;t.</p><h3>How are CISOs closing the AI enforcement gap today?</h3><p>This is one finding from a larger pattern in the research. CISOs aren&#x27;t questioning whether AI gets adopted. They&#x27;re trying to control it without slowing the business down. </p><p>The <a href="https://mind.io/events/[object Object]">{children}</a>: where enforcement is breaking inside real environments, which controls are actually holding up in production today and how high-performing teams are closing the gap. It includes direct quotes from CISOs and the specific approaches they&#x27;ve put in place. </p><p><a href="https://mind.io/content/[object Object]">{children}</a> to see what&#x27;s working, what isn&#x27;t and where to invest first.</p><h5><em>Data Trust + AI Success Blog Series</em></h5><ol><li><strong><em>Why seeing AI risk isn’t enough to protect you from it</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/why-seeing-ai-risk-isnt-enough-to-protect-you-from-it</link>
            <guid isPermaLink="true">https://mind.io/blog/why-seeing-ai-risk-isnt-enough-to-protect-you-from-it</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 29 Apr 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/d6d809b604b6a6a77a3893046415954a214304cd-5472x3648.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The Facebook ID problem breaking your DLP alerts]]></title>
            <description><![CDATA[<h2>How we reverse-engineered the structure of Facebook IDs to improve credit card classification.</h2><p><em>Classification Blog Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>The Facebook ID problem breaking your DLP alerts</em></strong></li></ol><p>The concept behind data loss prevention (DLP) platforms is simple and powerful: Discover and classify sensitive data then apply policies to prevent that data from leaving the safe perimeter. For example, financial institutions often define policies to prevent credit card information from leaking outside of the organization while inside of unstructured documents (emails, documents, messages, etc).</p><p>In the past, volume and complexity of data organizations managed was low enough that simple pattern matching rules were sufficient to implement this guardrail. A single DLP administrator could define a policy that considers every 14-16-digit number a credit card. Even today, Conventional DLP platforms still primarily offer thousands of policies just like this, as their primary means of identifying sensitive data.</p><p>Technology and organizational changes in recent years (cloud migration, zero trust, work from home and AI) have accelerated data sharing and created a new reality where the amount of data organizations are managing and being required to protect is growing exponentially. The same policy that once yielded 1-2 alerts per day can yield millions of alerts today. This leads to alert fatigue and the historical “DLP fatigue” that security teams have struggled with for years.</p><p>With the rapid evolution of Generative AI in today’s technology ecosystem, one might ask: </p><p><strong>&quot;Why not just send the document to an LLM and ask if it contains credit cards?&quot;</strong></p><p>The answer to this question is more complex. LLMs are remarkably good at understanding context, and in a one-off scenario, an LLM could likely look at a spreadsheet full of Facebook IDs and tell you &quot;these are ad campaign identifiers, not credit cards.&quot; But in practice, this approach simply doesn&#x27;t work for DLP at scale, and there’s a few reasons why:</p><ul><li><strong>Volume.</strong> A large enterprise generates millions of documents and messages per day. Sending each one to an LLM for classification is prohibitively expensive and slow. DLP classification needs to run in real time, on every file, at a fraction of a cent per document. Otherwise user workflows are impacted or, even worse, data exfiltration events are missed entirely.</li><li><strong>Privacy.</strong> The foundational purpose of a Data Loss Prevention program is to prevent sensitive data from leaving a controlled perimeter or custody. Sending potentially sensitive documents to an external AI service to check whether they&#x27;re sensitive is counter-productive to the goals of the security and governance teams in charge of protecting this data.</li><li><strong>Determinism.</strong> While an LLM may be able to correctly determine data types in controlled cases, targeted, bespoke techniques solve this problem reliably, cheaper and with more confidence. Algorithmic detections are reproducible, explainable and don&#x27;t carry the inherent variance of generative models.</li></ul><p>LLMs absolutely have a role in MIND&#x27;s detection pipeline, but as one layer among many. These layers are applied selectively where contextual understanding adds value that algorithms alone can&#x27;t provide. For high-volume, structural problems. like the one we&#x27;re about to discuss, a targeted algorithm is faster, cheaper and more reliable.</p><p>MIND&#x27;s approach to detecting sensitive information reflects this philosophy. Instead of relying on any single technique, we built a layered approach that combines pattern matching, statistical algorithms, ML and LLMs. Each of these techniques are applied when and where they’re most effective.</p><h3>How to perform a Luhn check</h3><p>If you’ve spent any amount of time in the data security space, you’ve probably heard of the “Luhn Check”. The <a href="https://en.wikipedia.org/wiki/Luhn_algorithm">Luhn algorithm</a> is a checksum formula embedded in credit card numbers that helps merchant vendors (think Point-of-Sale terminals) quickly validate whether a number is a plausible credit card. The last digit of a credit card is the check digit, and we can verify a credit card number by calculating the Luhn checksum over all digits, then comparing the result to the check digit.</p><p>For example, here&#x27;s how a Luhn check works on this machine generated credit card number </p><p><strong>4539 1488 0343 6467</strong></p><img src="https://cdn.sanity.io/images/3l9nidp2/production/f21cb35801ced2d430878273b93c721fa9318cc8-3600x2464.png?w=500" /><p>While some DLP vendors utilize Luhn validation to significantly reduce false positives in credit card detection, we were surprised to learn that others do not. The challenge is, even <strong>with </strong>proper use of a Luhn check, the check digit is a single digit with values 0-9, meaning there is still a <strong>~10% chance</strong> that a random 16-digit number will pass the Luhn check by coincidence and produce a false positive.</p><p>The challenge compounds even further when combined with other data structures that resemble a credit card number and have a high probability of passing a Luhn check by design, as we’ll discuss below.</p><h3>Why Facebook IDs are often false positives</h3><p>Through developing this classification pipeline and onboarding customers over the past year, we began hearing reports from a select few of our customers about false-positives in their credit card and PCI-focused policies. This initiated an unexpectedly thorough investigation from the data science team at MIND.</p><p>The start of our investigation was aimed at evaluating ML and context-word approaches to filter out the examples our customers had given. However, this proved unreliable. And even more challenging, the same examples provided by our customers often contained words like &quot;credit,&quot; &quot;price&quot; and other financial terminology, making it hard to distinguish at scale by context alone.</p><p>After some time, we noticed a common pattern: these customers were running advertising campaigns on Facebook and storing Facebook IDs to track campaign progress. This seemed innocent on the surface.</p><p>After much investigation, the commonality between our customers running Facebook advertising and those running into the same suspect false positives was too much for our data science team to ignore.</p><h3>Initial data gathering</h3><p>To properly start our investigation, we needed a large sample of Facebook IDs. Luckily, Facebook provides an <a href="https://www.facebook.com/ads/library/api/">Ad Library API</a>, which is a public transparency tool that lets anyone query metadata about ads running on the platform. Through this tool, we were able to verify that each and every ad and advertiser page had a unique numeric Facebook ID.</p><p>We used this API to find advertisers with large numbers of active ads, then collected all ad IDs from a single large advertiser. This gave us a dataset of IDs from the same origin, similar to what our customers had in their campaign reports. By paginating through the API results, we were able to gather a large dataset of IDs.</p><p>Examining these Facebook ID’s visually, it was pretty clear that there is a common digit structure when compared to credit card numbers. Here&#x27;s an example of what a Facebook ID looks like from that dataset:</p><p><strong>5842543952487337</strong></p><p>At a glance, it&#x27;s easy to see why a traditional DLP engine might flag this as a credit card. These Facebook IDs are a 16-digit number that could plausibly pass a Luhn check in good numbers, especially considering the volume of IDs each Facebook campaign was generating.</p><p>Once we had enough samples, we started testing hypotheses and running experiments to understand how Facebook IDs are structured.</p><p><br/></p><h3>Reverse engineering the Facebook ID format</h3><p>To fully test whether or not Facebook IDs could reliably contribute to credit card number false positives, we had to dive into the lower and upper limits of what that ID structure could be.</p><h5><strong>Understanding the Format</strong></h5><p>Commonly, IDs serve as a key to uniquely identify and fetch an object from a database. Modern database keys follow common patterns: they have varying levels of randomness built in (for <a href="https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/">BOLA</a> protection and security purposes), but may also follow structural patterns to allow faster indexing and generation (for example, <a href="https://www.ietf.org/rfc/rfc9562.html#name-uuid-version-7">UUID v7</a>).</p><p>Looking at our sample, we could see that Facebook IDs are 10-20 digit numbers, known as a bigint data type, which is a common format for MySQL and SQL-like database keys.</p><h5><strong>Testing Structural Randomness</strong></h5><p>If Facebook IDs were randomly generated, we can expect ~10% to pass the Luhn check. With this hypothesis in mind, we decided to run our entire sample set through a Luhn check. Shocked, but not surprised, we found that <strong>~13% of our Facebook ID dataset passed the Luhn check</strong>. Even more important was this deviation from the expected 10% is statistically significant and tells us something important: <strong>Facebook IDs are not randomly generated.</strong> In fact, their predetermined internal structure creates a bias in the digit distribution.</p><h5><strong>Testing Arithmetic Sequence</strong></h5><p>Now knowing that these IDs are not generated randomly, we were now focused on determining what predictability existed in the sequence of the IDs.</p><p>Looking at the data more carefully, we noticed some patterns:</p><ul><li>The leading digits don&#x27;t change often.</li><li>Some digit values appear more frequently than others.</li><li>The IDs are numerically close to each other.</li></ul><p>These patterns are characteristic of arithmetic sequences, such as:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/5a1bd9af4cff742b431bc1b1173cc3e7eae81b63-3600x604.png?w=500" /><p>Which can be made to generate numbers at scale with a pre-defined formula similar to:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/cab9cbf62d02994c46f46752439d4a6b969d69ff-3600x1120.png?w=500" /><p>where a is the starting value and d is the common difference.</p><p>To test this, we sorted the IDs and computed the differences between consecutive values:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/19778f9523c6331995f12d5b58bdaa686bdb296e-3600x1780.png?w=500" /><p>The differences were remarkably consistent: not always identical, but always exact multiples of a common value.</p><h3>Finding the common difference with GCD</h3><p>To find the exact step size within the sequence, we computed the <a href="https://en.wikipedia.org/wiki/Greatest_common_divisor">Greatest Common Divisor (GCD)</a> of the differences between consecutive sorted IDs. The GCD converged to:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/964e1aa9e2a122e45806c63d7eab703777bc54c4-3600x620.png?w=500" /><p>As a data science team, this was our breakthrough. This proved that Facebook IDs aren&#x27;t random, but instead they follow a pattern with a fixed step of <strong>3,333,333</strong>.</p><p>Digging further, we found confirmation in Facebook&#x27;s own code. An <a href="https://github.com/facebookarchive/connect-js/blob/30e7e779621d3d29660f20ac8e47ff4bd7fa81b8/src/xfbml/helper.js#L37">archived version of Facebook&#x27;s JavaScript SDK</a> contains this line for validating 64-bit user IDs:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/7333a76770513f645514cf2b41d1d188b5e22bf4-3600x604.png?w=500" /><p>The number 3,333,333 appears explicitly as an internal constant in Facebook&#x27;s ID range calculation, confirming that our reverse-engineered value is not a coincidence.</p><h3>The shard model</h3><p>The number 3,333,333 immediately suggests a <a href="https://en.wikipedia.org/wiki/Shard_(database_architecture)"><strong>database sharding scheme</strong></a>. In distributed databases, a common pattern formula for generating unique IDs across multiple shards without coordination is:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/761341b92f1e2f80e78dd6671e43e67a840235f3-3600x1164.png?w=500" /><p>Further, this would reflect:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/db99d7123d8ba544ab264eb0a4b09d9ff98baae0-3600x620.png?w=500" /><p>If we apply this to the same IDs from our earlier example, we see our proof:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/754cb3129afda8fdeb98a41ad9ae983364922c82-3600x1480.png?w=500" /><p>Every ID maps to the same shard: <strong>75,124</strong>. They all share the same residue because they are all part of the same arithmetic sequence with a step of 3,333,333.</p><p>With 3,333,333 shards, each shard is assigned an offset k (where 0 ≤ k &lt; 3,333,333). When a shard needs a new ID, it takes its last ID and adds 3,333,333, stepping over all other shards. This way, every shard generates IDs independently without risk of collision, and all IDs belonging to the same shard share the same residue modulo 3,333,333.</p><p>So the Facebook ID format can be described as:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/990e3ed66ba2e7bbe21e70370058425bc22fcd51-3600x1000.png?w=500" /><p>where k is the shard-specific offset, and n is the sequence number within that shard.</p><p>This explains:</p><ul><li><strong>Why the IDs form an arithmetic sequence</strong>: they are generated within a single shard.</li><li><strong>Why the Luhn pass rate is ~13% instead of ~10%</strong>: the structured digit patterns create a non-uniform distribution that biases the checksum.</li><li><strong>Why customer reports cluster</strong>: campaign-related entities (ads, audiences, etc.) likely live on the same shard.</li></ul><p><strong>A note on the data:</strong> This clean result depends on the sample being dominated by IDs from the same shard. In our case, the data came from a single advertising campaign, so the IDs naturally belonged to the same shard. If the sample had contained IDs from many different shards, the GCD of consecutive differences would have been much smaller (potentially 1), and this step would have required additional filtering to isolate per-shard sequences.</p><h3>Detecting Facebook IDs with a Chi-Square test</h3><p><strong>Detecting Facebook IDs with a Chi-Square Test</strong></p><p>After our investigation and being able to prove the structural consistency of Facebook IDs, we took the opportunity to add another layer to our classification engine. The key insight is:</p><ul><li><strong>Facebook IDs:</strong> When you compute ID % 3,333,333, all IDs from the same shard map to the <strong>same value</strong> (or a small number of values). The distribution across bins is highly non-uniform.</li><li><strong>Real credit card numbers:</strong> When you compute number % 3,333,333, the results are distributed <strong>roughly uniformly</strong> because credit card numbers have no relationship to this modulus.</li></ul><p>To do this at scale and efficiently, we use a <a href="https://en.wikipedia.org/wiki/Chi-squared_test">Chi-Square goodness-of-fit test</a> to distinguish between these two cases. The test compares an observed frequency distribution against an expected distribution (in our case, uniform) and tells us whether the difference is statistically significant.</p><p>Here&#x27;s the detection approach in pseudocode:</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/83c14144fc087f2774b2455eda0010279baa1cad-3600x2260.png?w=500" /><h5><strong>How it works step by step:</strong></h5><ol><li><strong>Compute the shard ID</strong> for each number: shard = number % 3,333,333.</li><li><strong>Count occurrences per shard</strong>: Facebook IDs will cluster into very few shards, while credit card numbers will spread across many.</li><li><strong>Build the expected distribution</strong>: if these were random numbers (like credit cards), each observed shard would have roughly the same count (uniform).</li><li><strong>Run the Chi-Square test</strong>: if the observed distribution is significantly different from uniform (p-value &lt; 0.005), these are Facebook IDs, not credit cards.</li></ol><p>As a single layer, this approach is lightweight and self-contained. It requires <strong>no hardcoded ID ranges</strong>, <strong>no ML model</strong> and <strong>no context analysis</strong>. It&#x27;s a pure<strong> statistical test</strong> that exploits the fundamental structure of how Facebook generates IDs. In our classification engine, this sits alongside many other layers (Luhn validation, BIN range checks, context word analysis, ML models, LLM-based classification and more) each catching what the others miss. Even if Facebook&#x27;s ID space shifts over time, the sharding structure remains, making this particular layer robust and future-proof.</p><h3>Results</h3><p>After deploying this detection layer, we eliminated an entire class of false positives for our customers running Facebook advertising campaigns, without any risk of suppressing real credit card alerts. The Chi-Square test cleanly separates the two populations because the underlying data generation processes are fundamentally different: one is structured (sharded database keys), the other is pseudo-random (credit card numbers with a Luhn checksum).</p><p>This is just one example of one layer in MIND&#x27;s classification engine, an approach that goes beyond simple pattern matching. Our pipeline includes dozens of such layers, from statistical tests like this one, through ML models, to LLM-based analysis. Each addresses a different class of false positives or detection gaps. By understanding the structure of the data and having an extensible multi-layer classification engine, rather than relying on any single technique, we can continuously improve accuracy without sacrificing coverage. This means our customers can trust that MIND’s DLP policies will prevent real risk, not negatively impact business.</p><h3>See MIND for yourself</h3><p>To see a full demo of the MIND platform, including our advanced multi-layer classification engine, get a <a href="https://mind.io/[object Object]">{children}</a>.</p>]]></description>
            <link>https://mind.io/blog/the-facebook-id-problem-breaking-your-dlp-alerts</link>
            <guid isPermaLink="true">https://mind.io/blog/the-facebook-id-problem-breaking-your-dlp-alerts</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Tue, 28 Apr 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/98191fdf0b5619ff4944a5a4827b0e458aec5869-1920x1080.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Data trust is the hidden reason most AI initiatives fail]]></title>
            <description><![CDATA[<h3>Ready, Fire, AI.</h3><p>Ninety percent of enterprises are already running Enterprise GenAI at scale. That number comes from new research conducted by MIND in partnership with <a href="https://cisoexecnet.com">CISO ExecNet</a>, and it should give every security leader pause. Not because AI adoption is surprising. But because of what sits directly beneath it.</p><p>Although 90% of organizations are deploying Enterprise GenAI at scale, only 34% of CISOs describe themselves as reasonably confident in their AI data security controls. As a result, only 1 in 5 of those AI initiatives are meeting their intended KPIs. </p><p>The adoption curve and the confidence curve are moving in opposite directions. That gap is what this research was built to examine.</p><h3>Why does AI adoption expose what poor data governance was hiding?</h3><p>For years, poor data governance was survivable. Files went unclassified. Repositories stayed ungoverned. Access controls were written for human actors who exercised natural judgment about what they touched and when. None of it surfaced as a crisis because no system was scanning everything at once.</p><p>AI changed that equation entirely. The moment an Enterprise GenAI tool connects to a data source, it finds everything within reach. Unclassified files, overshared repositories and sensitive data that nobody realized was broadly accessible. At one organization, executive compensation files had been sitting in SharePoint for years with no classification or access controls. When an Enterprise AI tool was deployed, those files became broadly accessible to a wide internal audience overnight. Security by obscurity ended the moment AI came online.</p><p>The research puts numbers to this reality. </p><ul><li>70% of security leaders struggle to enforce policies on GenAI tools</li><li>66% cannot enforce policies on AI agents</li><li>And 98% are dealing with at least one significant AI security challenge</li></ul><p>These aren&#x27;t organizations without governance. Boards have been briefed. Policies have been written. Frameworks have been established. But as the research makes clear, governance without technical enforcement is intention without effect. For most organizations, the mechanisms capable of applying those policies against data in motion, at the speed AI demands, simply don&#x27;t exist yet.</p><p>The deeper issue is structural. Every security framework in the enterprise was built with human actors in mind. Humans can be trained, audited and held accountable. Even privileged users exercise judgment about what they access and share. AI agents inherit the same permissions but operate without any of that judgment. They move at machine speed and find everything within reach, not just what&#x27;s relevant. Thirty-two percent of organizations already have unknown agents operating in their environments. The frameworks that were adequate before AI arrived are now being stress-tested at a scale they were never built to handle.</p><figure><blockquote><p>“undefined”</p></blockquote><figcaption><cite>Parrish Gunnels</cite> CISO, MVB Bank</figcaption></figure><h3>What does new research from 124 CISOs reveal about AI success and data trust?</h3><p>MIND and CISO ExecNet set out to understand exactly where data trust is breaking down and what it means for AI success. The study combined a quantitative survey of 124 senior security leaders with 20 qualitative interviews from CISOs at organizations with more than 1,500 employees or over one billion dollars in annual revenue. All participants held VP-level roles or higher. The seven insights that emerged from the convergence of survey data and practitioner experience represent the strongest and most consistent patterns across the entire research project.</p><p>Those insights trace a connected arc. </p><ul><li>The enforcement gap</li><li>The data debt problem</li><li>The structural mismatch between security frameworks designed for human actors and the non-human actors now operating against them</li><li>The measurable cost of AI initiative failure</li><li>The growing difficulty of communicating AI risk to a business that is committed to moving fast</li><li>The competitive advantage that flows to organizations who solve it first.</li></ul><p>The central thesis is that data trust is not a security feature. It is the invisible but decisive ingredient that determines whether AI initiatives succeed or fail. When data trust is high, organizations can use data freely to power AI-driven outcomes. When it isn&#x27;t, AI innovation slows, scales poorly or introduces risk that most organizations can&#x27;t yet see.</p><p>MIND isn&#x27;t just reporting on this gap. We&#x27;re minding the conditions that close it, helping organizations achieve visibility into what data exists, extend governance to non-human actors and build enforcement that operates at AI speed. The organizations that build that foundation now aren&#x27;t just reducing exposure. They&#x27;re building the only infrastructure that allows AI to become a genuine competitive accelerant.</p><figure><blockquote><p>“undefined”</p></blockquote><figcaption><cite>Jacob Combs</cite> CISO, Tandem Diabetes Care</figcaption></figure><h3> How can CISOs close the gap between AI adoption and data security?</h3><p>The full report, <a href="https://mind.io/content/[object Object]">{children}</a>, is available now. It covers the enforcement gap, the data debt problem, why AI agents behave so differently from human users, how AI initiative failure stays invisible and what a minimum viable security foundation actually looks like in practice. It also maps a clear path forward for CISOs who want security to be the function that enables AI adoption, not the one that slows it down.</p><p>If your organization is running AI at scale and the outcomes aren&#x27;t matching the investment, this research was written for you.</p><h5><a href="https://mind.io/content/[object Object]">{children}</a></h5>]]></description>
            <link>https://mind.io/blog/data-trust-is-the-hidden-reason-most-ai-initiatives-fail</link>
            <guid isPermaLink="true">https://mind.io/blog/data-trust-is-the-hidden-reason-most-ai-initiatives-fail</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/7c326b7095bb6d04c440b7ad4aa7bd30db917d8c-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The future of data security: Introducing the Autonomous DLP Analyst]]></title>
            <description><![CDATA[<h2>The scale of modern data environments has outpaced the manual workflows that DLP programs still depend on. Something has to change.</h2><p>Running a Data Loss Prevention program has never been easy. Security teams define policies, tune classifiers, investigate alerts and stitch together signals across dozens of systems. The mission is clear: protect sensitive data. The reality is a constant stream of operational work that pulls analysts away from higher-value security decisions.</p><p>What matters now is simple. Data security teams need a way to operate at the speed of their environments.</p><p>Sensitive data now moves across SaaS platforms, GenAI applications, endpoints, on-premise file shares and emails. At the same time, security teams are expected to protect it all without growing headcount. The gap between the scale of modern data environments and the capacity of security teams continues to widen.</p><p>Running a DLP program is not optional. The challenge is how much manual effort it still demands.</p><p><a href="https://mind.io/newsroom/[object Object]">{children}</a></p><h3>Why is traditional DLP so hard to operate today?</h3><p>Traditional DLP was built for a different era. Early systems relied heavily on pattern matching, static policies and manual review. As environments grew more complex, security teams responded by adding more rules, more policies and more investigation workflows.</p><p>Over time this created an operational burden. Alerts increased. False positives accumulated. Analysts spent more time triaging activity than understanding risk.</p><p>Modern environments simply move faster than manual workflows can keep up with.</p><h3>What does autonomous data security actually mean?</h3><p>This is where the idea of autonomous data security comes in.</p><p>Instead of asking security teams to run every workflow manually, the system can begin taking on parts of that operational work. Classification, investigation and triage become collaborative processes between analysts and intelligent systems. The analyst stays in control, but the heavy lifting starts to shift toward automation.</p><p>Our vision is to revolutionize data security by innovating with simplicity, AI and automation in MIND.</p><p>We believe that programs should scale with the business. Security teams should spend less time managing alerts and more time focusing on real risk.</p><h3>What is the Autonomous DLP Analyst?</h3><p>Today we are taking a meaningful step toward that vision.</p><p>MIND is introducing the Autonomous DLP Analyst, designed to help security teams run their data security programs at AI speed. Rather than requiring analysts to manually execute every step of the workflow, the Autonomous DLP Analyst performs key operational tasks through specialized skills.</p><p>People remain at the center of the process. What changes is how much repetitive work they have to do to get to an answer.</p><p>The first two skills focus on areas where security teams consistently spend the most time: building classifiers and investigating issues.</p><h3>How can security teams automatically classify business-specific data?</h3><p>Every organization has sensitive data that is unique to its business. Intellectual property, internal strategy documents, proprietary code and operational records rarely follow predictable patterns.</p><p>Historically, security teams attempted to identify this data using complex regex rules and static policy logic. Maintaining those rules required constant tuning and often generated large volumes of false positives.</p><p>The Custom Classifier skill changes this workflow.</p><p>Security teams can provide examples of the sensitive data that matters to their organization. The system analyzes those examples and automatically generates classifiers designed to recognize similar information across the environment.</p><p>These classifiers are then deployed into MIND&#x27;s multi-layer AI classification engine, allowing the platform to detect business-specific data across SaaS applications, GenAI tools, endpoints, on-premise file shares and email environments.</p><p>Instead of forcing teams to translate business knowledge into complex rules, the system learns directly from the data itself.</p><h3>How can AI help investigate DLP alerts faster?</h3><p>The second operational bottleneck in most DLP programs is investigation.</p><p>When alerts appear, analysts often need to reconstruct the entire sequence of events. Who accessed the data. Where it moved. How sensitive the information is. Whether the activity represents real risk or normal behavior.</p><p>Gathering that context typically requires pivoting between multiple tools and consoles.</p><p>The Issue Investigator skill streamlines this process.</p><p>Rather than assembling the story manually, analysts receive structured context that highlights the most relevant signals. User activity, file movement and data sensitivity are presented together so the investigation can begin with the right perspective.</p><p>Automation helps here, but the real value is clarity. When context arrives with the alert, security teams can understand what happened much faster and respond with greater confidence.</p><h3>What does the future of autonomous data security look like?</h3><p>These first skills represent the beginning of a broader shift in how data security programs operate.</p><p>Modern environments generate enormous volumes of operational work. Classification tuning, alert analysis, investigation and policy refinement can consume a security team&#x27;s time before they ever reach strategic risk decisions.</p><p>Autonomous data security aims to change that equation.</p><p>The Autonomous DLP Analyst will continue to evolve with additional skills designed to handle more of the workflows that slow security teams down today. Each skill moves another operational task from manual effort to intelligent assistance.</p><p>The goal is to reduce operational friction so security teams can focus on protecting what matters most.</p><h3>Why will autonomous data security define the next generation of DLP?</h3><p>The future of data security will not be defined by more alerts or more rules.</p><p>It will be defined by systems that understand context, reduce manual effort and help security teams move faster than the threats they face.</p><p>The Autonomous DLP Analyst is an important step toward that future. And we are only getting started.</p><p>More skills are already on the way, each designed to make data security programs easier to operate and easier to scale.</p><p>Learn more about it at <a href="https://mind.io/solutions/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/autonomous-dlp-analyst</link>
            <guid isPermaLink="true">https://mind.io/blog/autonomous-dlp-analyst</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/7ae543cff92c053a15ebcbf94d3188f4f5c5d8e5-1801x1080.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[MIND is the first data security company to achieve ISO 42001 certification]]></title>
            <description><![CDATA[<h2>AI is embedded in security tools across the enterprise. MIND is the first data security company to answer how their AI is governed, audited and held accountable.</h2><p>The AI tools built into your security stack are making decisions at a scale no human team can match. They&#x27;re classifying data, scoring risk, triggering enforcement and shaping your program&#x27;s posture without a line of policy being manually written. That&#x27;s the promise of AI-powered security. But it also raises a question most vendors haven&#x27;t been willing to answer: how do you know the AI doing that work is governed responsibly?</p><p>ISO 42001 is the answer the industry has been building toward. <a href="https://www.iso.org/standard/81230.html">Published by the International Organization for Standardization in December 2023</a>, it&#x27;s the world&#x27;s first international standard for AI management systems. It doesn&#x27;t certify a product. It certifies that an organization&#x27;s approach to developing and deploying AI, including the policies, controls, risk assessments and oversight mechanisms in place, meets a globally recognized standard.</p><p><a href="https://mind.io/newsroom/[object Object]">{children}</a></p><h3>What ISO 42001 actually requires</h3><p>This isn&#x27;t a checkbox audit. Certification under ISO 42001 requires an independent third-party assessment across 38 distinct controls organized into nine areas: data governance, model development, operations, security, ethics, accountability, transparency, incident response and continuous improvement. Every AI system MIND deploys has been evaluated for how it handles data quality and lineage, how it approaches adversarial testing, how it responds to incidents and how it maintains transparency with the organizations that rely on it.</p><p>The standard also requires continuous improvement. This isn&#x27;t a milestone you reach and file away. It&#x27;s a framework that evolves alongside the AI itself, with ongoing monitoring, documentation and governance cycles built into how we operate. That&#x27;s a meaningful commitment, and one that most AI-powered vendors in this space have not made.</p><h3>Why being first in data security matters</h3><p>Not all AI carries the same risk. A recommendation algorithm that misclassifies a product is inconvenient. An AI system that misclassifies sensitive data in your environment, or generates false positives that erode analyst trust, has real consequences: regulatory exposure, missed incidents and the slow erosion of confidence in the program itself.</p><p>Data security tools operate on the most sensitive information in the enterprise. Intellectual property, customer records, regulated data, the files that could become a breach headline if they reach the wrong destination. The AI that governs how that data is discovered, classified and protected needs to be held to a higher standard than tools operating in lower-stakes contexts.</p><p>Achieving ISO 42001 first in data security isn&#x27;t symbolic. It reflects what we believe responsible AI in this space should look like, and it sets a bar we&#x27;d encourage the rest of the industry to meet.</p><p><a href="https://mind.io/blog/[object Object]">{children}</a></p><h3>What this means for your program</h3><p>For security leaders managing risk and reporting to leadership, this certification changes a specific conversation. When you&#x27;re asked how the AI in your security stack is governed, what it&#x27;s been audited against and who holds it accountable, ISO 42001 gives you a clear and verifiable answer. Not a vendor&#x27;s word for it. An independent third-party assessment against an internationally recognized standard.</p><p>We&#x27;ve seen how the absence of AI governance frameworks creates friction, not just internally, but with auditors, regulators and boards who are increasingly asking these questions. The certification doesn&#x27;t just reflect MIND&#x27;s commitment to responsible AI. It gives the security leaders who rely on us something concrete to stand behind in those conversations.</p><p>That&#x27;s what Stress-Free DLP looks like in 2026: not just automation that works, but automation you can trust, explain and defend. If you&#x27;re ready to see how MIND&#x27;s certified platform fits into your data security program, we&#x27;d be glad to show you. </p><p><a href="https://mind.io/[object Object]">{children}</a>.</p>]]></description>
            <link>https://mind.io/blog/mind-first-iso-42001-data-security</link>
            <guid isPermaLink="true">https://mind.io/blog/mind-first-iso-42001-data-security</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Tue, 10 Mar 2026 10:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/f0fdeeebc051051a954132a409a96197ff4763d9-1920x1080.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft Copilot DLP Bypass: A Data Trust Wake-Up Call for AI Security]]></title>
            <description><![CDATA[<p>When Microsoft confirmed that a bug allowed <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/">Copilot to surface and summarize emails marked confidential despite existing DLP controls</a>, it reignited urgent questions about Microsoft Copilot security, DLP bypass risk and enterprise AI data protection. The reaction was immediate.</p><p>For many CISOs and security leaders responsible for Microsoft 365 security and AI risk management, it was a recognition of some exposure risks they were very much aware of.</p><p>AI assistants like Microsoft Copilot do not invent risk. They illuminate it. In this case, the Copilot DLP bypass highlighted a deeper enterprise AI security issue: data trust across Microsoft 365 and SaaS environments is not where it needs to be.</p><p>Copilot is easy to adopt. It integrates seamlessly into the Microsoft ecosystem. It promises productivity gains without heavy infrastructure changes. For organizations under pressure to move quickly into an AI-enabled future, enabling it feels natural and even necessary.</p><p>The controls were in place. The Microsoft 365 tenant was secured. DLP policies were configured.</p><p>Yet speed has a cost.</p><p>In the rush to capture AI value, many teams did not fully evaluate how sensitive data was classified, how permissions had expanded over time or how enforcement behaved under new AI-driven access patterns. What this moment exposed was not a single bug, but a broader condition: structural data fragility.</p><p>Over years, sensitive data sprawl, permission creep and incomplete classification quietly compound. The environment remains operational. Compliance boxes are checked. But structural risk accumulates beneath the surface, largely invisible until AI begins operating across it at scale.</p><h3>How did the Microsoft Copilot DLP bypass reveal a data trust gap?</h3><p>AI operates at machine speed. It searches, correlates and summarizes across vast volumes of content in seconds. If sensitive information is accessible within the environment, it will surface.</p><p>The core issue is not simply that Copilot bypassed DLP controls. The deeper issue is that protection depends on trust in your data foundation. Trust that you know what is sensitive, that it is accurately classified and that policies are enforced consistently across the estate.</p><p>Without that trust, controls become fragile.</p><p>For years, unstructured data has multiplied across cloud drives, SaaS, collaboration platforms and email systems. Files were shared. Access was granted. Exceptions were made. Policies were written but rarely continuously validated.</p><p>AI did not create this complexity. It revealed it.</p><h3>Are AI copilots exposing hidden DLP gaps and data exposure risks?</h3><p>This event may not be the last headline of its kind.</p><p>As organizations move quickly toward AI copilots, GenAI applications and agentic workflows, new edge cases will emerge. AI interacts with data differently than humans do. It traverses context. It aggregates at scale. It tests the boundaries of policy enforcement.</p><p>Unless data trust is embedded across the entire data estate, discovery, classification, detection, remediation, policy orchestration and prevention working in concert, similar exposures are a very real possibility for any company.</p><p>This is not a failure of innovation. It is a reminder that innovation amplifies whatever foundation it sits upon.</p><h3>Is Microsoft ecosystem security enough without a strong data foundation?</h3><p>Many leaders assumed that operating inside a trusted vendor ecosystem meant they were inherently protected. Platform security is critical, but it cannot compensate for incomplete visibility into your own data landscape. AI exposes the difference between compliance and confidence.</p><p><strong>Compliance asks,</strong> &quot;Do we have DLP rules?&quot;</p><p><strong>Confidence states,</strong> &quot;We truly understand what matters across our data estate.&quot;</p><p>Data trust means:</p><ul><li>Continuously discovering sensitive data wherever it lives</li><li>Accurately classifying it with business context</li><li>Monitoring how it is accessed and used</li><li>Detecting anomalous behavior in real time</li><li>Remediating risk automatically and consistently</li><li>Preventing data leaks and enforcing policies without relying on manual intervention</li></ul><p>When these elements operate together, AI becomes an accelerator. When they do not, AI becomes a magnifier of existing gaps.</p><h3>How can organizations build data trust and achieve DLP at AI speed?</h3><p>The Copilot story should not drive panic. It should drive reflection and action.</p><p>Organizations deserve to securely innovate at the speed of AI.</p><p>Data trust is not a feature, it&#x27;s an architectural commitment. It requires moving beyond static rules and fragmented tools toward a unified approach that continuously understands, prioritizes and protects what matters most.</p><p>This is where modern, AI-native data security platforms like MIND play a critical role.</p><p>MIND was built to establish data trust at scale and deliver Stress-Free DLP. It continuously discovers sensitive data and enables on-demand classification across SaaS, on-premise file shares, endpoints, emails and emerging AI tools, so protection keeps pace with change. It applies context-aware detection, prioritizes real risk and automates remediation to reduce noise and remove manual toil. The result is DLP on Autopilot, an intelligent system that understands your business and protects what matters without slowing it down.</p><p>When data trust is embedded across your environment, AI initiatives are no longer a source of uncertainty and exposure risk. They become sustainable, measurable and defensible.</p><p>Security and AI innovation do not have to compete.</p><p>But without data trust, they will.</p><p>The future of enterprise AI security will belong to organizations that move fast, thoughtfully, with clarity about what matters and confidence in how Microsoft Copilot, DLP controls and data trust are continuously protected.</p>]]></description>
            <link>https://mind.io/blog/microsoft-copilot-dlp-bypass-a-data-trust-wake-up-call-for-ai-security</link>
            <guid isPermaLink="true">https://mind.io/blog/microsoft-copilot-dlp-bypass-a-data-trust-wake-up-call-for-ai-security</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Thu, 26 Feb 2026 16:54:23 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ed22a806f0303d1e96fc47ce98acf7b4192c7b52-1096x720.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[7 Classification requirements for effective data security]]></title>
            <description><![CDATA[<h2>Modern data security rises or falls on the quality of its classification.</h2><p><em>Classification Blog Series</em></p><ol><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><strong><em>7 classification requirements for effective data security</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>Without an accurate view of the diversity and scale of sensitive data across the whole organization, it can be nearly impossible to enforce any security controls. They become either too restrictive or miss large swaths of risky file movements. In distributed, cloud-first environments, classification is no longer a preliminary step. It needs to be a continuously operating system that informs every control decision downstream. Static labels and periodic scans can’t keep pace with how data is created, modified and moved today.</p><p>At MIND, we believe classification should <strong>accurately empower effective data security</strong>. This drives how our classification engine is architected, how it operates at scale and how it connects directly to enforcement mechanisms.</p><h3>MIND's 7 data classification imperatives</h3><p>Our approach is anchored in seven non-negotiable principles that guide every technical decision:</p><ol><li><strong>Multi-layered by design</strong> to avoid single-model failure modes</li><li><strong>Complete coverage</strong> through full-content inspection, not sampling</li><li><strong>Real-time operation</strong> so classification scales with data movement</li><li><strong>Location-aware execution</strong> wherever data resides or flows</li><li><strong>Responsible AI</strong> applied deliberately and explainably</li><li><strong>Business-risk alignment</strong> beyond generic data types</li><li><strong>Direct enforcement coupling</strong> where classification drives control</li></ol><h3>1. Multi-layered classification is a technical necessity</h3><p>No single technique can reliably classify all forms of sensitive data. This isn’t a philosophical stance. It’s a proven property of machine learning systems. The <a href="https://www.cs.cornell.edu/~carlson/CS4780/NoFreeLunch.pdf"><strong>No Free Lunch Theorem</strong></a> shows that any model optimized for one class of problems will underperform on others.</p><p>MIND’s classification engine is intentionally multi-layered, combining complementary detection methods into a single decision framework:</p><ul><li><strong>Structural analysis</strong> evaluates file type, encoding, schema and syntax to establish baseline understanding</li><li><strong>Statistical detection</strong> applies deterministic and probabilistic techniques to identify known sensitive patterns such as credentials, PII and PCI</li><li><strong>Semantic modeling</strong> uses small and large language models to interpret meaning, relationships and intent within unstructured content</li><li><strong>Contextual evaluation</strong> correlates content with user identity, access patterns, data movement and destination</li></ul><p>Each layer independently contributes signal strength. Final classification decisions are derived from aggregated confidence, not single-model output. This design reduces false positives, improves recall and allows tuning without weakening overall accuracy.</p><h3>2. Complete coverage requires full-content inspection</h3><p>Sampling-based classification introduces unavoidable blind spots. Any system that inspects only a subset of files or partial content can’t guarantee coverage, especially in environments dominated by unstructured data.</p><p>MIND performs full-content inspection rather than probabilistic sampling. Files are scanned in their entirety, ensuring sensitive elements aren’t missed due to partial visibility. This approach is detailed and specific, but is made practical through:</p><ul><li>Parallelized scanning pipelines</li><li>Content de-duplication and locality-sensitive hashing</li><li>Incremental reclassification when files change</li></ul><p>The result is comprehensive visibility without linear performance degradation. Scale is achieved through architectural efficiency, not reduced fidelity.</p><h3>3. Classification must operate in real time</h3><p>Data classification that runs on a schedule is already out of date. Files change. Content is appended, removed and transformed continuously. Security controls must react to the current state of data, not a historical snapshot.</p><p>MIND classifies data in real time, both at rest and in motion. When content changes, classification updates as it moves, automatically. When sensitive elements are added or removed, downstream controls respond accordingly.</p><p>This real-time model enables immediate enforcement actions such as blocking, alerting or coaching users at the moment risk is introduced, rather than after exposure has already occurred.</p><h3>4. Location-aware classification reduces blind spots</h3><p>Where classification occurs directly impacts accuracy and enforcement reliability. Centralized-only classification architectures introduce latency, visibility gaps and dependency on data movement.</p><p>MIND classifies data at its point of residence and as it moves through the environment. This includes:</p><ul><li>Endpoints</li><li>SaaS and cloud storage platforms</li><li>Source code repositories</li><li>GenAI and Agentic AI interfaces</li><li>On-premises file shares</li><li>Email</li><li>Messaging applications</li><li>Wherever sensitive unstructured data resides</li></ul><p>By classifying data where it lives, MIND maintains consistent understanding regardless of location or transport path. Classification metadata travels with the data, enabling uniform policy enforcement across heterogeneous environments.</p><h3>5. Responsible AI enables precision at scale</h3><p>AI is essential for understanding modern unstructured data, but unbounded AI introduces risk. MIND applies AI deliberately, using purpose-built models optimized for classification tasks rather than generic inference.</p><p>Our approach combines:</p><ul><li>Deterministic statistical methods where precision is required</li><li>Small language models for constrained semantic interpretation</li><li>Larger models only where contextual depth is necessary</li></ul><p>All models are explainable, auditable and continuously evaluated. They are also proprietary to MIND and do not rely on publicly trained LLMs for effectiveness. AI is used to augment deterministic systems, not replace them. This ensures classification decisions remain defensible, tunable and aligned with business intent. In fact, our achievement of <a href="https://www.iso.org/obp/ui/en/#iso:std:iso-iec:42001:ed-1:v1:en">ISO 42001 certification</a> demonstrates our commitment to responsible, explainable and auditable AI.</p><h3>6. Classification must align to business risk, not just data types</h3><p>Traditional classification systems stop at identifying data types. They answer what the data is, but not why it matters. That gap leads to overprotection in some areas and dangerous blind spots in others.</p><p>At MIND, classification is designed to reflect business risk. Sensitive data is evaluated in context of its purpose, ownership and potential impact if misused or exposed. This allows security teams to prioritize protection based on real-world consequences, not generic labels.</p><p>Additionally, MIND&#x27;s classification can enhance other security measures and integrate with various tools for more effective security across the organization. For example, MIND can apply Microsoft Information Protection (MIP) labels to files, ensuring they are handled by Purview with the appropriate level of sensitivity within the Microsoft ecosystem.</p><p>By aligning classification to business risk, organizations gain clarity on what truly matters. Controls become proportional, decisions become defensible and security shifts from reactive compliance to intentional risk management.</p><h3>7. Classification directly drives security controls</h3><p>Classification without enforcement is observational. MIND treats classification as an active control plane.</p><p>Every classification decision feeds directly into data security actions, including:</p><ul><li>Blocking or allowing transfers</li><li>Enforcing encryption or access restrictions</li><li>Triggering user coaching or policy warnings</li><li>Generating real-time alerts and automated remediation</li></ul><p>There’s no abstraction layer between classification and control. This tight coupling ensures accuracy at the classification layer translates immediately into effective prevention.</p><h3>Conclusion: classification as an operating system</h3><p>At MIND, classification isn’t a feature. It’s an always-on system that continuously interprets data, context and risk. Multi-layered, real-time and location-aware classification enables security teams to move from reactive investigation to confident prevention.</p><h5><strong>Classification accurately empowers effective data security.</strong></h5><p><strong>See MIND in action</strong></p><p>To see how this architecture operates in real environments, <a href="https://mind.io/demo"><strong>get a demo</strong></a> and explore how MIND turns classification into control.</p>]]></description>
            <link>https://mind.io/blog/7-classification-requirements-for-effective-data-security</link>
            <guid isPermaLink="true">https://mind.io/blog/7-classification-requirements-for-effective-data-security</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Thu, 19 Feb 2026 18:00:36 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/192413c82a401fa0755dccd2bf1a8112be1a7a1b-3736x2301.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[How Can DLP Keep Up With AI Speed?]]></title>
            <description><![CDATA[<h2>Agentic AI is transforming the enterprise.</h2><p>Autonomous agents now summarize, decide and act on behalf of humans. They move data across SaaS apps, endpoints and AI tools at machine speed. For security leaders, this creates a new reality: <strong>innovation depends on AI, but traditional data loss prevention wasn’t built for autonomous systems.</strong></p><p>In fact, without the right controls, Agentic AI can be a data security nightmare.</p><p>The result is a widening gap between how fast data moves and how fast security can respond.</p><h3>Why does legacy DLP fail in an agentic AI world?</h3><p>Most DLP programs were designed for a human-first world. </p><p>Static rules. </p><p>Predictable workflows. </p><p>Manual review. </p><p>In an agentic environment, those assumptions no longer hold.</p><p>AI agents don’t pause for approval. They don’t follow linear paths. And they don’t generate neat, low-volume alerts that teams can triage by hand.</p><p>This leaves security teams with an impossible choice: slow AI adoption or accept blind spots.</p><h3>Why does speed matter for Data Loss Prevention in AI environments?</h3><p>Agentic AI changes the threat model.</p><p>Data can be accessed, transformed and shared in seconds. Risk compounds quickly. And when detection and response lag behind execution, prevention becomes a post-mortem exercise.</p><p>At AI speed, security has to move before humans can.</p><h3>What does data-centric AI security look like?</h3><p>As organizations race to adopt agentic AI, new security categories have emerged. While each plays a role, none are sufficient on their own to secure AI-driven business outcomes.</p><p>AI Security Posture Management (AI-SPM) helps teams understand how AI systems are configured and governed. AI runtime security monitors prompts, outputs and behavior once AI is already operating. Both are important, but both focus on the AI systems themselves.</p><p>What they don’t address is the most critical question: should this AI have access to this data in the first place?</p><p>MIND takes a data-centric approach to AI security, ensuring sensitive information is understood, governed and protected before any agentic AI can access or act on it. Instead of reacting to model behavior or configuration drift, MIND secures the data layer that all AI systems depend on.</p><p>This makes DLP fundamental to AI security. Without data-centric controls, posture and runtime protections can only respond after risk is introduced.</p><p>By putting data security at the center of AI adoption, MIND enables organizations to innovate with confidence and build a secure future for agentic AI.</p><p>That’s how security keeps up with AI.</p><h3>How can you secure agentic AI without slowing innovation?</h3><p>To safely adopt agentic AI, organizations need three core capabilities:</p><ol><li><strong>How Do You Know What Data AI Agents Are Accessing?<br/></strong>You can’t secure what you can’t see. MIND continuously discovers and understands sensitive data across SaaS apps, endpoints and AI workflows so security teams know exactly what information AI agents are touching.</li><li><strong>How Do You Know Which AI Agents Are Active in Your Environment?<br/></strong>Agentic AI shows up in many forms: SaaS features, homegrown agents and third-party tools. MIND provides visibility into where AI agents operate so organizations can reduce blind spots and unmanaged risk.</li><li><strong>How Do You Build the Right Controls Between Data and AI?<br/></strong>MIND helps teams enforce context-aware controls that ensure data and AI interact safely. Policies are based on risk and intent, not static rules, allowing AI to operate while sensitive data stays protected.</li></ol><p>The result is security that enables AI adoption instead of blocking it.</p><h3>How do you mind what matters at AI speed?</h3><p>Agentic AI isn’t slowing down. Neither is data movement.</p><p>With DLP at the speed of AI, MIND helps security teams stay ahead, protect what matters and adopt AI with confidence.</p><p>If your organization is embracing agentic AI, it’s time to rethink how DLP works.</p><h3>See it for yourself!</h3><p><a href="https://mind.io/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/how-can-dlp-keep-up-with-ai-speed</link>
            <guid isPermaLink="true">https://mind.io/blog/how-can-dlp-keep-up-with-ai-speed</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 28 Jan 2026 12:35:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/9557f75b5679892277a59cfd0c8e44c8e42832b0-5403x3240.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[NIST’s Blueprint for AI Security: How Data Trust Enables AI Success]]></title>
            <description><![CDATA[<h2>The rapid adoption of artificial intelligence has forced organizations to confront a hard truth: AI changes the cybersecurity equation.</h2><p>New attack surfaces, new misuse patterns and new forms of automation require a different approach to managing risk.</p><p>That’s why NIST has stepped forward.</p><p>Through its <a href="https://www.nist.gov/news-events/news/2025/12/draft-nist-guidelines-rethink-cybersecurity-ai-era">draft AI cybersecurity profile</a>, <a href="https://www.nist.gov/cyberframework">NIST CSF 2.0</a> and the <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI Risk Management Framework</a>, NIST makes one thing clear: AI security must be grounded in proven cybersecurity principles, adapted for an AI-driven world. That’s where a focus on data trust comes in.</p><p>NIST provides an effective structure that can be a helpful guide for teams. In practice, <strong>building data trust is one of the most effective steps teams can take to enable safe, effective AI usage</strong>.</p><h3>What is NIST’s view of AI security?</h3><p>NIST does not treat AI security as a standalone discipline. Instead, it extends existing cybersecurity frameworks to account for how AI systems consume data, make decisions and act autonomously.</p><p>Across both <a href="https://www.nist.gov/cyberframework">NIST CSF 2.0</a> and the <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI Risk Management Framework</a>, several themes are consistent:</p><ul><li>Organizations must govern AI use intentionally</li><li>Data and system dependencies must be understood before deployment</li><li>Risk must be measured continuously, not assumed</li><li>Controls must adapt as behavior changes</li></ul><p>At the center of all of these themes is a growing problem: organizations lack confidence in how their data is accessed and used. Without that confidence, they cannot meaningfully govern AI risk, because they don’t know whether data is being used safely, appropriately or at all as intended.</p><h3>What is data trust?</h3><p>Data trust is the degree of confidence an organization has that its systems use data safely and appropriately.</p><p>This aligns naturally with NIST’s intent. It’s not about perfection. It’s about having enough clarity and control to be confident that data use matches policy, regulatory obligations and business intent.</p><p>In an AI-driven environment, this matters because systems can move quickly and at scale. When data is overexposed or misunderstood, AI can spread that risk faster than most teams can react.</p><h3>How NIST frameworks use data trust to secure AI systems</h3><p><a href="https://www.nist.gov/cyberframework">NIST CSF 2.0</a> establishes the operational backbone for data trust.</p><ul><li><strong>Govern</strong> defines expectations for how data and AI systems should be used</li><li><strong>Identify</strong> creates visibility into sensitive data and data flows</li><li><strong>Protect</strong> enforces appropriate access and safeguards</li><li><strong>Detect</strong> validates that data is being used as intended</li><li><strong>Respond and Recover</strong> preserve confidence when incidents occur</li></ul><p>The <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI Risk Management Framework</a> builds on this foundation by focusing on AI-specific risk.</p><ul><li><strong>Govern</strong> aligns AI use with organizational values</li><li><strong>Map</strong> documents data inputs and dependencies</li><li><strong>Measure</strong> evaluates whether AI systems behave in trustworthy ways</li><li><strong>Manage</strong> adapts controls as risk changes</li></ul><p>Taken together, these frameworks describe the path to data trust, even if they don’t always use the term explicitly.</p><h3>What does data trust mean in the AI era?</h3><p>Traditionally, data security focused on protecting data at rest or in transit. AI changes the model because data is now actively used and manipulated by humans, applications and other AI systems across cloud platforms, SaaS tools, endpoints and GenAI services.</p><p>In this context, a practical definition of data trust is straightforward: you can explain, with evidence, that AI systems are accessing and using data safely and appropriately.</p><p>That typically means:</p><ul><li>Sensitive data is identified before it enters AI workflows</li><li>Access reflects least privilege, not convenience</li><li>Usage aligns with organizational policy and compliance obligations</li><li>Risk is monitored continuously, not discovered after the fact</li></ul><p>Without this foundation, AI introduces uncertainty instead of value.</p><h3>Why NIST-aligned data trust matters for AI security</h3><p>AI doesn’t create new data security problems. It magnifies existing ones.</p><p>If organizations lack visibility into where sensitive data lives, AI will find it anyway. If access controls are overly permissive, AI will inherit those permissions. If teams rely on static rules, AI-driven workflows will outpace them.</p><p>NIST explicitly warns against treating AI security as an overlay bolted onto existing programs, a theme reinforced across its <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI RMF guidance</a> and broader <a href="https://www.nist.gov/cybersecurity">cybersecurity publications</a>. Instead, AI risk must be integrated into core cybersecurity practices. A focus on data trust is what makes that integration tangible.</p><p>When teams can demonstrate that data is used safely and appropriately, AI becomes easier to govern and safer to scale.</p><h3>How organizations build data trust using NIST guidance</h3><p>Data trust isn’t achieved through policy alone. It’s built by applying NIST principles to how data is actually used, then validating that those controls work over time.</p><ol><li><strong>Continuous data visibility: </strong>NIST emphasizes understanding assets and dependencies. For AI, that starts with continuous discovery and classification of sensitive data across SaaS, cloud, endpoints and GenAI tools. Visibility cannot be periodic. AI usage evolves too quickly.</li><li><strong>Context-driven risk evaluation: </strong>NIST calls for improved signal quality and risk measurement. Context provides that signal. Understanding who is accessing data, what they are doing and whether behavior aligns with normal patterns reduces noise and surfaces real risk.</li><li><strong>Data-centric enforcement: </strong>NIST frameworks assume controls follow risk. In AI environments, risk follows the data. Enforcing policy based on data sensitivity rather than application boundaries enables safe AI adoption without adding friction.</li><li><strong>Responsible use of AI for security: </strong>NIST also highlights the defensive potential of AI. With trusted data and strong context, AI can help prioritize risk, detect anomalies faster and reduce manual remediation. Used this way, AI strengthens security instead of undermining it.</li><li><strong>Continuous verification of appropriate data use: </strong>NIST frameworks emphasize that trust must be continuously validated, not assumed. In practice, this means organizations must regularly verify that data is being accessed and used in ways that remain safe, appropriate and aligned with policy as AI systems, users and workflows evolve.</li></ol><h3>The impact on data security and the business</h3><p>Organizations that apply NIST guidance with a data trust focus often see benefits that extend beyond AI initiatives.</p><p>Security teams gain better visibility into real risk, fewer false positives and faster response times. The business gains safer AI adoption, reduced risk of data leakage and greater confidence in AI-driven outcomes.</p><p>Most importantly, security evolves from a reactive compliance function into an enabler of innovation.</p><h3>Why NIST and data trust matter now</h3><p>AI adoption is accelerating whether organizations are ready or not. Employees are using AI tools. Adversaries are exploiting automation. Regulators are paying close attention.</p><p>NIST provides the framework for navigating this shift. <strong>A deliberate focus on data trust is a practical way to put that framework into action</strong>.</p><p>If AI is going to deliver real value, organizations need confidence that their systems use data safely and appropriately. That confidence is built through governance, visibility and continuous verification.</p><p>In the AI era, NIST shows the way. A disciplined approach to data trust is one of the clearest paths to follow it.</p>]]></description>
            <link>https://mind.io/blog/nist-blueprint-for-ai-security-how-data-trust-enables-ai-success</link>
            <guid isPermaLink="true">https://mind.io/blog/nist-blueprint-for-ai-security-how-data-trust-enables-ai-success</guid>
            <dc:creator><![CDATA[Landen Brown]]></dc:creator>
            <pubDate>Tue, 20 Jan 2026 17:08:17 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/f72cefb996ff68eac399b45bc3d8b0cece4780c2-960x745.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[What does DLP really cost?]]></title>
            <description><![CDATA[<h2>Introducing MIND’s DLP Savings Estimator!</h2><p>Data loss prevention (DLP) has never been a question of <em>if</em> it’s needed. For most security leaders, the real question is what it’s actually costing them to manage and operate.</p><ul><li>Not in license fees.</li><li>Not in shelfware.</li><li>But in valuable time, critical headcount and constant tradeoffs.</li></ul><p>Security teams know the feeling well. Alerts pile up faster than they can be triaged. False positives drown out real risk. Coverage gaps quietly become accepted as “good enough.” And the unspoken reality sets in: most teams are only able to investigate a fraction of the alerts they generate. In fact, most teams <a href="https://mind.io/content/[object Object]">{children}</a>.</p><p>This is where confidence erodes. Not because teams don’t care, but because the math doesn’t math. There are just not enough analyst FTE hours in a year to get to them all.</p><p>That’s why we built the <a href="https://mind.io/product/dlp-savings-estimator">{children}</a>. Not as a marketing gimmick, but as a way to make the invisible visible. To help security leaders understand what it really takes to mind what matters and what changes when DLP works differently.</p><h3>What is the hidden cost of alert volume?</h3><p>Traditional DLP models assume infinite analyst time. In practice, teams operate with finite resources and escalating demand. In fact, some checkbox-driven DLP programs even pride themselves on the sheer number of alerts they generate, as if volume alone were a measure of security value rather than a signal of noise.</p><ul><li>Every user generates alerts.</li><li>Every alert requires context.</li><li>Every investigation takes time.</li></ul><p>Even when alerts are legitimate, the manual effort adds up quickly. When they’re not, the cost compounds. Hours are spent chasing noise. Analysts burn cycles validating false positives. Coverage quietly drops, not by design, but by necessity.</p><p>Independent research reinforces this reality. In <a href="https://mind.io/registration/[object Object]">{children}</a> Enterprise Strategy Group found that most organizations struggle with alert noise, manual remediation and the operational burden of maintaining DLP programs at scale. The research revealed a sobering fact: nearly 50% of DLP alerts are false positives. Reducing alert volume and gaining context awareness consistently ranked among the top priorities for security leaders.</p><p>For many organizations, this results in a hard truth: full alert coverage with traditional DLP typically requires additional headcount.</p><p>The estimator is designed to surface this reality. By starting with a simple input, your user count, it models the downstream impact of alert volume, triage time and analyst cost. The result is a clear view of how much effort is required just to reach full coverage.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/e96a6d3c075942f1af4365f82b221d3d8272c587-2764x1178.png?w=500" /><h3>What assumptions did we use to build this estimator?</h3><p>We’ve all seen ROI calculators that feel disconnected from reality. That’s not the goal here. Every input in the estimator is visible and adjustable, because every environment is different. You can tune:</p><ul><li>The average number of data security alerts generated per user each month</li><li>Analyst compensation assumptions</li><li>The average time required to triage a single alert</li></ul><p>Each default value is grounded in direct CISO feedback, but none are locked. The point isn’t to tell you what your environment looks like. It’s to let you reflect it accurately. This transparency matters. Because operational savings only mean something if they’re credible.</p><p>This estimator also projects the amount of resources needed to build out your team to handle 100% of DLP alerts. Since most teams are not </p><h3>What changes with MIND?</h3><p>Once the baseline is established, the estimator shows what happens when DLP stops behaving like a volume problem and starts behaving like a prioritization problem.</p><p>MIND reduces total alert volume by an average of <strong>67%</strong> (SOURCE: MIND customer installations and CISO interviews) through smarter data classification, automated remediation and user-guided enforcement. Fewer alerts and false positives mean fewer investigations. Better context means faster decisions. Automation means less manual effort across the board.</p><figure><blockquote><p>“We’re spending probably a fifth of the time we used to managing our DLP program.”</p></blockquote><figcaption><cite>Yaron Blachman</cite> Chief Information Security Officer, OpenWeb</figcaption></figure><p>Instead of asking, “How many analysts do we need to keep up?” the model shifts the question to, “What could we do if we didn’t have to?”</p><figure><blockquote><p>“MIND was a lot more accurate and I can't remember a single case where we had false positives.”</p></blockquote><figcaption><cite>Mike Moratto</cite> CISO & Head of IT, Noname Security</figcaption></figure><p>The savings shown aren’t theoretical. They represent labor cost reductions driven by lower alert volume, shorter triage time and less repetitive manual work. More importantly, they reflect a different operational outcome: the ability to reach full alert coverage without adding headcount.</p><video controls><source src="https://stream.mux.com/FfrraabHkYh02IHAO5d6C7JMTw82pdohfrB9A4LbHGMo.m3u8" type="application/x-mpegURL"></video><h3>How do you go from compliance to confidence?</h3><p>When teams are forced to choose which alerts to investigate, DLP becomes a compliance exercise. Boxes get checked but risk remains unmitigated. Confidence is hard to come by.</p><p>When alert volume drops and context improves, something changes. Teams can investigate everything that matters. They can trust what they see. They can make decisions proactively instead of reactively.</p><p>That’s the outcome the estimator is meant to clarify.</p><p>It doesn’t promise perfection. It doesn’t assume zero effort. It simply shows what it really takes to mind what matters today and how that equation changes when DLP runs on intelligence instead of noise.</p><h3>Why did we build this?</h3><p>Security leaders are under constant pressure to justify spend, headcount and tooling. At the same time, they’re expected to reduce risk, enable the business and prepare for what’s next.</p><p>We built the MIND DLP Savings Estimator to support that reality. To replace vague assumptions with clarity. To ground conversations in data. And to give teams a way to evaluate DLP not just by what it detects, but by how it operates.</p><p>Because stress-free DLP isn’t about doing more work faster. It’s about doing the right work effectively.</p><p>If you’re ready to see what that looks like in your environment, the estimator is a good place to start.</p><h4>👉 <a href="https://mind.io/product/dlp-savings-estimator">{children}</a></h4>]]></description>
            <link>https://mind.io/blog/what-does-dlp-really-cost</link>
            <guid isPermaLink="true">https://mind.io/blog/what-does-dlp-really-cost</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 14 Jan 2026 13:20:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/0898a656f21b9537bc59582a8b12d920c1741c50-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Network, Endpoint and Cloud DLP Explained]]></title>
            <description><![CDATA[<p>Data loss prevention (DLP) has been around for decades, but the way organizations use data has changed dramatically. Files no longer live in a single data center. They move across cloud apps, personal devices, collaboration tools and AI systems. As a result, DLP solutions have evolved into three primary categories: network DLP, endpoint DLP and cloud-based DLP.</p><p>Each type addresses a different part of the data lifecycle. Understanding how they work and where they fit helps teams make more informed decisions about protecting sensitive information.</p><h3>What are the main types of DLP Solutions?</h3><h6>Network DLP</h6><p>Network DLP is one of the earliest forms of data loss prevention. It focuses on monitoring and controlling data as it moves across the network perimeter. These solutions typically inspect traffic leaving the organization through email gateways, web proxies or network appliances.</p><p>The core strength of network DLP is visibility into outbound traffic. It can detect sensitive data being sent via email, uploaded to external websites or transferred through network protocols. When a policy violation occurs, the system may block the transmission, quarantine the content or alert security teams.</p><p>However, network DLP relies heavily on traffic inspection and predefined rules. It often struggles with encrypted traffic, which now represents a large portion of network activity. It also has limited insight into user intent or business context. A file transfer that looks risky on the network may actually be a legitimate business process.</p><p>Network DLP is most effective in environments where data flows through controlled gateways and where encryption and cloud usage are limited. In modern environments, it often serves as one layer of protection rather than a complete solution.</p><h6>Endpoint DLP</h6><p>Endpoint DLP focuses on protecting data directly on user devices such as laptops, desktops and servers. Instead of watching traffic at the network level, it monitors actions performed by users and applications on the device itself.</p><p>Endpoint DLP can see when a user copies data to a USB drive, uploads a file to a web app, prints a document or pastes content into a browser. Because it operates at the device level, it can enforce controls even when the user is off the corporate network.</p><p>This visibility makes endpoint DLP valuable for understanding how data is used in daily workflows. It allows organizations to apply controls closer to the point of action and respond in real time.</p><p>At the same time, endpoint DLP can be challenging to manage. Agents must be deployed and maintained across many devices. Policies can become complex and overly restrictive if they are not carefully tuned. Without strong classification and context, endpoint DLP can generate false positives that frustrate users and overwhelm security teams.</p><p>Endpoint DLP works best when organizations need direct control over user actions and when they can support agent deployment and policy management at scale.</p><h6>Cloud-Based DLP</h6><p>Cloud-based DLP emerged as organizations moved data into SaaS platforms and cloud infrastructure. Instead of focusing on networks or devices, this approach protects data where it lives and moves in cloud environments.</p><p>Cloud DLP solutions typically integrate with SaaS applications, cloud storage platforms and sometimes AI tools. They scan data at rest, monitor sharing and access controls and detect risky activity such as public exposure or excessive permissions.</p><p>One of the key advantages of cloud-based DLP is visibility. It helps teams understand where sensitive data exists across cloud services and how it is shared. This is especially important as collaboration tools and third-party integrations become more common.</p><p>Cloud DLP can also struggle if it relies solely on pattern matching or static rules. Without context, it may flag benign sharing as risky or miss subtle misuse. Coverage can vary depending on the depth of integration with each platform.</p><p>Cloud-based DLP is essential for organizations that rely heavily on SaaS and cloud infrastructure. It provides insight that network and endpoint tools cannot reach on their own.</p><h3>How do different types of DLP work together?</h3><p>No single type of DLP covers every risk. Network, endpoint and cloud-based solutions each see a different slice of data activity. Network DLP watches traffic leaving the environment. Endpoint DLP observes user actions at the source. Cloud DLP provides visibility into data stored and shared in cloud services.</p><p>Modern data environments require a more connected view. Data may originate on an endpoint, move through a SaaS app and eventually leave the organization through an integration or API. When DLP tools operate in isolation, gaps appear. Alerts lack context and teams struggle to understand what truly matters.</p><p>That’s why many organizations now look for ways to combine signals across these layers. When content, context and behavior are considered together, DLP becomes less about blocking and more about understanding risk.</p><h3>How do I choose the right mix of DLP coverage?</h3><p>Selecting DLP solutions is not about picking a single category. It’s about understanding where your data lives, how it moves and which risks matter most to your organization.</p><p>Network DLP can still play a role in controlling outbound traffic. Endpoint DLP helps protect data at the point of use. Cloud-based DLP brings visibility to SaaS and cloud environments. Together, they form a more complete picture.</p><p>The goal is not more alerts or stricter rules. It’s clarity. When teams understand how data is used across the organization, they can protect it in a way that supports people, workflows and the business itself.</p>]]></description>
            <link>https://mind.io/blog/network-endpoint-and-cloud-dlp-explained</link>
            <guid isPermaLink="true">https://mind.io/blog/network-endpoint-and-cloud-dlp-explained</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Tue, 06 Jan 2026 15:08:51 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/e62c2710db4bf4328163c9d2cf04cbd3c0ea3544-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[2026 predictions: Agentic AI is breaking identity and data security as we know it]]></title>
            <description><![CDATA[<h2>The security landscape is shifting and agentic AI is moving faster than traditional security approaches can keep up.</h2><p>AI has changed how work gets done and how risk materializes. What once felt experimental is now operational: GenAI in the hands of employees, autonomous agents executing workflows and sensitive data moving across SaaS and GenAI apps, clouds, on-prem systems, endpoints and emails at machine speed.</p><p>As we look toward 2026, security leaders will be forced to confront a hard truth. In an AI-driven world, treating data and identity as isolated silos will break all the models we know, creating blind spots that are easy to miss and hard to manage.</p><p>Historically, identity and data lived in separate domains. Different teams. Different tools. Different success metrics. Identity answered who could access systems. Data security focused on what was being accessed. Together, they defined when and where access occurred.</p><p>AI breaks that model.</p><p>AI agents operate across identity and data simultaneously. They act, generate, analyze and transmit sensitive information, sometimes without a human in the loop. Risk no longer fits neatly into IAM or DLP alone.</p><p>Looking ahead to 2026, I think we will see 5 trends in cybersecurity. Each points to the same imperative: security must become more unified, more adaptive and more context-aware.</p><h3>2026 predictions</h3><h3>1. Security will return to first principles: identity and data</h3><p>As environments grow more complex, security will come full circle.<br/>In 2026, organizations will realize that most modern controls are abstractions layered on top of two foundational truths: who or what is acting and what data is being used. Networks, perimeters and destinations will matter less than identity and data context.</p><p>Identity defines intent and accountability.</p><p>Data defines value and risk.</p><p>Everything else becomes an implementation detail.</p><p>This shift won’t be nostalgic. It will be pragmatic. AI introduces too much speed and autonomy for surface-level controls to keep up, forcing security teams to rethink what they anchor on.</p><h3>2. AI will break deterministic, rule-based risk models</h3><p>Traditional security assumes predictable behavior. But AI is a &#x27;non-deterministic&#x27; wild card.</p><p>AI agents and systems learn, adapt and evolve. They introduce risk that static policies and Boolean logic can’t keep up with. Rules like “if X, then block Y” will generate more noise than signal as AI-driven workflows accelerate.</p><p>In 2026, organizations will move away from rigid policies toward adaptive risk models. These models will evaluate behavior, identity (human, non-human, AI systems, agents) and data sensitivity in real time, factoring in context rather than relying on predefined assumptions.</p><p>Instead of guessing risk based on patterns, column headers or lineage alone, security systems will understand content and intent and respond accordingly.</p><h3>3. CISOs will shift from gatekeepers to enablers of trusted autonomy</h3><p>The role of the CISO is definitely changing and this will only accelerate in 2026.</p><p>For years, security leaders were positioned as gatekeepers, responsible for saying no to risky behavior. In the era of AI, that posture won’t scale. The mission won’t be to stop everything. It’ll be to guide innovation safely.</p><p>In 2026, effective CISOs will focus on designing trust into systems that enable their business to thrive. That means embedding policy awareness into AI workflows, enabling agents to operate autonomously while respecting data sensitivity, compliance requirements and ethical boundaries.</p><p>Security will become a design discipline, not just a control function.</p><h3>4. Agentic AI adoption will outpace its reliability</h3><p>Agentic AI will move from experimentation to execution faster than most organizations expect.</p><p>Next year, AI agents won’t just assist users. They’ll provision access, move data, generate content and make decisions on behalf of the business and its people. Adoption will accelerate because the value is real.</p><p>Reliability will lag.</p><p>Early deployments will suffer from over-privileged agents, incomplete context and weak guardrails. The result won’t always be dramatic breaches. It’ll be frequent, subtle failures: unintended data exposure, policy drift and autonomous actions that violate intent without malicious behavior.</p><p>The problem won’t be AI itself. It will be the lack of sufficient context or understanding of how a non-deterministic system operates at scale in the organization.</p><h3>5. AI regulation will arrive, imperfect but unavoidable</h3><p>In 2026, AI regulation will become a reality.</p><p>It won’t be elegant. It won’t be uniform. But federal, state and local governments will introduce guidelines focused on accountability, explainability and data protection. These rules won’t dictate architectures, but they’ll demand clearer answers to basic questions: Who acted? What data was used or exposed? Why was a decision made?</p><p>Organizations relying on opaque, siloed controls will struggle to respond, especially as regulatory expectations continue to evolve.</p><h3>The bottom line: Automation is the future of security</h3><p>As we move into 2026, the lines between user and agent, access and action, data content and context and traditional IT environments will continue to blur.</p><p>What matters isn’t visibility or control in isolation. It’s understanding risk continuously and in real time. Identity and data are no longer separate problems. They’re part of the same challenge and must be part of the same solution.</p><p>Companies that embrace convergence and enable innovation with trust will unlock a new era of resilience, productivity and innovation for their overall business.</p><p>And in 2026, security leaders will be at the helm of this transition.<br/></p>]]></description>
            <link>https://mind.io/blog/why-agentic-ai-breaks-the-traditional-security-approach</link>
            <guid isPermaLink="true">https://mind.io/blog/why-agentic-ai-breaks-the-traditional-security-approach</guid>
            <dc:creator><![CDATA[Eran Barak]]></dc:creator>
            <pubDate>Tue, 30 Dec 2025 13:57:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ea049a8c044a0e5a1478b82a35794af5c8fe2d4f-3600x2409.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[How do DLP policies work to protect sensitive data?]]></title>
            <description><![CDATA[<h2>In today’s data-driven world, sensitive information moves constantly. It flows through SaaS apps, endpoints, cloud storage, collaboration tools and now GenAI platforms.</h2><p>For security leaders, the challenge isn’t just knowing where data lives. It’s ensuring that data is handled correctly wherever it goes. That’s where Data Loss Prevention policies come in.</p><p>DLP policies are the rules that define how sensitive data should be stored, used and moved. When designed and enforced correctly, they help organizations reduce risk, meet compliance requirements and protect what matters most without slowing the business down.</p><h3>What is a DLP policy?</h3><p>At its core, a DLP policy is a set of conditions and actions. The conditions define what data matters and what risky behavior looks like. The actions define what should happen when that behavior occurs.</p><p>A typical policy answers three key questions:</p><ul><li>What type of data are we protecting?</li><li>Where is that data allowed or not allowed to go?</li><li>What action should be taken if the policy is violated?</li></ul><p>For example, a policy might state that files containing personal data shouldn’t be shared externally or uploaded to public AI tools. If that action occurs, the policy can trigger an alert, block the action or guide the user with a warning.</p><h3>How do DLP policies identify sensitive data?</h3><p>DLP policies can only work if the system understands what data is sensitive in the first place. This starts with data discovery and classification.</p><p>Modern DLP platforms scan data across environments to identify sensitive content such as personal information, financial data, credentials or intellectual property. Instead of relying only on simple pattern matching, more advanced approaches analyze context and content to understand meaning.</p><p>This step is critical because inaccurate classification leads to false positives or missed risk. When policies are built on a clear understanding of data, enforcement becomes more precise and trustworthy.</p><h3>How do DLP policies define acceptable data use?</h3><p>Once sensitive data is identified, DLP policies define how that data can be used. This is where business intent is translated into enforceable rules.</p><p>Policies typically focus on common risk scenarios, including:</p><ul><li>Data exfiltration, such as uploading sensitive files to unsanctioned websites or AI tools</li><li>Data exposure, such as sharing files publicly or with the wrong users</li><li>Improper access, such as employees accessing data outside their role</li></ul><p>The goal isn’t to lock data down completely, it’s to align protection with business context. Finance teams need different access than engineering. Vendors need different access than employees. Effective DLP policies reflect these realities.</p><h3>How do DLP policies monitor data in real time?</h3><p>With policies in place, DLP continuously monitors data activity. This includes data at rest and in motion.</p><p>As users share files, send emails, collaborate in SaaS apps or interact with GenAI tools, the system evaluates each action against defined policies. When a risky event is detected, the policy is triggered.</p><p>This real-time monitoring is what allows DLP to move from a reactive audit tool to an active security control.</p><h3>How do DLP policies enforce actions to reduce risk?</h3><p>Detection alone doesn’t stop data loss. Enforcement is where DLP policies deliver value.</p><p>Depending on severity and context, a policy can trigger different responses:</p><ul><li>Blocking the action outright</li><li>Allowing the action with a user justification</li><li>Alerting security teams</li><li>Coaching users with in-the-moment guidance</li><li>Automatically remediating exposure, such as removing public access</li></ul><p>The most effective policies use graduated responses. Low-risk behavior might warrant education. High-risk behavior might require immediate prevention. This balance helps protect data while maintaining productivity.</p><h3>How do DLP policies improve over time?</h3><p>DLP policies aren’t set-and-forget. As data, tools and workflows evolve, policies must adapt.</p><p>Modern platforms use risk signals and behavior patterns to refine enforcement. This reduces noise, cuts down false positives and helps teams focus on what truly matters. Over time, policies become more aligned with how people actually work.</p><h3>Why do DLP policies matter more than ever?</h3><p>Traditional DLP often failed because policies were static, noisy and disconnected from context. Today’s environments demand something smarter.</p><p>When policies are built on accurate data classification, applied consistently across environments and enforced with context, DLP becomes a strategic asset. It shifts security from reactive compliance to proactive protection.</p><p>For CISOs and security leaders, the outcome is confidence. Confidence that sensitive data is protected. Confidence that teams aren’t buried in alerts. Confidence that security enables the business instead of slowing it down.</p><p>That’s the real purpose of DLP policies. Not just to check a box, but to mind what matters.</p>]]></description>
            <link>https://mind.io/blog/how-do-dlp-policies-work-to-protect-sensitive-data</link>
            <guid isPermaLink="true">https://mind.io/blog/how-do-dlp-policies-work-to-protect-sensitive-data</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Tue, 23 Dec 2025 23:24:22 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/76b070dc075534b4d342e1c715a3c272271a4da7-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[What upcoming AI Security regulations should you be aware of?]]></title>
            <description><![CDATA[<h2>Stay ahead of the curve in a rapidly changing compliance landscape</h2><p>Artificial intelligence is no longer a future concern; it’s today’s governance challenge. As AI systems become more deeply embedded in business operations, regulators across the United States are racing to establish frameworks that protect individuals, ensure fairness and preserve trust.</p><p>For security leaders, that means one thing: compliance complexity is about to grow.</p><p>Below, we’ve outlined the key <strong>AI security and privacy laws</strong> coming into effect in <strong>2026</strong>, at a national level and broken down by geography. Knowing what’s ahead gives you a head start on preparation and helps you mind what matters before enforcement begins.</p><h3>Federal Outlook: Unified Executive Order on AI controls</h3><p>At the national level, there is some movement towards an <a href="https://www.reuters.com/world/trump-says-he-will-sign-executive-order-this-week-ai-approval-process-2025-12-08/">Executive Order</a> (EO) defining the limits of AI governance and regulation. While the U.S. legislature has yet to enact any federal rules, this Executive Order is expected to have jurisdictional authority and pave the way for any future regulation.</p><p><strong>What to watch:</strong></p><ul><li><strong>Upcoming Executive Order, </strong>once signed, will need to be evaluated by companies to ensure any compliance requirements.</li><li><strong>The White House Executive Order on Safe, Secure, and Trustworthy AI (2023)</strong> continues to influence agency rulemaking and standards.</li><li><strong>NIST AI Risk Management Framework (RMF)</strong> is becoming the de facto baseline for responsible AI practices. Expect increasing pressure for organizations to demonstrate RMF alignment during audits and vendor reviews.</li><li><strong>Federal agencies</strong> including the FTC, EEOC and CFPB have all issued warnings on AI bias, consumer protection and data handling, signals of stronger enforcement to come.</li></ul><p><strong>The takeaway: </strong>This Executive Order is intended to make it simpler to understand and comply with a single set of regulations instead of a shifting mosaic of state-level guidance. However, some states are concerned that this EO won’t go far enough in protecting their people. Expect confusion around AI regulations as this plays out in the court system and legislative bodies across the country.</p><h3>State-Level Regulations: The current front lines</h3><p>States are leading the charge for AI regulation, each introducing distinct laws to govern AI development, deployment and data use. Here are the most significant to watch in 2026:</p><h5><strong>California</strong></h5><p><a href="https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942"><strong>The AI Transparency Act (SB 942)</strong></a></p><p><strong>Effective:</strong> January 1, 2026</p><p>California expands its privacy leadership into AI. The new law mandates:</p><ul><li>Clear notice when consumers interact with AI systems</li><li>Documentation of AI functionality and data sources</li><li>Disclosure requirements for generative and conversational AI platforms</li></ul><h5><strong>New York State</strong></h5><p><a href="https://www.nysenate.gov/legislation/bills/2025/A6453/amendment/A"><strong>The Responsible AI Safety and Education (RAISE) Act</strong></a></p><p><strong>Effective:</strong> January 1, 2026</p><p>This bill targets “frontier” or “high-risk” AI models that could influence safety, financial systems or civic operations. It introduces:</p><ul><li>Independent audits and incident reporting</li><li>Safety plans and documentation of model intent</li><li>Public transparency reports for large AI developers</li></ul><h5><strong>Texas</strong></h5><p><a href="https://capitol.texas.gov/tlodocs/89R/analysis/html/HB00149S.htm"><strong>The Responsible AI Governance Act (TRAIGA)</strong></a></p><p><strong>Effective:</strong> January 1, 2026</p><p>Texas focuses on accountability and governance, requiring:</p><ul><li>Documented AI lifecycle management</li><li>Red-teaming, transparency reporting and oversight for “high-impact” systems</li><li>Annual internal reviews to validate compliance</li></ul><h5><strong>Colorado</strong></h5><p><a href="https://leg.colorado.gov/bills/sb24-205"><strong>The Colorado AI Act (SB 205)</strong></a></p><p><strong>Effective:</strong> February 1, 2026</p><p>Colorado became the first state to pass a comprehensive AI accountability law. It defines “high-risk” AI systems and requires:</p><ul><li>Impact assessments for systems influencing employment, education, finance or healthcare</li><li>Transparency disclosures to users</li><li>Risk mitigation and bias monitoring obligations for developers and deployers</li></ul><h3>Local and Municipal: NYC leads the way</h3><p><a href="https://rules.cityofnewyork.us/rule/automated-employment-decision-tools-updated/"><strong>NYC Local Law 144 – Automated Employment Decision Tools</strong></a></p><p><strong>In effect since 2023, continuing enforcement into 2026</strong></p><p>This law regulates the use of automated hiring and promotion tools. It requires organizations to:</p><ul><li>Conduct independent bias audits annually</li><li>Notify candidates and employees when AI tools are used in decision-making</li><li>Publish summaries of audit results for transparency</li></ul><p>While not new, its continued enforcement and the expansion of similar policies in other cities mark a pivotal shift: municipalities are no longer waiting for federal action.</p><p><strong>What’s next: </strong>The <a href="https://www.nyc.gov/assets/oti/downloads/pdf/reports/artificial-intelligence-action-plan.pdf">NYC AI Action Plan (2023)</a> sets the stage for additional oversight of how city agencies and contractors deploy AI, establishing a framework other municipalities are likely to follow by 2026.</p><h3>Why This Matters: AI, privacy and data security converge</h3><p>Every one of these laws ties back to a shared principle: <strong>AI systems can’t be trusted unless data is protected, traceable and governed intelligently. </strong>For CISOs, compliance officers and data protection teams, 2026 isn’t just about checking regulatory boxes, it’s about building defensible systems that demonstrate control.</p><p><strong>What leaders should do now:</strong></p><ol><li><strong>Map your AI footprint</strong>: Know where AI systems exist across the organization.</li><li><strong>Document data flows</strong>: Understand what data AI models access, store, and generate.</li><li><strong>Automate compliance evidence</strong>: Use intelligent DLP and classification to track sensitive data, AI usage and risk posture in real time.</li><li><strong>Stay adaptive</strong>: Treat each state/local law as a building block toward a unified, responsible AI governance model.</li></ol><h3>Mind what matters</h3><p>Regulation will continue to evolve at the federal and state levels, along with being contested in the legal system, but readiness doesn’t have to wait. MIND helps organizations stay ahead of AI-driven data risk with intelligent discovery, automated policy enforcement and real-time compliance visibility.</p><p>As AI transforms how we work, <strong>MIND ensures your organization stays compliant, secure and confident, automatically.</strong></p><p><strong>Ready to prepare for 2026?</strong> Let’s turn compliance complexity into clarity.</p><p><a href="https://mind.io/demo">Request a demo at mind.io</a></p>]]></description>
            <link>https://mind.io/blog/what-upcoming-ai-security-regulations-should-you-be-aware-of</link>
            <guid isPermaLink="true">https://mind.io/blog/what-upcoming-ai-security-regulations-should-you-be-aware-of</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Thu, 11 Dec 2025 11:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/2adb841eac1a8ca0af2a889783a31897c60731dd-1920x1080.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[How to protect CUI data and achieve CMMC Level 2 ]]></title>
            <description><![CDATA[<p>In today’s cyber-threat landscape, it’s no longer enough to <em>say</em> you’re protecting sensitive data. For organizations handling controlled unclassified information (CUI), the challenge is real: you must <em>find</em> it, <em>protect</em> it and <em>prove</em> you’ve done so. That’s why, for many defense-industry contractors and service providers, the phrase “CUI compliance” is more than jargon, it’s mission-critical.</p><h3>Why protecting CUI is harder than you think</h3><p>Handling CUI isn’t simply a matter of putting a locked file cabinet around your most sensitive documents. Several factors make it uniquely difficult:</p><ol><li><strong>Visibility is inherently difficult.</strong> CUI must be shared across finance, legal, underwriting, project management and other teams essential to contract delivery. As it spreads across network shares, cloud tools, vendor environments and even generative-AI inputs, visibility fragments quickly. Without a clear, continuously updated inventory of where CUI lives and who touches it, organizations operate with critical blind spots.</li><li><strong>Control is widely distributed.</strong> In government contracting, large groups legitimately need access to CUI to support complex projects. Restricting access to a few individuals isn’t realistic. Instead, we need precise, autonomous controls that govern how CUI moves across devices, identities, networks, clouds and partners, because the data moves and our protections must move with it.</li><li><strong>Proof is now mandatory.</strong> Under frameworks like <a href="https://dodcio.defense.gov/cmmc/About/">CMMC 2.0</a>, organizations must justify why each person needs access, not just rely on project association. The “need-to-know” principle must be enforced and documented. This requires complete auditability: who has access to every piece of CUI, why they have it and how those controls are maintained over time.</li><li><strong>The threat environment has evolved.</strong> Advanced persistent threats, supply-chain attacks, insider risks and real-time exfiltration raise the bar for what effective protection must look like today.</li></ol><p><strong>In short:</strong> you’re dealing with <em>where</em> the data is, <em>who</em> has access, <em>how</em> it’s used and <em>whether</em> you can show you’ve secured it. That complexity demands a modern, holistic approach rather than a checkbox.</p><h3>Why NIST 800-171 Rev. 3 matters</h3><p>CMMC 2.0 Level 2 maps to the 110 controls of NIST SP 800‑171 Rev. 2 framework. For organizations that are subject to it, the latest standard from the National Institute of Standards and Technology (<a href="https://csrc.nist.gov/pubs/sp/800/171/r3/final">NIST SP 800-171 Rev. 3</a>) signals the future of CUI protection. While Rev. 2 remains the enforced baseline for now, Rev. 3 offers insight into the trajectory of expectation.</p><p>Here are some of the key takeaways:</p><ul><li>Rev. 3 <a href="https://redspin.com/white-papers/exposed-the-hidden-changes-in-nist-sp-800-171-rev-3/">aligns the security requirements</a> more closely with the controls of NIST SP 800‑53 Rev. 5 and the moderate baseline of SP 800-53B.</li><li>The number of <a href="https://www.summit7.us/blog/nist-800-171-revision-3">security requirement families expands</a> (with new families like Planning (PL), System &amp; Services Acquisition (SA), Supply Chain Risk Management (SR)).</li><li>The standard introduces <a href="https://dodecacore.com/resources/revision-3/timeline">“organization-defined parameters” (ODPs)</a> so that controls can be tailored, but also demands that to be defined and measurable.</li><li>It removes ambiguity: the older “basic vs derived” categorizations are gone and wording like “periodically” has been eliminated to drive specificity.</li></ul><p><strong>The implication for you:</strong> if you’re already pursuing CMMC Level 2 (i.e., full NIST 800-171 Rev. 2 compliance), you’re on the right path. But Rev. 3 gives you a view into how the standard will evolve and how your controls must evolve to stay ahead.</p><h3>What achieving CMMC Level 2 really means</h3><p>If your organization is working toward or has achieved CMMC 2.0 Level 2, you’ve committed to the full set of NIST 800-171 Rev. 2 controls: 110 security requirements across 14 families. That means not just writing policies, but operationalizing access control, auditing, incident response, configuration management, media protection and more.</p><p>Level 2 certification qualifies you to work with CUI, but it’s not a point of completion. Long-term success depends on your ability to continuously uphold that standard and anticipate future obligations.</p><h3>How MIND helps you bridge the gap, from compliance to continuous assurance</h3><p>This is why organizations turn to autonomous DLP like MIND. We understand the practical challenges CISOs face, securing complex environments amid tight budgets, limited headcount and an evolving threat landscape. Our approach is to deliver Stress-Free DLP and help you mind what matters.</p><ol><li><strong>Discover and classify CUI where it lives<br/></strong>We begin by discovering sensitive information across SaaS apps, on-premise file shares and endpoints. While most organizations have designated and highly controlled environments for CUI, the real risk lies in CUI elements stored outside of these areas. MIND can accurately classify CUI using our multi-layered classification engine and we alert if any CUI is found outside of the controlled storage areas. We classify it using context: who accessed it, where it came from and how it’s used. This ensures that the CUI you’ve contracted to protect is visible and, thus, protectable.</li><li><strong>Enforce policy aligned to your controls<br/></strong>Once CUI is visible, MIND applies controls aligned with your NIST 800-171 requirements: controlling access, enforcing encryption, blocking risky activities, monitoring media transfers, restricting network egress and integrating with identity systems for least-privilege.<br/>For example, you can define policies that block sensitive documents from syncing to unapproved collaboration tools or prompt users when a potential violation occurs, turning the policy into a real-time action.</li><li><strong>Automate audit-ready evidence<br/></strong>Under CMMC Level 2, you must show auditors proof, not just that you <em>wrote</em> policies, but that they <em>work</em>. MIND’s dashboards capture access events, data movement, policy violations and remediation workflows. Your next assessment is no longer a scramble - it’s a status report.</li><li><strong>Continuously validate and improve<br/></strong>Because threats evolve, so must your controls. MIND gives you continuous monitoring, analytics and risk scoring, identifying when a control drifts, when user behavior changes and when a vendor rises in risk. With these insights, you maintain a posture of <em>assurance</em> rather than just <em>compliance</em>.</li><li><strong>Align to where the standard is heading<br/></strong>With NIST 800-171 Rev. 3 on the horizon, your investments today matter. MIND helps you build controls that are not just “enough for today’s audit” but scalable for tomorrow’s requirements, supply-chain risk management, planning controls, acquisition controls and measurable organization-defined parameters. You’re ready when the standard shifts.</li></ol><h3>Why this matters</h3><p>Contractors in the defense supply chain are under increasing scrutiny. With major national security implications, the U.S. government expects non-federal systems processing CUI to meet robust standards. Failing to secure CUI isn’t just a regulatory issue; it puts your reputation, business and the mission at risk.</p><p>When you bring visibility, enforcement and proof together, you shift from a “compliance firewall” to a strategic data-protection posture. That’s what MIND helps you achieve.</p><h3>Final thought</h3><p>CUI is more than just secrets; protecting it helps ensure the integrity of the mission. Meeting NIST SP 800‑171 Rev. 3 (and by extension CMMC 2.0 Level 2 today) is more than a tick-box. It’s about transforming how you view, control and prove the protection of your most important data. With MIND, you can move from “we hope it’s protected” to “we know it’s protected.”</p><p>If you’re ready to move from reactive checklists to proactive assurance, and to ensure your CUI is truly under control, let’s talk. Because when you mind what matters, compliance becomes confidence.</p>]]></description>
            <link>https://mind.io/blog/how-to-protect-cui-data-and-achieve-cmmc-level-2</link>
            <guid isPermaLink="true">https://mind.io/blog/how-to-protect-cui-data-and-achieve-cmmc-level-2</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 10 Dec 2025 22:39:54 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/942d71915341198f2269ceaede0befe4ad597ff0-1920x1080.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Upcoming AI Security Regulations You Need to Be Aware Of]]></title>
            <description><![CDATA[<h2>Staying ahead of the curve in a rapidly changing compliance landscape is tough and new AI regulations can make it challenging to do business.</h2><p>Artificial intelligence is no longer a future concern, it’s today’s governance challenge. As AI systems become more deeply embedded in business operations, regulators across the United States are racing to establish frameworks that protect individuals, ensure fairness and preserve trust.</p><p>For security leaders, that means one thing: compliance complexity is about to grow.</p><p>Below, we’ve outlined the key <strong>AI security and privacy laws</strong> coming into effect in <strong>2026</strong>, broken down by geography. Knowing what’s ahead gives you a head start on preparation and helps you mind what matters before enforcement begins.</p><h3>Federal Outlook: The Framework Phase</h3><p>At the national level, the U.S. has yet to enact a comprehensive AI or privacy law with a firm 2026 start date. Instead, we’re seeing guidance, frameworks and executive actions that pave the way for future regulation.</p><p><strong>What to watch:</strong></p><ul><li><strong>The White House Executive Order on Safe, Secure, and Trustworthy AI (2023)</strong> continues to influence agency rule-making and standards.</li><li><strong>NIST AI Risk Management Framework (RMF)</strong> is becoming the de facto baseline for responsible AI practices. Expect increasing pressure for organizations to demonstrate RMF alignment during audits and vendor reviews.</li><li><strong>Federal agencies</strong> including the FTC, EEOC and CFPB have all issued warnings on AI bias, consumer protection and data handling, signals of stronger enforcement to come.</li></ul><h5><strong>The takeaway</strong></h5><p>Federal law isn’t here yet, but accountability already is. Companies deploying AI must treat these frameworks as compliance prerequisites, not suggestions.</p><h3>State-Level Regulations: The New Front Lines</h3><p>States are leading the charge, each introducing distinct laws to govern AI development, deployment, and data use. Here are the most significant to watch in 2026:</p><h5><strong>Colorado – The Colorado AI Act (SB 205)</strong></h5><p><strong>Effective:</strong> February 1, 2026Colorado became the first state to pass a comprehensive AI accountability law. It defines “high-risk” AI systems and requires:</p><ul><li>Impact assessments for systems influencing employment, education, finance, or healthcare</li><li>Transparency disclosures to users</li><li>Risk mitigation and bias monitoring obligations for developers and deployers</li></ul><h5><strong>California – The AI Transparency Act (SB 942)</strong></h5><p><strong>Effective:</strong> January 1, 2026California expands its privacy leadership into AI. The new law mandates:</p><ul><li>Clear notice when consumers interact with AI systems</li><li>Documentation of AI functionality and data sources</li><li>Disclosure requirements for generative and conversational AI platforms</li></ul><h5><strong>Texas – The Responsible AI Governance Act (TRAIGA)</strong></h5><p><strong>Effective:</strong> January 2026Texas focuses on accountability and governance, requiring:</p><ul><li>Documented AI lifecycle management</li><li>Red-teaming, transparency reporting, and oversight for “high-impact” systems</li><li>Annual internal reviews to validate compliance</li></ul><h5><strong>New York State – The Responsible AI Safety and Education (RAISE) Act</strong></h5><p><strong>Effective:</strong> January 1, 2026This bill targets “frontier” or “high-risk” AI models that could influence safety, financial systems, or civic operations. It introduces:</p><ul><li>Independent audits and incident reporting</li><li>Safety plans and documentation of model intent</li><li>Public transparency reports for large AI developers</li></ul><h3>Local & Municipal: New York City Leads the Way</h3><h5><strong>NYC Local Law 144 – Automated Employment Decision Tools</strong></h5><p><strong>In effect since 2023, continuing enforcement into 2026</strong>This law regulates the use of automated hiring and promotion tools. It requires organizations to:</p><ul><li>Conduct independent bias audits annually</li><li>Notify candidates and employees when AI tools are used in decision-making</li><li>Publish summaries of audit results for transparency</li></ul><p>While not new, its continued enforcement and the expansion of similar policies in other cities marks a pivotal shift: municipalities are no longer waiting for federal action.</p><h5><strong>What’s next:</strong></h5><p>The <strong>NYC AI Action Plan</strong> (2023) sets the stage for additional oversight of how city agencies and contractors deploy AI, establishing a framework other municipalities are likely to follow by 2026.</p><h3>Why This Matters: AI, Privacy and Data Security Converge</h3><p>Even if your organization is not headquartered in one of these jurisdictional areas, it is likely that if your company does any business there, these rules will apply to you. This means most of these rules and guidelines will be applicable to most organizations.</p><p>Every one of these laws ties back to a shared principle: <strong>AI systems can’t be trusted unless data is protected, traceable and governed intelligently. </strong>For CISOs, compliance officers, and data protection teams, 2026 isn’t just about checking regulatory boxes, it’s about building defensible systems that demonstrate control.</p><p><strong>What leaders should do now:</strong></p><ol><li><strong>Map your AI footprint</strong>: Know where AI systems exist across the organization.</li><li><strong>Document data flows</strong>: Understand what data AI models access, store and generate.</li><li><strong>Automate compliance evidence</strong>: Use intelligent DLP and classification to track sensitive data, AI usage and risk posture in real time.</li></ol><p><strong>Stay adaptive</strong>: Treat each state law as a building block toward a unified, responsible AI governance model.</p><h3>MIND What Matters</h3><p>Regulation will continue to evolve, but readiness doesn’t have to wait. MIND helps organizations stay ahead of AI-driven data risk with intelligent discovery, automated policy enforcement and real-time compliance visibility.</p><p>As AI transforms how we work, <strong>MIND ensures your organization stays compliant, secure and confident, automatically.</strong></p><p><strong>Ready to prepare for 2026?</strong> Let’s turn compliance complexity into clarity.</p><p><a href="https://mind.io/[object Object]">{children}</a>.</p>]]></description>
            <link>https://mind.io/blog/upcoming-ai-security-regulations-you-need-to-be-aware-of</link>
            <guid isPermaLink="true">https://mind.io/blog/upcoming-ai-security-regulations-you-need-to-be-aware-of</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 26 Nov 2025 20:13:45 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/26c35cba06f01d6ae9dc772004ede859de4af2ed-1024x1024.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Classification done right: The key to scalable, accurate data protection]]></title>
            <description><![CDATA[<h2>Classification isn't just a DLP step, it's the technical foundation for secure, scalable and context-aware data protection.</h2><p><em>Classification Blog Series</em></p><ol><li><strong><em>Classification done right: The key to scalable, effective data security</em></strong></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li><li><a href="https://mind.io/blog/[object Object]">{children}</a></li></ol><p>Classification is the practice of identifying and categorizing different types of data across an organization. This includes understanding what the data is, how it is used, where it resides and how sensitive it is. Done well, classification provides a reliable foundation for enforcing security policies, enabling data governance and reducing risk exposure.</p><p>Despite its importance, many organizations still lack a clear view of their data because their classification strategies are incomplete or overly reliant on narrow techniques. True classification must scale across environments and data types, adapting to both context and risk.</p><p>This isn’t about labeling a few files, it’s about building a consistent, organization-wide view of your data landscape, so you can take informed action to protect what matters most.</p><p>This piece breaks down the primary classification methods used in data security today and explains how MIND&#x27;s Multi-Layer Classification approach categorizes and protects sensitive data across all environments.</p><h3>Why do organizations need accurate classification?</h3><p>Without accurate classification, DLP breaks down. A single mis-classification can set off a cascade of failures: a confidential file goes unflagged, an alert never fires, a user shares it externally and no one knows until it’s too late. Every policy, alert and enforcement action depends on it.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/b712552077408dc31f0a8f1bb2c62756538d69b0-2410x646.png?w=500" /><h3>How do you find sensitive data?</h3><p>Before data can be classified, it needs to be extracted, transformed and loaded (ETL) into a classification workflow.</p><p>Two common approaches dominate this phase:</p><ol><li><strong>Sampling</strong><br/>Sampling takes a lighter-touch approach. It looks at <em>a subset of files</em> and often just <em>portions</em> of a file. This reduces workload, but it also reduces visibility, creating blindspots that allow sensitive data to slip through undetected.</li><li><strong>Bit-by-Bit Scanning</strong><br/>This method processes <strong><strong><em>every file</em></strong></strong> in a given location, scanning each one in full. It’s accurate and thorough, but can be slower, resource-intensive and often impractical for modern environments or endpoints.</li></ol><p>Most vendors pick one path or the other.</p><h3>How is sensitive data classified?</h3><p>After ETL, data is analyzed and classified using one or more techniques. These typically fall into three categories:</p><h5>Rule-Based Techniques</h5><p>These rely on known patterns and human-defined rules.</p><ul><li><strong>Regular Expressions (RegEx):</strong> Detect known formats like SSNs or credit card numbers</li><li><strong>EDM (Exact Data Matching):</strong> Match against predefined values (e.g., a list of patient IDs)</li><li><strong>Policy-Based Classification:</strong> Use logic rules or boolean conditions to label content</li></ul><p><strong>Strength:</strong> High precision on known formats<br/><strong>Weakness:</strong> Easily bypassed, brittle, high false positives</p><h5>Statistical &amp; Probabilistic Techniques</h5><p>These methods use math to infer likelihoods.</p><ul><li><strong>Statistical Analysis:</strong> Estimate the probability that content belongs to a given category</li><li><strong>Predictive Models:</strong> Apply statistical features and learned behaviors to new data</li><li><strong>Hashing &amp; Signature Matching:</strong> Check against known sensitive data fingerprints</li></ul><p><strong>Strength:</strong> Useful at scale, can flag novel instances<br/><strong>Weakness:</strong> Can miss nuanced or complex content</p><h5>Semantic &amp; Machine Learning Techniques</h5><p>These systems learn patterns over time or from context.</p><ul><li><strong>Vector Similarity (Categorization):</strong> Compare content to known examples via embeddings</li><li><strong>Machine Learning:</strong> Classify content based on trained models using labeled data</li><li><strong>SLMs/LLMs (Language Models):</strong> Understand data based on meaning, not just metadata</li></ul><p><strong>Strength:</strong> Adaptive, powerful on unstructured data<br/><strong>Weakness:</strong> Often expensive, opaque, and hard to tune</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/66031c77b6bb4a036b98996d7dfd59bb45dde1f8-2410x1054.png?w=500" /><h3>The problem with most vendors</h3><p>Most classification engines today suffer from the same issue: they rely too heavily on <strong>a single method</strong> or <strong>rigid sequences</strong> for analysis.</p><ul><li>DSPM vendors lean heavily into visibility, but rarely go beyond structured data found in spreadsheets. For classification, they tend to rely on LLMs that do not scale and suffer from inconsistent results when asked the same question multiple times. These scale issues require them to default to a data sampling approach, limiting their effectiveness.</li><li>Traditional DLP vendors rely on RegEx and rules, which has significant manual effort and staffing overhead. These techniques fail to interpret the intent or context behind the data which generate an enormous amount of false positive alerts. Some bolt on machine learning, but lack the architecture to apply it at scale, in context, or in real-time.</li></ul><p>The result? Security teams get fragmented, inconsistent signals. Sensitive data goes undetected. Alerts pile up. And nobody trusts the output.</p><p>Classification, done poorly, becomes just another checkbox without delivering real security value.</p><h3>The MIND approach: Multi-layered, context-aware, scalable</h3><p>MIND reimagines classification from the ground up. It uses a <strong>multi-layered engine</strong> that applies the right technique in the right context, guided by <strong>environmental signals and risk posture</strong>.</p><p>MIND’s Differentiators:</p><ul><li><strong>Risk-First Ingestion Strategy:</strong> MIND uses a bit-by-bit, full-file scanning approach that targets the sensitive data locations with the highest risk to the organization.</li><li><strong>Proprietary AI Models:</strong> MIND doesn’t outsource classification to public LLMs. We&#x27;ve built dozens of tailor-made <strong>Large &amp;</strong> <strong>Small Language Models</strong> for the specific tasks required. This approach scales with your environment and understands the nuance of enterprise data</li><li><strong>Multi-Modal Analysis:</strong> Where it makes sense, we combine our proprietary trained LLMs, SLMs, EDM, RegEx pattern matching, statistical tests, vector similarity and proprietary ML for high-fidelity classification</li><li><strong>Beyond Structured Data:</strong> MIND is file type agnostic, allowing us to classify sensitive elements found in images, archives, documents, and rich media, not just .csvs and databases</li><li><strong>Autonomous Categorization:</strong> Instead of tagging individual data points, MIND categorizes entire datasets by meaning, usage, format and location, enabling policy by <em>category</em> (e.g., “PII in HR Reports shared externally”)</li></ul><h3>Why it matters</h3><p>With a layered classification engine that scales across cloud, endpoint, on-premise file shares, email and GenAI apps, MIND reduces false positives, enhances the effectiveness of automated controls and builds lasting confidence in the integrity of data security workflows.</p><p>Instead of focusing on isolated identifiers like Social Security Numbers, MIND identifies entire <strong>categories of risk</strong> such as &quot;regulated data shared in collaborative tools&quot; or &quot;sensitive contracts accessed by third parties.&quot;</p><p>When classification is done right, everything downstream, from detection to response, becomes more accurate, scalable and effective. That’s the argument we opened with, and it holds true across any environment, industry or data type. MIND’s layered, risk-aware classification engine was built to meet that standard.</p><p>If you&#x27;re evaluating how to improve fidelity, coverage and automation in your data protection program, our team is available to explore how this approach fits your environment.</p>]]></description>
            <link>https://mind.io/blog/how-to-classify-sensitive-data</link>
            <guid isPermaLink="true">https://mind.io/blog/how-to-classify-sensitive-data</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Thu, 23 Oct 2025 17:44:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/764d5b25eca7d46d893c58d1c6c17a9149e84696-7680x4320.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[MIND upgrades endpoint DLP (and more!)]]></title>
            <description><![CDATA[<p><em>MIND Flight 1021 with service to Stress-Free DLP is now boarding. All ticketed and confirmed passengers should make their way to the boarding gate at this time.</em></p><p>The airport hums with noise. Rolling suitcases bump over tile floors, boarding announcements echo through speakers and the line at TSA snakes endlessly ahead. You shift your weight from one foot to the other, clutching your laptop bag and thinking about all the places your data could be exposed. Every checkpoint feels like another manual and tedious friction point. But this trip is necessary. You’re heading to <strong>Stress-Free DLP</strong>, and it’s a journey worth taking.</p><p>You know you need to get on the plane, but it’s a long flight and it would be nice if the travel experience could be better somehow. You check your phone again, just to see. Maybe, this time, there’s an upgrade.</p><p>Then it happens. The notification lights up your screen. You refresh your airline app and the tension you didn&#x27;t fully realize you were carrying eases as your hopes come true. </p><img src="https://cdn.sanity.io/images/3l9nidp2/production/f1453c5b855885eb859fab440dc630a0f3317dd3-1039x693.png?w=500" /><p>The terminal noise fades. You walk to the gate with a lighter step, a new boarding pass pulled up on your device, ready for a different kind of experience.</p><p>You settle into your seat. The cabin lighting is soft, the hum of the engines low. A favorite beverage appears as if by instinct. The seat is plush and comfortable, the world quiets and for the first time in a long time, you exhale. It&#x27;s amazing how one upgrade can change the entire tone of your experience. Everything feels calm, effortless and under control. This is how travel was meant to be.</p><p>That’s the feeling you get as MIND upgrades your seat to Business Class on your journey to Stress-Free DLP.</p><h3>Welcome to Business Class</h3><p>In the enterprise today, the endpoint is where work happens, and where risk often begins. Endpoint DLP has been clunky, hard to manage and intrusive. More like a middle seat somewhere towards the back of the plane, with neighbors who don’t share the armrest.</p><p>That’s why MIND reimagined endpoint protection from the ground up, delivering clarity, control and confidence at every altitude. This is more than a seat upgrade, it’s how Endpoint DLP should be. Smooth, efficient and designed to actually protect sensitive data without compromising the user experience. </p><p>Now you can have an upgraded way to provide DLP on your endpoints, one that is like an upgrade to Business Class from that middle seat in the back.</p><h5>Let’s prepare for takeoff</h5><p>The boarding doors are closed, the pilots have finished their pre-flight safety checks and we&#x27;re getting ready to push back from the gate. Now is a good time to take a deeper dive into the specific elements that MIND is releasing into our platform.</p><h3>Upgraded endpoint DLP</h3><p>MIND’s endpoint expansion brings enhanced controls to its unified platform. As the most immediate and active touchpoint for sensitive data, the endpoint plays a pivotal role in the data security lifecycle. This upgrade brings some new and advanced features to the MIND endpoint agent.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/a4a2c82a2cb57f79828f1c8ca628cbdee7c3cc7e-7204x4320.png?w=500" /><ul><li><strong>Full Data Lineage:</strong> Follow each file’s complete travel itinerary across every device and destination, ensuring sensitive data never deviates from its approved flight plan or ignores Air Traffic Control directions.</li><li><strong>Native App Protection:</strong> Keep data secure within locally installed applications, providing peace of mind and seamless protection for critical leak vectors without disrupting the work journey.</li><li><strong>USB and Peripheral Controls:</strong> Enforce limits on what’s carried on and off your endpoint, ensuring no sensitive information leaves the environment without the proper clearance.</li><li><strong>Evidence Collection:</strong> Just like a plane selfie, now you can record key moments during every trip, capturing user actions, file movement and screenshots to ensure accountability and investigation readiness.</li></ul><h3>Key enterprise application integrations</h3><p>The ground crew loads fuel, checks systems and stocks the cabin and MIND connects to the critical systems that power modern business. These integrations unify visibility, synchronize identity and data controls and ensure every system is fully prepared for flight, keeping your journey to Stress-Free DLP smooth and uninterrupted.</p><h5>Okta integration</h5><p>Integrating identity signals from Okta allows MIND to align users and data with precise security policies, ensuring protection always follows the person, not just the device.</p><p>Security teams can now tailor enforcement actions based on user attributes such as department, role, risk level and location, offering precision protection at machine speed and at scale. The solution provides enhanced protection against insider threats by evaluating user context and behavior in tandem with data sensitivity and activity.</p><h5>Salesforce integration</h5><p>MIND discovers, classifies and protects data within Salesforce, reducing risk in one of the most sensitive repositories for customer and business information.</p><h3>Additional classification techniques</h3><p>While turbulence can be unexpected, a seasoned pilot can identify risk based on the weather report. MIND&#x27;s multi-layer AI classification engine discovers, labels and protects sensitive information wherever it travels. From standard identifiers to entirely custom patterns, advanced classification ensures every piece of data is seen, understood and secured before the journey begins.</p><h5>Protected Health Information (PHI)</h5><p>MIND continues to advance the discovery and protection of novel PHI data types across industries, even those beyond healthcare, reducing exposure and helping organizations stay compliant automatically.</p><h5>Passwords</h5><p>Identify and secure stored credentials across your environments, eliminating one of the most overlooked and dangerous forms of data exposure and risk to your systems.</p><h5>Controlled Unclassified Information (CUI)</h5><p>Find and manage CUI from multiple agencies, simplifying compliance and ensuring consistent protection wherever this data appears.</p><p></p><h3>Remediation options</h3><p>When exposure is detected, swift and intelligent response is critical. MIND automates remediation to contain risk immediately, correcting permissions, labeling data and securing files before leaks occur. These features ensure that protection systems respond instantly, keeping sensitive data safely within policy.</p><h5>Microsoft Information Protection (MIP) Labels</h5><p>Write and read Microsoft sensitivity labels directly on files, strengthening integration with Microsoft’s native data protection tools.</p><h5>Google Data Security Tags</h5><p>Read/write Google-native security tags for better enforcement within Workspace environments.<br/></p><h5>Auto-adjust file permissions</h5><p>Modify or revoke permissions, or delete files entirely, through automated actions that prevent data exposure before it happens.</p><p></p><p>All together, these capabilities expand MIND’s capabilities to secure your data journey, empowering organizations to navigate complex, multi-cloud environments without turbulence or friction.</p><h3>A new paradigm of data security</h3><p>We will be taking off shortly for our non-stop flight to <strong>Stress-Free DLP</strong>, where data security runs smoothly, automation does the heavy lifting and your team can focus on what matters most.</p><p>The future of DLP isn’t about control, it’s about confidence. It’s about giving teams freedom to collaborate, innovate and move fast, knowing protection travels with them. While other DLP and data security solutions detect and alert. MIND learns, acts and automates. Every policy is context-aware. Every enforcement is intelligent. Every outcome is intentional.</p><p>Welcome aboard! Sit back, relax and enjoy your flight. </p><p>You’ve been upgraded to Business Class.</p><p><br/></p><h3>Check in for your upcoming flight!</h3><p>We will be sharing even more product release details in this webinar:</p><h5><a href="https://www.brighttalk.com/webcast/20990/655198?utm_source=MINDSecurity&amp;utm_medium=brighttalk&amp;utm_campaign=655198">Reserve your seat on MIND Flight 1021 today!</a></h5><img src="https://cdn.sanity.io/images/3l9nidp2/production/e9b58afc5d25ef849a01aa6a410051cd3ad11ba7-3840x2160.png?w=500" />]]></description>
            <link>https://mind.io/blog/stress-free-endpoint-dlp</link>
            <guid isPermaLink="true">https://mind.io/blog/stress-free-endpoint-dlp</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Tue, 21 Oct 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/d4bed2baf190e3eb89f8bf6dfbba37a80abef421-5760x3240.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Better Together: MIND + Okta to Stop Insider Threats]]></title>
            <description><![CDATA[<h2>Identity and data security have long been treated separately, leaving dangerous gaps</h2><p>Data loss prevention (DLP) has a reputation for being painful. False positive alerts overwhelm teams and lead to alert fatigue, especially with regex-only pattern matching that misses nuanced data types like source code or subscriber IDs. Poorly tuned rules sprawl, policies are brittle and managing them is time-consuming. Even then, coverage gaps abound across SaaS, on-prem file shares, endpoints, emails, GenAI and collaboration tools. Worse, motivated insiders can often bypass traditional DLP with minimal effort.</p><p>The industry needed a new approach to stopping insider threats.</p><p>To address these pain points, we are announcing our integration with <a href="https://www.okta.com/">Okta</a>, the leading independent identity partner. By bringing Okta’s user identity intelligence into the MIND platform, it becomes much harder for malicious or inadvertent insiders to leak sensitive data.</p><p>With this integration, MIND will ingest identity insights directly from Okta’s APIs to supercharge our data security engine, reducing false positives, simplifying brittle rule management and hardening defenses against risky or malicious insiders.</p><p>Together, MIND and Okta are delivering something new: <strong>a smarter, identity-aware approach to data loss prevention.</strong></p><h3>How do identity and data security work together?</h3><p>MIND has long used identity signals to inform and enforce data security. With Okta as the trusted source of truth for user identity, we now provide a new level of detail and precision. Okta bridges security across all your users, apps and APIs, while MIND secures data at rest and in motion, autonomously. Together, we create a powerful foundation for modern security teams: data protection that knows who’s behind every action, and why it matters.</p><p>Here’s what happens when identity and data security work together:</p><ol><li><strong>Data security policies dynamically adapt with identity risk signals<br/></strong>Not all users are created equal, and not all data events deserve the same level of scrutiny. A developer downloading source code may be normal. That same activity by a contractor logging in from an unmanaged device may be a red flag.<br/><br/>With this integration, MIND ingests Okta’s identity context and risk indicators, such as group membership, role, geolocation, device trust and authentication method. Data security policies in MIND can then automatically adjust based on identity risk posture.<br/><br/>That means security teams no longer need to rely on static rules which develop an enormous amount of alert noise and false positives. Instead, they can let the system adapt in real time, ensuring sensitive data stays protected.</li><li><strong>Identity and context-aware data security policies can be enforced<br/></strong>Most DLP solutions look only at the data, what file is being moved, what keyword is inside it, what channel it’s going to. But data alone doesn’t tell the full story.<br/><br/>By combining Okta’s identity insights with MIND AI, policies now consider <em>who</em> is accessing the data,<em> when and where</em> it’s happening and <em>whether it makes sense</em>. This makes enforcement more precise and less disruptive.<br/><br/>For example, if an authenticated employee in the finance group downloads payroll data to a managed laptop, that may be permitted. If the same file is downloaded to a personal device or shared externally, MIND can automatically block, coach the user or escalate for review.<br/><br/>And all of this sensitive data should be prevented from being sent into an unsanctioned GenAI app.<br/><br/>This level of nuance isn’t just smarter security, it’s a better experience for employees who can work without unnecessary friction.</li><li><strong>Risky insiders can be autonomously prevented from leaking sensitive data<br/></strong>Insider risk remains one of the most difficult challenges for security teams. Whether malicious or accidental, users with valid credentials can cause enormous damage if sensitive information leaves the organization.<br/><br/>With MIND + Okta, insider threats are easier to spot and stop. Okta provides the identity signal — a user logging in from an unusual location, elevating privileges, or failing MFA. MIND provides the data signal — an attempt to move large volumes of sensitive files, upload customer records to a GenAI tool, or share source code with an external party.<br/><br/>Together, these signals allow MIND to autonomously prevent high-risk actions. Security teams can enforce progressive controls, from coaching users in real time to fully blocking data exfiltration. The integration ensures that sensitive data stays where it belongs.</li></ol><figure><blockquote><p>“undefined”</p></blockquote><figcaption><cite>Stephen Lee</cite> Vice President of Technical Strategy & Partnerships - Okta</figcaption></figure><h3>What does this mean for security leaders?</h3><p>For today’s security leaders, the mandate is clear: secure the business without slowing it down. But with sprawling data environments and complex identity ecosystems, the task can feel overwhelming.</p><p>MIND is the first-ever autonomous DLP platform. With Okta as the trusted source of truth for user identity, that promise goes even further. This integration removes the guesswork and brings a much finer identity lens, delivering the advanced precision of identity-aware data security policies, the efficiency of automated enforcement and the assurance that insider risks are under control.</p><p>The result is a DLP program that isn’t just reactive, it’s proactive, adaptive, intelligent and far easier to manage.</p><figure><blockquote><p>“undefined”</p></blockquote><figcaption><cite>Julie Chickillo</cite> VP of Information Security - Guild</figcaption></figure><h3>How can you integrate identity and data security?</h3><p>Identity and data security no longer need to be separate. They are two sides of the same coin and combined they can deliver true protection.</p><p>MIND + Okta provides exactly that: a unified approach that helps organizations mind what really matters; their sensitive data, people and reputation.</p><p>Security teams gain:</p><ul><li><strong>Dynamic protection</strong> that adapts policies based on identity risk</li><li><strong>Context-aware enforcement</strong> that reduces false positives and friction</li><li><strong>Autonomous insider risk mitigation</strong> that keeps data safe in real time</li></ul><p>The outcome is peace of mind for CISOs, productivity for employees and resilience for the business.</p><p><a href="https://mind.io/[object Object]">{children}</a></p><img src="https://cdn.sanity.io/images/3l9nidp2/production/260e7742092411d023553587b5602d779eb5379a-3840x2160.png?w=500" /><h3>FAQ</h3><ol><li><strong>How does the Okta MIND integration address coverage gaps?</strong><br/>Legacy DLP relies on regex-only detection, creating volumes of alert noise and false positives. MIND + Okta reduce noise by aligning data alerts with real identity context.</li><li><strong>Why is traditional DLP hard to manage?</strong><br/>Rules are brittle and tuning is painful. With Okta as the source of identity truth, MIND simplifies policies and automates enforcement, easing ongoing management.</li><li><strong>How does this integration address coverage gaps?</strong><br/>MIND extends protection across SaaS, endpoints, on-prem file shares, emails, GenAI and collaboration tools. Okta&#x27;s identity insights ensure consistent coverage across all environments.</li><li><strong>Can insiders still bypass DLP controls?</strong><br/>Traditional DLP is easy to evade. MIND + Okta combine identity and data signals to autonomously block risky actions in real time, preventing sensitive data exfiltration before it happens.</li><li><strong>How does the Okta MIND integration improve user experience?</strong><br/>Instead of blanket blocking, context-aware controls allow safe activity while only interrupting risky behavior. Employees stay productive without constant security roadblocks.</li><li><strong>What about context in DLP policy decisions?</strong><br/>Legacy tools lack awareness of <em>who, what, when, where</em> and <em>why</em>. Okta provides role and authentication data so MIND can enforce smarter, context-rich policies with confidence.</li><li><strong>How does DLP automation help?</strong><br/>MIND automates data discovery, classification, detection, remediation and prevention. Combined with Okta identity and risk context, security teams save hours on manual tasks and focus on high-value risk reduction.</li></ol><h3>Glossary</h3><ul><li><strong>DLP (Data Loss Prevention)</strong><br/>A security strategy and set of tools designed to prevent sensitive data from being leaked, misused or accessed by unauthorized users.</li><li><strong>False Positives</strong><br/>Alerts triggered by DLP systems that flag benign activity as risky, leading to wasted time, alert fatigue and missed true incidents.</li><li><strong>Identity Context</strong><br/>User-specific signals such as role, group membership, authentication method and device trust, which help determine the risk behind a data event.</li><li><strong>Insider Threat</strong><br/>Risk posed by employees, contractors or partners who may intentionally or accidentally leak sensitive data using valid credentials.</li><li><strong>Context-Aware Policies</strong><br/>Data security rules that factor in who is accessing information, why and under what circumstances, rather than relying solely on static keywords or patterns.</li><li><strong>Coverage Gaps</strong><br/>Blind spots in traditional DLP solutions that fail to monitor SaaS apps, endpoints, GenAI tools or collaboration platforms, leaving sensitive data unprotected.</li><li><strong>Stress-Free DLP</strong><br/>MIND’s approach to making data loss prevention simpler to manage, reducing noise, false positives and policy sprawl through automation and identity integration.</li><li><strong>Source of Truth</strong><br/>A reliable system, like Okta for identity, that provides accurate and authoritative data to guide policy enforcement and reduce complexity.</li></ul>]]></description>
            <link>https://mind.io/blog/mind-okta-better-together</link>
            <guid isPermaLink="true">https://mind.io/blog/mind-okta-better-together</guid>
            <dc:creator><![CDATA[Eran Barak]]></dc:creator>
            <pubDate>Tue, 23 Sep 2025 10:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/d48c2df1bef55130aa535e08eba721360b80b935-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why usability is the real growth engine of a SaaS product]]></title>
            <description><![CDATA[<h2>In cybersecurity, more features often mean more friction. By treating simplicity as a feature, we ensure our platform delivers value immediately, builds trust from day one and scales with confidence.</h2><p>In B2B SaaS, especially in cybersecurity, there’s a common instinct to lead with features. You build for technical buyers, prioritize enterprise checklists and assume more capabilities lead to more value.</p><p>But more functionality can sometimes create more friction. Complexity slows adoption and confusing setup leads to the platform becoming shelf-ware. And when users can’t intuitively operate the tools meant to protect them, security risks multiply.</p><p>At MIND, we’ve learned that simplicity isn’t the opposite of advanced features, it’s what unlocks them. A product that delivers immediate value, without onboarding hurdles or lengthy documentation, builds trust from day one. When users can navigate on their own, without relying on specialists or support, they engage more deeply. And that’s when DLP starts to work as intended.</p><p>That’s why we made usability a core product principle, not a polish phase or a post-launch fix. We treat simplicity as a growth-driving feature.</p><h3>What this practically looks like</h3><p>Smart defaults play a key role in delivering early value. Most users never modify settings, so we designed our out-of-the-box experience to serve 80% of use cases with no configuration required. Every decision is shaped by that mindset. Before building anything new, we ask: <em>will this create friction?</em> If the answer is yes, we reconsider. Sometimes we hide complexity behind advanced settings and other times, we eliminate the feature entirely.</p><p>We also know that powerful tools need intuitive access. That’s why our AI assistant exists to bridge the gap between intent and execution. Users can describe what they want in plain language, and the system interprets and responds accordingly. But we don’t rely on AI as a magic solution, it’s grounded in clear logic, fallbacks and controls. We also test relentlessly with real users. If someone gets stuck, confused or slows down, we refine the design. Our goal is always the same: to create clarity without compromise.</p><h3>5 principles we follow at MIND</h3><ol><li><strong>Build for 80%, not 100%</strong><br/>Prioritize the most common use cases. Make sure those users who need that use case succeed quickly. Advanced needs can be served, but they shouldn’t weigh down the experience for everyone else.</li><li><strong>Measure usability like a feature</strong><br/>We track time-to-value. We measure how many customers succeed without changing defaults. We review the volume of support tickets tied to core flows. Usability isn’t subjective, it’s measurable.</li><li><strong>Design around user outcomes, not features</strong><br/>Instead of starting with functionality, we map the journey. What’s the user trying to achieve? How can we reduce steps, friction and context-switching along the way?</li><li><strong>Watch users fail and then fix it</strong><br/>Failures are feedback. We observe users trying to complete tasks. If they stumble, it’s not a user error, it’s a design opportunity.</li><li><strong>AI is powerful, but not magic</strong><br/>It should reduce cognitive load, not introduce new ambiguity. We use it to streamline, guide and educate, without replacing thoughtful design.</li></ol><h3>How does usability impact product adoption and growth?</h3><p>Usability isn’t just about aesthetics, it’s about impact. It drives faster implementation, increases retention and reduces support costs. It amplifies the value of every feature you ship. In fast-moving organizations, this can be the difference between a product that earns trust and one that gets replaced. Customers aren’t asking for more features. They’re asking for fewer obstacles.</p><p>Usability is how you deliver that.</p>]]></description>
            <link>https://mind.io/blog/why-usability-is-the-real-growth-engine-of-a-saas-product</link>
            <guid isPermaLink="true">https://mind.io/blog/why-usability-is-the-real-growth-engine-of-a-saas-product</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Wed, 17 Sep 2025 14:37:28 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/fd4c9493fd44fa29f77e178b6c4ce38b7919c0c7-1096x720.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Product Update: PHI Classification]]></title>
            <description><![CDATA[<p>Protected Health Information (PHI) is some of the most sensitive data an organization can hold, and it’s also some of the most complex to classify. This week, we released new PHI classification capabilities inside the MIND platform, helping our customers detect, distinguish and act on PHI with more clarity and precision than ever before.</p><h3>Why is PHI so difficult to classify?</h3><p>Unlike traditional identifiers like social security numbers or credit card data, PHI is not always a single, standardized field. Instead, PHI is often a combination of personal identifiers and medical context, and that context is everything.</p><ul><li><strong>A name on its own? → PII</strong></li><li><strong>A name with a lab result? → PHI</strong></li></ul><p>That distinction is subtle but critical, especially in regulated industries. Add to that the challenge that PHI can appear across formats and systems: in emails, HR files, shared drives, PDFs, EHR exports and even Slack. And because every healthcare system formats medical record numbers differently, with their own prefixes, lengths and conventions, creating a classifier that works across environments without generating noise is uniquely difficult.</p><p>PHI isn’t just a concern for hospitals or healthcare providers. With this new classification capability, we’re identifying PHI across a wide range of industries, from financial services and insurance to retail and tech. Sensitive health-related data often surfaces in unexpected places, like employee records, support tickets or internal messaging platforms. Our classifier allows organizations to uncover and manage PHI even if they aren’t in a regulated healthcare environment. This means that businesses once unaware of their PHI exposure can now detect it, define policies around it and take action to prevent sensitive health data from leaking or being mishandled.</p><h3>How does MIND help with PHI classification?</h3><p>To address this, we built PHI classification from the ground up by researching how different health systems structure medical record numbers, collecting public datasets and collaborating with customers to understand real-world formats, and training our engine to identify not just keywords but the relationships between personal identifiers and medical data.</p><p>The result is a new PHI classification capability that recognizes medical record numbers, claims data, diagnostic imaging, electronic health records and more with high precision, reduces false positives and gives customers the ability to:</p><ul><li>Differentiate PHI from PII across dashboards and policies</li><li>Filter, detect and act on PHI with more confidence</li><li>Find and monitor PHI across all the environments it may live in</li></ul><p>We also made it easy to build policies specific to PHI, whether to block, alert or educate, and to distinguish PHI exposure events from broader data incidents.</p><p>MIND brings everything together, discovery, classification, policy enforcement and remediation, into one unified platform. That means organizations can define and enforce PHI-specific policies, track issues across systems and respond faster with less effort. No switching tools. No stitching together workflows. Just one clear, automated way to keep sensitive health data safe, everywhere it lives.</p><h3>What's coming next</h3><p>This release is just the beginning. We’re actively expanding our PHI taxonomy to include imaging data, diagnosis codes, billing and claims information and other health-related identifiers required for HIPAA compliance and healthcare workflows.</p><p>With every update, we’re aiming for the same outcome: to help our customers confidently detect and prevent the leakage of sensitive health information, wherever it lives.</p><p>Now you can confidently keep your PHI data safe, no matter where it lives or how it moves.</p>]]></description>
            <link>https://mind.io/blog/product-update-phi-classification</link>
            <guid isPermaLink="true">https://mind.io/blog/product-update-phi-classification</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Tue, 09 Sep 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/e4d7dbbc729162e9a3053e894c7aa2c487c996db-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The pressure to stay silent: A growing risk to cybersecurity]]></title>
            <description><![CDATA[<h2>If you’re a CISO reading this, we know the burden is heavy. But here’s what we also know: your voice matters. Your decisions set the tone. And your transparency can change the trajectory for your organization and our industry.</h2><p>There’s a stat that stopped me in my tracks this week. According to a <a href="https://businessinsights.bitdefender.com/research-growing-pressure-hide-cyberattacks?utm_source=chatgpt.com">new Bitdefender survey</a>, nearly <strong>70% of CISOs have felt pressured to cover up a security incident</strong>. Let that sink in.</p><p>Not downplay. Not delay.<br/><strong>Cover up.</strong></p><p>And it’s not theoretical pressure. It’s real. It’s increasing. And it’s becoming institutional.</p><p>This isn’t just a cybersecurity issue. It’s a culture issue. A leadership issue. And if we’re not careful, it could become a systemic failure that undermines every improvement we’ve made in modern security over the last decade.</p><h3>The human cost of silence</h3><p>I had a conversation with Eran Barak, our CEO at MIND, and Landen Brown, our Field CTO, we broke down what this pressure really means for security teams.</p><figure><blockquote><p>“There are so many different ways breaches can happen today... it’s almost impossible to determine how big or small a breach really was.”</p></blockquote><figcaption><cite>Landen Brown</cite> Field CTO - MIND</figcaption></figure><p>He’s right. The complexity of hybrid environments, the expansion of GenAI, the fragmentation of data flows, <strong>it’s never been harder to define the boundaries of an incident</strong>. And in that ambiguity, pressure thrives.</p><p>Executives ask for “more time to validate.”<br/>Legal suggests “it might not be material.”<br/>PR prepares for “minimal disclosure.”</p><p>Meanwhile, the CISO sits in the middle <strong>not only managing risk but absorbing it</strong>.</p><video controls><source src="https://stream.mux.com/7uvqrPLuzjEAATl1fWe00sz01UNX82xmLov01VHMj15TZc.m3u8" type="application/x-mpegURL"></video><h3>Liability is no longer theoretical</h3><p>Let’s be honest. The <a href="https://nationalcioreview.com/articles-insights/information-security/ubers-former-ciso-conviction-upheld-a-warning-for-cybersecurity-leaders/">Uber case changed the conversation</a>.<br/>When a CISO is held personally liable, it becomes clear: <strong>this job can cost you more than your career</strong>.</p><p>Eran put it simply:</p><figure><blockquote><p>“They expect to be protected. But when they see peers held liable... they will try to minimize their risk.”</p></blockquote><figcaption><cite>Eran Barak</cite> Co-Founder & CEO - MIND</figcaption></figure><p>And that’s the quiet part no one wants to say out loud: when your job, your reputation and your legal safety are all on the line, the natural human instinct is to protect yourself. And in that moment, even the most ethical leaders might hesitate.</p><p>That’s not a flaw in character.<br/>That’s a failure of culture.</p><h3>What we’re losing</h3><p>When CISOs are pressured into silence, the cost isn’t just personal. It’s strategic.</p><ul><li>We lose the opportunity to learn</li><li>We lose the trust of regulators</li><li>We lose credibility with our peers, customers and users</li><li>And most dangerously, we lose visibility into patterns that could help prevent the next breach</li></ul><p>Transparency isn’t just about compliance. It’s about progress. It’s about building better systems, faster.</p><h3>What needs to change</h3><ol><li><strong>Organizations must de-risk transparency<br/></strong>Executives can’t expect CISOs to be open while threatening them with liability or career consequences. Boards need to establish <strong>safe reporting frameworks, </strong>not just incident response plans.</li><li><strong>We need to treat breach disclosure like incident medicine<br/></strong>As I mentioned during our discussion, healthcare has long used “sentinel events” to proactively learn from near misses, without blame. Cybersecurity needs the same mindset. <strong>No-fault learning. Cross-functional review. Psychological safety.</strong></li><li><strong>We need tools that give clarity, not chaos<br/></strong>Part of the problem is that most security teams still fly blind during an incident. As Landen pointed out, very few organizations practice <strong>real tabletop exercises or know how to quickly assess impact</strong>. This needs to change.</li></ol><h3>Final thoughts</h3><p>I hope we build a future where <strong>transparency is normalized</strong>, not punished. Where <strong>CISOs aren’t scapegoats</strong>, but strategic advisors. Where <strong>security leaders can speak plainly</strong>, backed by clear policy and strong culture. And where we see incidents not as failures, but as feedback.</p><p>Because when CISOs feel they have to choose between doing what’s right and keeping their job, we all lose.</p><p><strong><em>Security isn’t just about defending systems.<br/>It’s about defending trust.</em></strong></p><p>The moment we start hiding the truth, even for understandable reasons, we risk losing the very thing we’re trying to protect. Let’s not let that happen. Let’s mind what matters.</p>]]></description>
            <link>https://mind.io/blog/the-pressure-to-stay-silent-a-growing-risk-to-cybersecurity</link>
            <guid isPermaLink="true">https://mind.io/blog/the-pressure-to-stay-silent-a-growing-risk-to-cybersecurity</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Fri, 05 Sep 2025 22:16:46 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/cbb88e4d8b9e40c762094eda36c70061606e10a9-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why Salesforce and third-party integrations demand a smarter security lens]]></title>
            <description><![CDATA[<h2>Salesforce is the source of truth for many organizations and it contains highly sensitive data elements. 
But you already knew that! 
Now, we need to secure those elements.</h2><p>When headlines broke about the recent breaches involving Salesforce integrations, many leaders felt a familiar pang of worry: If one of the most trusted platforms in the world can be compromised, what chance do we have?</p><p>The truth is more nuanced. Salesforce itself wasn’t the weak link. The breach happened through third-party integrations, such as Salesloft Drift, that organizations rely on every day to drive sales, marketing and customer success.</p><p>This incident isn’t just about what went wrong. It’s a reminder of what’s at stake, and why protecting data inside Salesforce and its connected ecosystem requires a fresh approach.<br/></p><h3>Salesforce: The beating heart of the business</h3><p>Salesforce isn’t just another SaaS app. It’s where relationships live. Inside Salesforce you’ll find:</p><ul><li>Customer and prospect contact information</li><li>Contracts, proposals and revenue forecasts</li><li>Support case histories and sensitive conversations</li><li>Intellectual property and development life cycles</li></ul><p>It’s the backbone of growth. And it doesn’t exist in isolation.</p><p>Salesforce offers thousands of third-party integrations through its AppExchange. Marketing platforms, sales enablement tools, data enrichment services, collaboration apps – the list goes on. These integrations make Salesforce more powerful, but they also dramatically expand the attack surface.</p><p>Even if Salesloft, the integration that caused the incident in this case, isn’t part of your stack, the broader issue remains: any integration can become the weak link because it has access to sensitive data from Salesforce.</p><h3>What we learned from the incident</h3><p>The <a href="https://www.itpro.com/security/cyber-attacks/warning-issued-to-salesforce-customers-after-hackers-stole-salesloft-drift-data">Salesloft Drift incident</a> exploited OAuth tokens to access Salesforce environments across hundreds of organizations, including well-known names in tech and security. According to <a href="https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/">BleepingComputer</a>, companies like Cloudflare proactively rotated over 100 API tokens after discovering exposure.</p><p>This wasn’t about Salesforce vulnerabilities. It was about attackers abusing the trust placed in a connected application. And while the stolen data was largely business contact details, that information is still sensitive and valuable in the wrong hands.</p><h3>The challenge of securing your data source of record</h3><p>Security teams know this story well:</p><ul><li>Salesforce environments grow complex fast, with countless users, apps and permissions</li><li>Legacy DLP tools drown teams in false positives without context</li><li>Most competitors stop at scanning – they can tell you sensitive data is there, but not prevent it from leaving</li></ul><p>The result? Blind spots that attackers can exploit. Leaders are left asking: How can we empower teams to use Salesforce and its integrations without exposing our most sensitive data?</p><p><br/></p><h3>Knowing isn’t enough. Protection is what matters</h3><p>This is the critical difference. It’s not enough to simply know that sensitive data exists in Salesforce. It should be reasonably assumed that there is a lot of sensitive data elements inside your SFDC instance. Data discovery and classification is just step one. Data must also be protected with policies that work at rest and in motion:</p><ul><li><strong>At rest: </strong>Control exposure inside Salesforce and across integrated apps, ensuring sensitive files and records aren’t over-shared or left accessible.</li><li><strong>In motion:</strong> Enforce policies when data is being shared, exported or synced to connected tools, blocking or remediating risky behaviors before leaks occur.</li></ul><h3>Don't just scan SFDC. Secure it with MIND</h3><p>That’s where MIND stands apart. With MIND’s Salesforce integration, you can:</p><ul><li>Discover and classify sensitive data automatically (customer PII, contracts, credentials, proprietary files)</li><li>Understand context (who has access, what’s being done, how data flows across integrations)</li><li>Protect with policies at rest and in motion (block risky actions, enforce compliance, remediate in real time)</li></ul><p>Instead of stopping at visibility, MIND delivers true protection. We don’t just scan, we safeguard Salesforce and its ecosystem.</p><h3>Stress-Free DLP for SFDC</h3><p>The Salesforce breach was a wake-up call. But it doesn’t need to be a cause for panic. It’s a chance to rethink how we approach security in the systems most critical to business.</p><p>That’s why we’re offering organizations a free Salesforce Risk Assessment:</p><p>✅ Connect MIND directly to your Salesforce environment</p><p>✅ Automatically discover and classify your sensitive data inside Salesforce</p><p>✅ Protect that data with policies at rest and in motion, where it lives and as it moves</p><p>It’s stress-free DLP for Salesforce, built to protect what matters without adding complexity.</p><p>👉 See how it works in your own environment. <a href="https://mind.io/registration/[object Object]">{children}</a></p>]]></description>
            <link>https://mind.io/blog/salesforce-integration-breach</link>
            <guid isPermaLink="true">https://mind.io/blog/salesforce-integration-breach</guid>
            <dc:creator><![CDATA[Samuel Hill]]></dc:creator>
            <pubDate>Wed, 03 Sep 2025 18:31:39 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/01cade3a053d5d03d3e33ceb4206818ba6733a53-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why modern DLP must understand Content and Context to actually work]]></title>
            <description><![CDATA[<h2>You need deep content analysis with contextual intelligence to protect data without disruption.</h2><p>For years, data loss prevention (DLP) relied on a simple assumption: if you could identify content as sensitive, you could stop it from leaking. But in reality, that approach triggered endless false positives, slowed down users and overwhelmed security teams because it relied on manual effort to identify the sensitive content.</p><p>Eventually, content-first models gave way to context-aware tools, those that look at behavior, user identity and destination. This shift reduced noise but created a new blind spot: these tools still didn’t understand the details of whether the data is sensitive or not. </p><p>You need both perspectives to act with precision.</p><h3>Real-world examples</h3><ul><li>Consider a PowerPoint presentation uploaded to Dropbox. Alone, the context tells you little. But content inspection reveals it contains board meeting notes and projected acquisition targets - business-critical intel headed to an unmanaged account.</li><li>Or take an email sent via Outlook. The context suggests low risk - it’s internal. But the attachment includes hundreds of customer tax IDs pulled from an ERP export. The content changes the risk assessment dramatically.</li><li>Then there&#x27;s an engineer committing code to GitHub. Context flags the public repository. Content confirms it includes AWS access keys. That’s a serious policy violation.</li><li>Now imagine the opposite: a flagged document from SharePoint. Context raises alarms. But content analysis reveals it’s just a blank contract template, with no proprietary terms or client data. That’s noise you can silence.</li></ul><h3>Content alone is no longer enough</h3><p>Trying to prevent a data leak by only inspecting the content is an incomplete lens. </p><p>Sensitive content today is varied and complex, often unstructured and includes everything from personally identifiable information like social security numbers, addresses and phone numbers, to payment details such as credit card numbers and bank account information. </p><p>It also covers authentication credentials including usernames, passwords and API keys, as well as intellectual property like source code, product schematics and proprietary research. Legal and regulatory documents, contracts, compliance reports, business-critical communications like board minutes and internal memos, protected health information, and operational assets such as engineering drawings, supply chain data and facility blueprints all fall within the scope.</p><p>This is nuanced. A string of numbers might be a credit card or just placeholder text. A schematic might be core IP, or just a template. Even a benign-looking spreadsheet could hide columns of customer payment details.</p><p>Without understanding content, traditional security systems such as <a href="https://mind.io/blog/[object Object]">{children}</a>, static content filters and rules-based scanners fall short. They fire off alerts without knowing if something truly matters, leaving security teams overwhelmed by noise and missing the threats that count.</p><h3>Context alone falls short too</h3><p>Now flip the scenario. You assume anything leaving Salesforce is high-risk. That’s helpful, but imprecise. What about content shared from Box, or downloads from a Git repository? Are all files from these locations equally sensitive? Definitely not.</p><p>Not all file activity is high-risk. A PDF sent from an HR folder might be a company policy doc, or it might be a resignation letter with salary information and other PII. Context without content is a half-built map.</p><p>Context can help answer: Who moved the file? When did they access it? Did they upload it to Dropbox, email it to a vendor or copy it to a USB drive? Was the user flagged as risky due to recent behavior?</p><p>But without knowing what’s in the file, you’re still guessing. Guesswork leads to inefficiency, alert fatigue and the kind of blind spots that leave gaps in your data protection posture.</p><h3>Content + Context = Confidence</h3><p>At MIND, we believe modern DLP must understand both content and context equally and in concert.</p><p>We go deep on content. Our multi-layer AI classification engine recognizes real-world business data: secrets, financials, PII, contracts, regulatory content and more. We classify sensitive material across document formats, from PDFs and spreadsheets to zip archives and image-based scans.</p><p>We enrich that insight with contextual signals: where the file originated, who interacted with it, whether it was shared externally, sent to a personal email, uploaded to a GenAI app or accessed from an unmanaged device.</p><p>This dual-layer understanding powers a smarter, more intuitive DLP approach. One that:</p><ul><li>Eliminates false positives</li><li>Detects the incidents that matter</li><li>Automates meaningful, risk-aware remediation</li><li>Enables visibility without obstructing productivity</li></ul><h5><strong>Effective DLP isn’t about blocking everything. </strong></h5><h5><strong>It’s about blocking the right things intelligently and automatically.</strong></h5><p>That&#x27;s what MIND delivers.</p>]]></description>
            <link>https://mind.io/blog/dlp-content-and-context</link>
            <guid isPermaLink="true">https://mind.io/blog/dlp-content-and-context</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Mon, 16 Jun 2025 14:52:10 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/76b070dc075534b4d342e1c715a3c272271a4da7-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Posture ≠ Protection]]></title>
            <description><![CDATA[<h2>Posture tools offer visibility, not protection. Security leaders don’t need more alerts, they need action.</h2><p>CSPM, DSPM, ASPM, SSPM, ESPM — the alphabet soup of Security Posture Management (SPM) tools promises visibility into risk. They map misconfigurations, surface exposure paths and highlight policy gaps. That can be useful. But let’s not confuse awareness with action.</p><h5>They don’t block threats.<br/>They don’t enforce controls.<br/>They don’t prevent breaches.</h5><p>SPMs detect, then delegate. A ticket. A Slack alert. An integration call. Protection is someone else’s problem.</p><p>To compensate, many posture tools claim to orchestrate security. They integrate with enforcement tools like DLP, CWPP, EDR and WAF. But wiring systems together doesn’t make the system secure.</p><h5>Coordination ≠ Protection<br/>Visibility ≠ Control<br/>Monitoring ≠ Security</h5><h3>So why is there an abundance of SPM vendors?</h3><p>Because posture is easier.</p><ul><li><strong>Easier to build.</strong> Cloud-only, read-only, event-driven. No need to support endpoints, on-prem, hybrid or inline enforcement. Just scan, analyze, alert.</li><li><strong>Easier to sell. </strong>No rip-and-replace. Posture tools bolt onto the existing stack, not replace it. That also means customers end up managing yet another vendor, another dashboard, another integration.</li><li><strong>Easier to adopt.</strong> No agents, low friction, fast time-to-value. Good enough to show progress, but not strong enough to stop attacks.</li></ul><p>Yes, posture matters. But let’s not mistake issue tracking for actual security.</p><p>Security requires action — not just awareness.</p><h3>False confidence, real consequences</h3><p>There’s an illusion of progress that posture tools can create. Dashboards look active. Tickets are assigned. Metrics suggest movement. But beneath that layer of perceived control, many organizations remain dangerously exposed.</p><p>In fact, <a href="https://mind.io/registration/[object Object]">{children}</a>. Visibility alone isn’t moving the needle—security teams are still drowning in noise while real risks slip through. That&#x27;s the difference between knowing something&#x27;s wrong and doing something about it.</p><p>It’s why so many breaches still happen in environments that were “monitored.” The problem wasn’t a lack of alerts, it was the inability to respond in time.</p><p>And the results? Stolen IP. Leaked customer records. Compliance violations. Brand damage. Leadership churn.</p><p>The stakes aren’t theoretical. And yet too many teams are trapped in a cycle of detection without defense.</p><h3>It’s time to rethink what protection means</h3><p>The right approach isn’t a patchwork of posture tools and point integrations. It’s a unified system — deep within a specific domain — that doesn’t just highlight problems but solves them in real time.</p><p>Whether you’re focused on data, identities or assets, true security means:</p><ul><li><strong>Continuous classification</strong> of what’s sensitive: Modern DLP starts by building a living inventory of sensitive data — constantly discovering and labeling information across SaaS apps, endpoints, on-premise file shares and emails. It ensures you always know what you&#x27;re protecting, even as your data changes and moves.</li><li><strong>Real-time monitoring</strong> of how it’s accessed and shared: Visibility into who’s touching your data, when, and how allows security teams to identify risky behavior instantly — not after the fact. This creates accountability and supports both proactive defense and forensic insight.</li><li><strong>Contextual enforcement</strong> that prevents misuse: It’s not enough to just watch. Real-time protection at the endpoint means applying intelligent controls based on business context — blocking or coaching users when behavior looks risky, not just flagging it.</li><li><strong>Automated remediation</strong> that closes the loop: When policies are violated, MIND acts. From revoking access and deleting shared links to educating users in near real time, the loop is closed automatically — without requiring tickets, escalations or delays.</li></ul><p>This isn’t a wishlist. This is what modern DLP — done right — can and should deliver.</p><h3>Enter MIND: Posture & Prevention</h3><p>That’s what MIND was built to do.</p><p>MIND combines the context-aware insights of DSPM (posture) with the automated enforcement of modern DLP (prevention).</p><p>We help security teams move beyond alert fatigue to actual control. Beyond passive monitoring to meaningful action. Beyond fractured tools to full-spectrum protection.</p><p>Our AI-powered classification engine understands your data in context—whether it’s source code, contracts, financial records, credentials, passwords, or PII. And it enforces your policies wherever data lives: SaaS and Gen AI apps, endpoints, on-premise file shares, emails and beyond.</p><h5>We don’t just surface issues. We solve them.<br/>We don’t just map risks. We mitigate them.<br/>We don’t just warn you. We stop the leaks.</h5><img src="https://cdn.sanity.io/images/3l9nidp2/production/4b4c41a244b3484dfea3b45994791885a0e8ee67-1620x2025.png?w=500" /><p>Security leaders are overburdened, not underinformed. With limited resources, increasing complexity and high expectations, they need solutions that deliver results, not just more dashboards.</p><p>Stop scanning. Start securing.</p><h5>Mind What Matters.</h5>]]></description>
            <link>https://mind.io/blog/posture-protection</link>
            <guid isPermaLink="true">https://mind.io/blog/posture-protection</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Tue, 03 Jun 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/4c8d0bc5aeb190580207f02a6c2ae325ac94caf7-2198x1528.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Innovation in DLP: Rewriting the rules to mind what matters]]></title>
            <description><![CDATA[<p>Security leaders want confidence – not just in their tools, but in their ability to protect sensitive data, support business innovation and respond swiftly when risk arises. They want full visibility into their data landscape, clarity about what data is at risk and assurance that their security measures are both intelligent and adaptive. But they’re held back. By outdated tools that drown teams in false positives. By policies that are hard to tune and harder to trust. And by processes so brittle they slow innovation instead of supporting it. The desire to modernize is clear, but the path has been clouded by complexity, noise and inefficiency.</p><p>But something is shifting. According to <a href="https://mind.io/registration/[object Object]">{children}</a>, 60% of organizations say innovation in the category is “excellent.” Security teams are no longer settling for complexity disguised as control; they’re rethinking how DLP should work. They want more clarity. More intelligence. More confidence.</p><p>And they’re finding it in platforms like MIND.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/3525e383290cfb4c0a5b7a34344f4ff195ad47ec-2938x1654.png?w=500" /><h3>The DLP dilemma</h3><p>Let’s get specific: modern security leaders face a massive volume of unstructured data across SaaS, Gen AI, endpoints and emails. Their DLP alerts? More than 90% go unremediated or ignored. And nearly half are false positives.</p><p>That creates three critical problems:</p><ul><li><strong>Teams are overwhelmed.</strong> Manual workflows and redundant tools sap resources that could be better spent.</li><li><strong>Security is reactive.</strong> Most incidents are addressed after the damage is done.</li><li><strong>Innovation stalls.</strong> Teams are afraid to enforce policies that might block productivity or trigger alert fatigue.</li></ul><p>The result? An industry trapped in a compliance checkbox, not empowered to deliver real security outcomes.</p><h3>Today's data security needs intelligent, automated DLP</h3><p>Where traditional DLP ends, MIND begins. As the first complete data security platform – built from the ground up – to automatically discover, fix and prevent data leaks, MIND is designed for how data actually moves today.</p><p>Our approach combines posture management and real-time prevention in one unified platform. It&#x27;s a holistic approach that redefines how data protection should operate in modern environments. MIND&#x27;s data protection starts by discovering sensitive data, then classifying and protecting it using AI. It evaluates risks and triggers actions to prevent potential leaks and monitors data in use to ensure real-time protection. This layered approach safeguards sensitive information at rest, in motion and in use.</p><p>This end-to-end model allows teams to fix what matters and protect what’s next.</p><p>Rather than react to alerts, MIND helps organizations proactively understand what sensitive data they have, where it lives and who has access. That’s Posture, and MIND helps to remediate the sensitive data at rest. From there, we apply smart policies to prevent leaks as they happen, in motion and in use – without disrupting the business. That’s Prevention.</p><h3>From friction to flow</h3><p>OpenWeb and Noname Security are just two examples of companies that made the leap from legacy to modern DLP with MIND.</p><p>For OpenWeb, a digital community platform handling data from over 100 million users monthly, traditional DLP was a black hole of alert fatigue. MIND helped them reduce DLP resource allocation by 80% and eliminate false positives almost entirely.</p><figure><blockquote><p>“We’re definitely saving a lot of time not looking at irrelevant data and false positives. Resource-wise, probably a fifth of the time we spent managing our DLP program in the past.”</p></blockquote><figcaption><cite>Yaron Blachman</cite> CISO at OpenWeb</figcaption></figure><p>At Noname, a leader in API security, DLP alerts had become background noise. Their security team was numb to constant false alarms. After switching to MIND, they gained accuracy, context and control, cutting incident response time in half.</p><figure><blockquote><p>“MIND was a lot more accurate and I can't remember a single case where we had false positives.”</p></blockquote><figcaption><cite>Mike Morrato</cite> CISO & Global Head of IT at Noname Security</figcaption></figure><p>What’s consistent in both cases? Clarity. Confidence. And security that scales without slowing anything down.</p><h3>The future is context-aware</h3><p>The future of DLP must include fewer alerts. That’s why 91% of organizations say reducing alert noise is their top priority – and why 43% are prioritizing AI/ML-powered <a href="https://mind.io/">{children}</a> in their next investment cycle. It’s clear that the key to reducing is by embracing tools that understand the sensitive data you’re trying to protect and provide the right context about it.</p><h3>MIND is leading that charge</h3><p><a href="https://mind.io/product/mind-ai">{children}</a>, our multi-layer AI classification engine, goes way beyond regular expression (RegEx) pattern matching. It understands context, differentiating between valid and inactive AWS keys, a source code file and a spreadsheet template. Only MIND AI can uniquely categorize sensitive file types (e.g. agreements, configuration files, scripts, board minutes, medical records, bank statements, contracts, tax forms, payroll reports and so much more) and classify specific sensitive records within those files (e.g. PCI, PII, PHI, credit card numbers, social security numbers, cloud keys, credentials, etc.). That’s how we enable real-time policy enforcement without disrupting work.</p><p>And by putting DLP on autopilot, MIND frees teams to focus on higher priorities, not endless manual triage.</p><h3>MIND: Built for what’s next</h3><p>Our mission is to help digital organizations thrive in this AI era. That means helping them innovate securely. Collaborate safely. And move fast without compromising data protection. We believe DLP shouldn’t be a barrier to innovation – it should be the engine that drives it forward.</p><p>With MIND, security leaders don’t just manage risk. They understand it. They fix it. And they prevent it before it becomes a problem.</p><p>Because when you mind what matters, the rest falls into place.</p><p>Read <a href="https://mind.io/registration/[object Object]">{children}</a> to understand the DLP innovations security leaders are demanding and looking forward to.</p><p>Ready to reimagine DLP? <a href="https://mind.io/[object Object]">{children}</a> and see how effortless data security can be.</p>]]></description>
            <link>https://mind.io/blog/innovation-in-dlp-rewriting-the-rules-to-mind-what-matters</link>
            <guid isPermaLink="true">https://mind.io/blog/innovation-in-dlp-rewriting-the-rules-to-mind-what-matters</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Wed, 23 Apr 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/0898a656f21b9537bc59582a8b12d920c1741c50-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[You’re not alone: 78% of companies also struggle with their DLP]]></title>
            <description><![CDATA[<h2>Why conventional DLP is broken – and what a better way looks like</h2><p>Modern security teams are overworked, under-resourced and constantly playing catch-up. Despite the best intentions – and budgets – data loss prevention (DLP) tools are falling short. And not just by a little.</p><p>According to <a href="https://mind.io/registration/[object Object]">{children}</a>, a staggering <strong>78% of organizations say it&#x27;s challenging to administer and maintain their existing DLP solutions</strong>​. These are seasoned teams. Smart professionals. But the tools they’ve been given are outdated, fragmented and frustrating.</p><p>So if you&#x27;re feeling like your DLP program is a patchwork of policies and products that never quite delivers, you&#x27;re not alone.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/8786c2398169f7749fa4c2efcce9fd3781850668-2942x1654.png?w=500" /><h3>The Problem: DLP Is a full-time job that doesn’t work</h3><p>Legacy DLP wasn’t built for today’s complexity, including the <strong>emergence of Gen AI</strong> and <strong>large language models (LLMs)</strong>. These technologies expand the data security risk by introducing new vectors for leaking sensitive data and raising questions about data ownership and compliance. You’re juggling:</p><ul><li><strong>Multiple point tools</strong> that don’t talk to each other</li><li><strong>Overlapping or conflicting policies</strong></li><li><strong>Hours of manual work</strong> for investigation, tagging and remediation</li><li>And yet… <strong>false positives still flood your dashboards</strong></li></ul><p>What’s worse? All that effort still doesn&#x27;t stop sensitive data from leaking. In fact, organizations report an average of <strong>4.2 known data loss events per year</strong>, even when they have multiple DLP tools in place​.</p><p>That’s because <strong>traditional DLP tools don’t accurately and comprehensively discover, classify or remediate sensitive data</strong>. Most DLP products enforce static policies, which are often ineffective. These solutions lack the context to differentiate between actual threats and benign activity, leading to a high volume of false positives. This lack of context, combined with a lack of automation, burdens security teams with manual investigation and remediation tasks, hindering their ability to respond proactively to real threats.</p><h3>The Hidden Cost: False positives, missed alerts and burnout</h3><p>The data paints a clear picture:</p><ul><li><strong>92% of DLP alerts are false positives or ignored</strong>​</li><li><strong>Only 8% are actual issues that get remediated</strong></li><li>Security teams spend hours reviewing each alert only to find they are irrelevant</li></ul><p>This alert fatigue leads to burnout. Time is wasted. Confidence erodes. And critical issues, like insider risk or data exfiltration, slip through the cracks.</p><figure><blockquote><p>“We became very numb to the alerts. Our previous DLP tool generated more noise than benefit.”</p></blockquote><figcaption><cite>Mike Morrato</cite> CISO & Head of IT at Noname Security​</figcaption></figure><h3>It doesn’t have to be this way</h3><p>DLP should <em>work for you</em>, not the other way around.</p><p>That’s why MIND reimagined data loss prevention from the ground up. Not as a patch or plug-in, but as a <strong>fully integrated, AI-powered data security platform</strong> that unifies discovery, classification, detection, prevention and remediation.</p><p>MIND delivers both posture and prevention to companies by providing them with complete visibility and understanding of their data landscape and the ability to enforce contextually-aware policies that support, not hinder, the business.</p><p>MIND goes beyond enforcement. It understands.</p><h3>Why MIND is the modern alternative</h3><ul><li><strong>Discover and classify automatically<br/></strong>MIND AI is a multi-layer classification engine that identifies sensitive data across all environments, including Saas and Gen AI apps, on-premise file shares, endpoints and emails, without manual tagging or relying solely on regular expression (RegEx) pattern matching.</li><li><strong>Remediate data security issues autonomously<br/></strong>MIND can autonomously discover and remediate issues with sensitive data at rest, such as PII, PHI, PCI, financial information, credentials and so much more.</li><li><strong>Context-aware, risk-based insights<br/></strong>Alerts are enriched with context and prioritized by severity, so teams can focus on what really matters.</li><li><strong>Real-time protection and response<br/></strong>MIND actively stops sensitive data leaks across data in motion and in use. And when a violation occurs, it can <strong>autonomously prevent</strong>, notify users or apply custom policies in the moment.</li><li><strong>Fewer tools, fewer policies, fewer headaches<br/></strong>MIND consolidates functionality into a <strong>single, seamless data security platform</strong>, cutting out swivel-chair security.</li></ul><p>And it doesn’t take an army to manage.</p><figure><blockquote><p>“Being able to modernize our DLP without hiring a bunch of new people was huge. MIND lets us scale protection without scaling headcount.”</p></blockquote><figcaption><cite>Julie Chickillo</cite> VP of Information Security at Guild</figcaption></figure><p>DLP is a challenge for most organizations. Conventional DLP tools are often fragmented, time-consuming and ineffective, leading to alert fatigue and missed threats.</p><p>The MIND platform offers a modern alternative. By automating discovery, classification, detection, prevention and remediation, MIND provides organizations with the visibility, control and confidence they need to protect their sensitive data.</p><h3>Ready to rethink data security?</h3><p><strong>You’re not alone.</strong> Don&#x27;t remain stuck – MIND can help.</p><p><strong>👉 <a href="https://mind.io/registration/[object Object]">{children}</a><br/></strong>See what over 100 CISOs are saying about the future of data security – and how to finally make DLP work for you.</p>]]></description>
            <link>https://mind.io/blog/you-re-not-alone-78-of-companies-also-struggle-with-their-dlp</link>
            <guid isPermaLink="true">https://mind.io/blog/you-re-not-alone-78-of-companies-also-struggle-with-their-dlp</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Wed, 16 Apr 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/297a0e5361f962505e31a9287f8fc34ba6e2b282-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why compliance-driven security puts your data at risk]]></title>
            <description><![CDATA[<h2>Compliance isn't the easy button for data security</h2><p>For many organizations, compliance mandates drive data protection more than actual data security best practices. <a href="https://mind.io/registration/[object Object]">{children}</a> from ESG and sponsored by MIND underscores a growing concern: compliance-driven security strategies create a false sense of protection while exposing organizations to real threats.</p><h3>The Problem: Security that meets the minimum standard</h3><p>Regulatory frameworks and cybersecurity insurance policies establish essential baselines for protecting sensitive data. However, the report highlights a significant disconnect between what compliance requires and what effective data security demands. <strong>The majority of security leaders surveyed identified compliance-driven data security as a major issue, with 14% ranking it as their single biggest challenge—making it the top concern among all reported issues.</strong></p><p>Simply put, many organizations prioritize checking compliance boxes rather than implementing meaningful security measures that prevent sensitive data loss. This approach results in policies that look effective on paper but fail in practice.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/568aacbebb52ffcd66944399cc9db0ca30b529e1-2938x1654.png?w=500" /><h3>The Disconnect: Why compliance alone isn’t enough</h3><p>While compliance frameworks are critical in enforcing baseline security standards, they often fail to address modern data risks. Some of the key pain points security teams experience include:</p><ul><li><strong>False sense of security:</strong> Organizations may assume that meeting compliance standards equates to comprehensive data security, but <strong>53% of enterprises in the study experienced multiple data loss incidents in the past year</strong>, proving otherwise.</li><li><strong>Static and outdated controls:</strong> Compliance mandates often rely on policies that do not adapt to evolving threats, leaving businesses vulnerable.</li><li><strong>Alert fatigue and manual workloads:</strong> Legacy DLP solutions generate excessive false positives, requiring security teams to sift through noise rather than focusing on real risks.</li><li><strong>Limited visibility and context:</strong> Traditional compliance-driven solutions fail to provide a holistic view of sensitive data movement, making it difficult to differentiate between harmless activities and real threats.</li></ul><h3>The real cost of compliance-only security</h3><p>A security strategy built solely around compliance not only increases the likelihood of data breaches but also has direct business consequences. The report found that <strong>organizations still struggle with insider risk management, cloud data security and protecting unstructured data despite following regulatory frameworks.</strong> When security policies are designed to satisfy auditors rather than proactively mitigate risk, companies face increased exposure to data breaches and leaks, higher operational costs due to inefficient security workflows, potential regulatory fines and legal liability, and reputational damage that erodes customer trust.</p><h3>A Smarter Approach: Compliance + real security</h3><p>Organizations need security solutions that bridge the gap between compliance and actual risk reduction. This is where <strong>MIND</strong> comes in. Unlike traditional DLP tools that focus solely on compliance requirements, MIND provides a <strong>context-aware, AI-driven approach</strong> that protects sensitive data before a breach occurs.</p><ul><li><strong>Accurate discovery and classification:</strong> MIND continuously scans, classifies and protects sensitive data across SaaS apps, endpoints, on-premise servers and cloud environments. Compliance mandates were developed to secure the bare minimum of sensitive data for PII, PCI, PHI and others, and don’t cover those that can matter most to many organizations including intellectual property, credentials, cloud keys, financial statements and so much more.</li><li><strong>Context-aware protection:</strong> Instead of relying on rigid rule-based policies, MIND understands how and why data moves, ensuring smarter threat detection.</li><li><strong>Automated risk mitigation:</strong> Security teams spend 80% less time managing false positives, freeing them to focus on real threats..</li><li><strong>Seamless compliance and security:</strong> MIND ensures businesses meet regulatory requirements while also proactively and reactively protecting their data without adding unnecessary complexity.</li></ul><h3>The Bottom Line: Data security shouldn’t be just a compliance exercise</h3><p>Compliance is essential, but <strong>it should be the floor, not the ceiling,</strong> of a strong data security strategy. The results from The State of DLP report confirm that organizations relying solely on compliance-based security are still experiencing data leaks, breaches and inefficiencies.</p><p>MIND helps companies go beyond compliance checkboxes to implement effective, intelligent DLP that actually protects sensitive data while ensuring regulatory alignment. Don’t settle for the illusion of security – ensure your organization is truly protected.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> and see how you can rethink your approach to data security.</p>]]></description>
            <link>https://mind.io/blog/why-compliance-driven-security-puts-your-data-at-risk</link>
            <guid isPermaLink="true">https://mind.io/blog/why-compliance-driven-security-puts-your-data-at-risk</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Thu, 10 Apr 2025 12:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/b4704fff023285756b737a8d6e719f601a872e00-2880x1620.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Cut through the noise: Why 91% of security leaders want a better DLP solution]]></title>
            <description><![CDATA[<h2>Traditional DLP tools are not made for the modern way of working</h2><h3>It’s time to cut through the noise</h3><p>It’s 2:00 AM. Your security team is staring at an endless stream of alerts, trying to separate real threats from false positives. Critical risks are buried in the clutter. Frustration is mounting and focus is slipping. Sound familiar? You’re not alone.</p><p>Data Loss Prevention (DLP) tools were designed to protect sensitive information, yet for many organizations, they generate more noise than signal. In fact, <strong>91% of cybersecurity professionals agree: it’s time to cut through the noise</strong>,<strong> </strong>according to <a href="https://mind.io/registration/[object Object]">{children}</a> report from the <a href="https://www.techtarget.com/esg-global/">Enterprise Strategy Group™ (ESG)</a> and sponsored by MIND™.</p><p>The numbers are stark. In a survey of 100 senior cybersecurity and IT leaders, we found:</p><ul><li><strong>47% of DLP alerts are false positives</strong>, wasting countless hours.</li><li>Manual inspection is <strong>the top challenge</strong> for security teams.</li><li>Outdated DLP tools hinder rather than empower teams, leading to <strong>inefficiency, burnout and missed threats.</strong></li></ul><p>It’s time to reimagine how DLP can help—not hinder—your security efforts.</p><p></p><img src="https://cdn.sanity.io/images/3l9nidp2/production/c6e5ad7544fb7a50e76b295fe431a4e6acebd960-2940x1654.png?w=500" /><h3>The hidden cost of alert fatigue</h3><p>For security teams, the stakes couldn’t be higher. Every wasted minute chasing a false positive is a minute not spent addressing real risks. The fallout from noisy DLP solutions goes beyond operational inefficiencies - it takes a human toll.</p><p>Endless alerts drain morale, stretching work hours and eroding focus. As critical risks slip through the cracks, buried in a sea of irrelevant notifications, the fear of missing something crucial becomes ever-present. Time that should be spent on strategic priorities is instead wasted on acting as human filters, leaving teams frustrated and burned out. Over time, trust in the tools evaporates, forcing teams to resort to inefficient workarounds just to stay afloat.</p><p>Far from streamlining data security, many DLP systems become bottlenecks, turning what should be an essential safeguard into a source of daily frustration.</p><h3>Why traditional DLP falls short</h3><p>Legacy DLP systems were built for static, on-premises environments. But today’s dynamic, hybrid infrastructures demand tools that can adapt. Traditional DLP falls short in three key ways:</p><ol><li><strong>Static Policies</strong>: Rigid rule-based configurations can’t keep up with rapidly evolving data environments.</li><li><strong>Manual Processes</strong>: Teams are stuck inspecting alerts instead of addressing threats, slowing response times.</li><li><strong>Fragmented Tools</strong>: Disjointed systems overwhelm teams with irrelevant alerts and competing dashboards across multiple IT environments.</li></ol><p>More tools don’t mean better protection. They mean more noise, more inefficiency and more risks.</p><h3>MIND: Cutting through the noise</h3><p>It doesn’t have to be this way. <strong>MIND</strong> is a purpose-built solution that transforms how organizations approach DLP. Designed for clarity and precision, MIND uses advanced AI to deliver meaningful insights and streamline workflows.</p><p>Here’s how MIND changes the game:</p><ul><li><strong>Accurate alerts</strong>: MIND eliminates false positives so your team can focus on real threats.</li><li><strong>Context-aware intelligence</strong>: By analyzing sensitive data in context, MIND prioritizes risks that matter most.</li><li><strong>Streamlined workflows</strong>: Simplified processes reduce complexity, empowering your team to act confidently.</li><li><strong>Time savings</strong>: With intelligent automation, MIND frees your team from manual inspections, allowing them to focus on proactive strategies.</li></ul><p>MIND isn’t just another tool. It’s a smarter, more mindful way to secure your sensitive data.</p><h3>Empowering security teams to Mind What Matters</h3><p>The biggest problem with DLP isn’t the concept—it’s the execution. <strong>Noise, inefficiency and outdated tools have turned traditional solutions into liabilities.</strong> MIND redefines DLP, offering a clear path to stronger security without the clutter. Built from the ground up with simplicity, advanced AI and context-awareness, MIND discovers and classifies your sensitive data, fixes data security issues and stops sensitive data leaks.</p><p>It’s time to give your security team the clarity and confidence they need to focus on what truly matters: protecting your organization’s most sensitive data.</p><p><strong>Ready to take control of your data security?</strong></p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to learn how organizations are overcoming the limitations of legacy solutions—and how MIND is leading the way.</p>]]></description>
            <link>https://mind.io/blog/cut-through-the-noise-why-91-of-security-leaders-want-a-better-dlp-solution</link>
            <guid isPermaLink="true">https://mind.io/blog/cut-through-the-noise-why-91-of-security-leaders-want-a-better-dlp-solution</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Tue, 01 Apr 2025 19:40:16 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/cbb88e4d8b9e40c762094eda36c70061606e10a9-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[The complexity of DLP: Why multiple tools and policies leave sensitive data vulnerable]]></title>
            <description><![CDATA[<h2>DLP shouldn't be this hard today</h2><p>In the fast-paced world of cybersecurity, protecting sensitive data has never been more critical. Yet paradoxically, many organizations find themselves entangled in a web of multiple data loss prevention (DLP) tools and policy sets, creating a complex environment where sensitive information can easily slip through the cracks.</p><h3>The challenge: Too many tools, too much noise</h3><p>According to <a href="https://mind.io/content/[object Object]">{children}</a> from the <a href="https://www.techtarget.com/esg-global/">Enterprise Strategy Group™ (ESG)</a> and sponsored by MIND™, <strong>68% of organizations maintain policies across their IT environments using multiple DLP tools</strong>. This complexity raises a crucial question: Are these tools providing the protection they promise? Unfortunately, the answer is often no. <strong>Seventy-eight percent of organizations indicated that administering and maintaining existing DLP technology solutions and policies is a significant challenge</strong>.</p><p>Multiple tools and policy sets do not translate to better security. Instead, they create confusion and fragmentation, leading to inefficiencies that can leave sensitive data vulnerable. Security teams are left juggling different dashboards, each with its own alerts and configurations. This lack of integration can result in critical data being unprotected while regulatory compliance becomes a daunting task.</p><img src="https://cdn.sanity.io/images/3l9nidp2/production/fc8edbf32c38e689254b1e1798c11115a7de21d1-2938x1654.png?w=500" /><h3>The real pain: Frustration and fatigue in security teams</h3><p>The emotional and mental impact on security teams is profound. Constantly managing numerous tools and policies leads to frustration and burnout as they battle against an avalanche of alerts. In fact, <strong>forty-seven percent of DLP alerts are false positives</strong>, causing teams to waste valuable time chasing down non-issues instead of focusing on real threats.</p><p>Imagine a security analyst exhausted from sifting through countless alerts, trying to distinguish between legitimate threats and false alarms. The weight of this responsibility can be overwhelming. Each false positive is not just a distraction; it represents hours of work that could have been spent on proactive security measures. Compliance audits often turn into last-minute fire drills, and the fear of a potential breach looms large as critical data remains unprotected.</p><h3>The lack of innovation: A stagnant landscape</h3><p>While many vendors offer DLP as a feature, the lack of innovation prevents real progress in securing sensitive data. Traditional DLP solutions often rely on static rules and manual processes that are ill-equipped to handle the complexities of modern data environments. As organizations embrace cloud-first and hybrid infrastructures, the need for intelligent, adaptive solutions has never been more apparent.</p><p>The traditional approach to DLP has become a compliance checkbox rather than a proactive security measure. As security teams struggle with outdated methodologies, they find themselves flying blind, unable to accurately classify, prioritize and protect sensitive data.</p><h3>A smarter approach: MIND as the solution</h3><p>It doesn’t have to be this way. MIND redefines the DLP landscape by offering a DLP solution built from the ground up that addresses the complexities of today’s data environments. Unlike traditional tools that create additional noise, MIND&#x27;s AI-powered platform autonomously scans your entire data ecosystem—whether in SaaS and Gen AI apps, on-premise file shares, endpoints and emails—to classify and protect your sensitive information in real-time.</p><p>MIND streamlines the process with intelligent automation, reducing the need for multiple tools and disparate policies. With MIND, security teams can expect accurate alerts with virtually no false positives, freeing up their time to mind what truly matters—protecting sensitive data and responding to genuine threats swiftly and effectively.</p><h3>The future of DLP</h3><p>Data security shouldn’t be this hard today, but the traditional approach to DLP is broken. More tools and policies are not the answer; organizations must simplify and streamline their DLP programs with intelligent, purpose-built solutions. By doing so, they can regain control over their security posture and ensure that sensitive data is protected without the overwhelming burden of managing multiple disconnected systems.</p><p><strong>Are you ready to take your data security to the next level?</strong> <a href="https://mind.io/content/[object Object]">{children}</a> to learn how organizations address gaps in their DLP strategy and how MIND is changing the game.</p>]]></description>
            <link>https://mind.io/blog/the-complexity-of-dlp-why-multiple-tools-and-policies-leave-sensitive-data-vulnerable</link>
            <guid isPermaLink="true">https://mind.io/blog/the-complexity-of-dlp-why-multiple-tools-and-policies-leave-sensitive-data-vulnerable</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Wed, 26 Mar 2025 22:53:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/c09c3b34e02d4a05eb7d4b86c4dce358f30c3078-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Why 73% of Sensitive Data goes unprotected—and how to change that]]></title>
            <description><![CDATA[<h2>Data security can’t succeed without full visibility into where sensitive data lives, what it contains and the context around it</h2><p>Sensitive data is at the heart of every modern organization. It drives innovation, fuels strategic decisions and is the cornerstone of trust between you and your customers. But despite its critical importance, a staggering 73% of this vital data remains undiscovered, unclassified and vulnerable, according to a recent research report, <a href="https://mind.io/registration/[object Object]">{children}</a>, of 100 senior cybersecurity and IT leaders, conducted by the <a href="https://www.techtarget.com/esg-global/">Enterprise Strategy Group™ (ESG)</a> and sponsored by MIND™.</p><p><strong>The truth is, data security can’t succeed without full visibility into where sensitive data lives, what it contains and the context around it.</strong> In today’s fast-paced digital world, the constant growth of unstructured data—projected to double every 2.2 years—makes it even harder to stay on top of what matters. Without clear data classification, your security strategy is left in the dark, facing immense challenges:</p><ul><li><strong>Prioritizing Protections</strong>: When you don’t know what data is most critical, your security efforts become scattered, leaving your organization’s most valuable assets exposed.</li><li><strong>Enforcing Data Security and Compliance</strong>: Without classification, data protection and compliance becomes guesswork, risking costly penalties and reputational damage.</li><li><strong>Responding to Threats</strong>: In the event of a data leak or breach, not understanding what’s at risk leads to slow, ineffective responses, amplifying the damage.</li></ul><img src="https://cdn.sanity.io/images/3l9nidp2/production/6f429248551b9f9bb081f7fcc17da7e1f1d28d50-3208x1806.png?w=500" /><h3>The gold standard for data security</h3><p>Discovery and classification are the foundation of modern data security. With clarity into your sensitive data, your team can proactively protect what matters most, streamline compliance processes and respond swiftly to emerging threats.</p><p>This shift from reactive to proactive security allows organizations to stay ahead of risks and safeguard critical assets. <strong>Discovery and classification aren’t just important—they’re the gold standard in data security.</strong> In today’s increasingly complex, data-driven landscape, these efforts are no longer a luxury; they’re essential to the long-term success of a comprehensive security and compliance program.</p><h3>The fuzzy problem with today’s DLP tools</h3><p>According to the research report, an alarming 73% of unstructured sensitive data remains undiscovered and unclassified. That’s three-quarters of your organization’s most valuable assets left unprotected because the data is unknown.</p><p>Why does this happen? Traditional data loss prevention (DLP) tools and systems weren’t designed to tackle today’s rapidly evolving data environments and diverse sensitive data types specific to each organization. These outdated solutions rely on integration with a limited number of data sources, simple and inaccurate data classification schemes, static policies and manual oversight, struggling to keep up with:</p><ul><li><strong>Sprawling cloud infrastructures</strong></li><li><strong>Dynamic hybrid workforces</strong></li><li><strong>Unpredictable data movements</strong></li><li><strong>Rapid unstructured data growth</strong></li><li><strong>Sensitive data beyond just credit card and social security numbers</strong></li></ul><p>Instead of providing clarity, these tools leave big gaps in sensitive unstructured data discovery with today’s modern apps and data sources, leading to data slipping through the cracks, unaddressed.</p><h3>Unclassified data: A hidden threat</h3><p>When sensitive data goes unclassified or misclassified, the consequences reach far beyond missed alerts. Security teams feel it the hardest:</p><ul><li><strong>Wasted time</strong>: Hours are spent chasing false positives and a flood of trivial alerts, draining teams of focus and energy.</li><li><strong>Increased risk</strong>: Real threats remain undetected, and teams live in constant uncertainty about what they’ve missed.</li><li><strong>Compliance checkbox:</strong> DLP programs become compliance checkboxes since teams can’t precisely classify sensitive data that matter, such as cloud credentials, secrets, board minutes, M&amp;A agreements, bills of materials and so much more that organizations need to protect.</li></ul><p>Many security leaders believe this is the cost of doing business with legacy DLP tools. But it doesn’t have to be this way. <strong>Alert fatigue, endless manual oversight and sleepless nights don’t have to be the price of protecting sensitive data.</strong></p><p>Unclassified data isn’t just a vulnerability—it’s a source of constant stress, wasted effort and avoidable risk. <strong>It’s time to stop accepting the unacceptable.</strong></p><h3>A smarter alternative</h3><p>MIND redefines data security by delivering both Posture (data discovery and classification) and Prevention (data loss prevention and remediation). Unlike traditional tools, MIND:</p><ul><li><strong>Scans your entire data ecosystem</strong>—whether in SaaS apps, endpoints, on-premise files shares and emails—in real-time.</li><li><strong>Eliminates noise and false positives</strong>, by classifying your sensitive data that matter most (think beyond credit card and social security numbers) with precision.</li><li><strong>Reduces the burden</strong> on your security team by automating workflows, using <a href="https://mind.io/product/mind-ai">MIND AI</a> to classify with precision and minimizing manual effort.</li></ul><p>With MIND, you gain the clarity to see what matters, act on risks and threats faster and ensure that no sensitive file is left unprotected.</p><h3>See the full picture</h3><p>This report delves into the DLP challenges facing security leaders today and how modern solutions, like MIND, are helping organizations reimagine their data protection strategy.</p><p><a href="https://mind.io/registration/[object Object]">{children}</a> to explore how MIND’s approach to DLP can transform your data security efforts and drive better outcomes for your organization.</p>]]></description>
            <link>https://mind.io/blog/why-sensitive-data-goes-unprotected-and-how-to-change-that</link>
            <guid isPermaLink="true">https://mind.io/blog/why-sensitive-data-goes-unprotected-and-how-to-change-that</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Wed, 19 Mar 2025 10:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/b2c9bcf61f96c486b40a9d68f95f02c64d638e36-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Top 5 Data Security Imperatives for 2025]]></title>
            <description><![CDATA[<h2>Data security has become a critical business imperative for every organization</h2><p>In my conversations with cybersecurity leaders, last year was a watershed moment – a stark reminder that data security is no longer a back-office concern – it&#x27;s a critical business imperative. Protecting sensitive data is top of mind for these CISOs and, in 2025, the stakes are higher than ever. Organizations across every industry are grappling with a complex web of challenges – the explosive growth of generative AI, an endless stream of data security alerts and the persistent struggle to balance security with user productivity.</p><p>So, what lies ahead? What key insights will shape the data security landscape in 2025? Based on my decades of experience building and leading cyber companies and current conversations with industry leaders, here are my 5 key data security imperatives for this year:</p><h3>1. It’s Time for Posture AND Prevention</h3><p>Organizations are realizing the limitations of managing a patchwork of tools, each with its own interface, set of policies, reporting structures and potential for gaps in coverage. In 2025, we&#x27;ll see a strong shift towards fewer data security solutions that consolidate essential capabilities – data discovery, classification, risk detection, remediation and loss prevention to name a few. This consolidation will not only streamline security operations but also reduce costs and improve overall effectiveness.</p><p>Expect to see DSPM (Data Security Posture Management) fully absorbed by more comprehensive, modern DLP (Data Loss Prevention) solutions, offering a complete lifecycle of data protection. Posture without prevention is interesting but not nearly sufficient for CISOs. Prevention without proper posture that includes accurate data discovery and classification is what plagues traditional DLP tools today. With these two Ps in a pod, security teams will get comprehensive security with visibility and classification along with detection and prevention of data leaks for structured and unstructured data at rest, in motion, and in use.</p><h3>2. AI: Force (& Risk) Multiplier</h3><p>Artificial intelligence is a present-day powerhouse in the realm of data security; it’s also the bane of cyber leaders with the rise of Gen AI apps like Microsoft Copilot, Google Gemini and Glean that businesses are adopting rapidly, and others like DeepSeek and Grok that consumers – and your employees – are using.</p><p>In 2025, DLP systems will go beyond stale algorithms and RegEx pattern matching for data classification and simple automations. They will use specifically trained AI and large language models (LLMs) to classify novel sensitive data types beyond credit card and social security numbers, categorize sensitive file types (think contracts, intellectual property, bill of materials and so much more), analyze user behavior, detect risks and anomalies and prevent data leaks.</p><p>This is critical because the explosive growth of generative AI platforms for business and personal use presents significant challenges by creating massive volumes of new data and opening up new avenues for data leakage and insider risks. Organizations need to be vigilant in implementing safeguards to prevent sensitive information from being inadvertently exposed through these platforms, with a focus on educating employees about the risks and implementing robust controls to limit access and monitor usage. Modern DLP solutions will be key in stopping these leaks through Gen AI apps.</p><h3>3. Automation, Finally</h3><p>For years, the promise of automation in data security has been tantalizingly close, yet just out of reach. The lack of trust in underlying data classification algorithms and static policies, and the resulting flood of false positives, have led to valid concerns about automation that prevent companies from even attempting it. This situation has led many organizations to rely on manual processes, draining valuable time and resources.</p><p>However, with advancements in AI-powered DLP, that&#x27;s about to change. In 2025, CISOs will finally embrace AI and automation for data security, confident that these systems can accurately classify the sensitive data that matters, detect and get context around potential issues and proactively respond to risks without overwhelming security teams with false alarms. This shift will free up analysts to focus on strategic initiatives and proactive data – and business – risk mitigation.</p><h3>4. Renewed Data-Centric Security Mindset</h3><p>Data security is no longer an isolated function within the IT department; it&#x27;s a core business imperative. In 2025, we&#x27;ll see a growing adoption of a data-centric security mindset, where data protection is embedded into every aspect of the organization. Emerging tools will empower security teams to accurately manage their sensitive data, which results in the ability to keep pace with all the data the business operates with. This shift requires a collaborative approach, with security teams working closely with business units and individual users to understand data flows, identify critical assets and implement appropriate safeguards.</p><p>This shift to a data-centric security mindset is a move away from the prevailing security tool mindset, where teams look to a new system or technology to secure their data. With a data-centric approach, even specific business units will be able to enforce security on their unique forms of sensitive data. By distributing the security for these sensitive assets, enforcement happens at the point where it can be most effective; where the data is stored, sent or used.</p><h3>5. Striking a Balance in DLP</h3><p>The traditional approach to DLP, characterized by rigid rules, draconian controls and complicated tools, is giving way to a more nuanced strategy. Organizations recognize that overly restrictive policies usually get turned off anyway when business units complain about how much they hinder their legitimate work. Additionally, the cost/benefit analysis will swing away from complex tools that might provide a wide swath of features towards nimble tools that better protect the sensitive data that matters.</p><p>In 2025, we&#x27;ll see a greater emphasis on finding the right balance between security and usability. Right-sized DLP solutions, focused on protecting critical assets while minimizing disruption to workflows, will become the preferred choice for many businesses. They won’t have to endure complex programs or tools when a more purpose-built solution can get the job done. With businesses reviewing the cost of their security programs and tools, finding ways to provide more benefits while spending less money will be key. And many legacy DLP tools won’t make the cut, with companies realizing they can achieve their data security goals with an effective and nimble strategy.</p><h3>Time to balance proactive and reactive data security</h3><p>2025 promises to be a pivotal year for data security. By understanding and embracing these key trends, organizations can navigate the evolving data risk landscape and safeguard their most valuable assets. It&#x27;s time to move beyond just reactive measures and build a proactive, data-centric security posture that supports innovation and drives business growth.</p><p>In this rapidly evolving environment, simply reacting to threats is no longer enough. We need to adapt and proactively safeguard our most valuable assets. This requires a fundamental shift in our approach to data security, one that embraces innovation, prioritizes efficiency and effectiveness, and fosters a culture of shared responsibility.</p><p>See our <a href="https://mind.io/customers">{children}</a> to learn more about how we&#x27;re already helping customers with these critical imperatives.</p>]]></description>
            <link>https://mind.io/blog/top-5-data-security-imperatives-for-2025</link>
            <guid isPermaLink="true">https://mind.io/blog/top-5-data-security-imperatives-for-2025</guid>
            <dc:creator><![CDATA[Eran Barak]]></dc:creator>
            <pubDate>Wed, 05 Mar 2025 20:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/3bbdf043f0203b7457b05cc1cd65033998a16c39-3840x2160.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[North Korean ‘IT Warriors’ and the Rise of Insider Threats: How MIND can protect against insider risks]]></title>
            <description><![CDATA[<h2>The FBI issued a public service announcement of North Korean IT Warriors posing as remote IT workers</h2><h3>FBI's PSA of North Korean IT workers</h3><p>The digital age has blurred geographical boundaries, allowing businesses to tap into a global talent pool. But this interconnectedness also brings new risks, as flagged by the <a href="https://www.ic3.gov/PSA/2025/PSA250123">Federal Bureau of Investigation (FBI) about North Korean IT workers</a>. These individuals, dubbed &quot;IT warriors,&quot; increasingly use fake identities to secure remote IT jobs at US-based companies, not to contribute but to <a href="https://cybersecuritynews.com/north-korean-it-workers/#google_vignette">steal sensitive data and intellectual property</a>. This warning by the FBI highlights potential external threats and bad actors working as insiders to exfiltrate sensitive data, demanding a robust and modern approach to data protection for organizations.</p><p>These workers appear legitimate and often have the surroundings of an IT outsourcing company. These companies are as fake as the workers they provide. <a href="https://www.sentinelone.com/labs/dprk-it-workers-a-network-of-active-front-companies-and-their-links-to-china/">Authorities are working to take down these fraudulent companies&#x27; websites</a>, but you can be sure more will pop up. The FBI recommends data monitoring and data loss prevention (DLP) controls to detect, identify and stop data leaks from these types of threats.</p><h3>Impact of malicious insiders</h3><p>Once inside, they can exfiltrate code, proprietary data, and even customer information, potentially leading to:</p><ul><li><strong>Financial losses: </strong>Data breaches can be incredibly costly, involving extortion, ransom payments, regulatory fines, legal fees and remediation efforts.</li><li><strong>Reputational damage:</strong> Losing sensitive data can erode customer trust and negatively impact a company&#x27;s brand image.</li><li><strong>Intellectual property theft:</strong> Competitors could gain an unfair advantage if trade secrets or proprietary technology are stolen.</li><li><strong>Disruption of operations: </strong>Significant data loss events can disrupt business operations, leading to downtime and lost productivity.</li></ul><h3>Legacy DLP and DSPM are not enough</h3><p>Traditionally, companies have relied on <a href="https://mind.io/solutions/[object Object]">{children}</a> to mitigate these risks. However, legacy DLP tools are struggling to keep pace with today&#x27;s complex threat landscape. They often fail to:</p><ul><li><strong>Discover all sensitive data:</strong> Legacy DLP tools often rely on predefined rules and patterns, making them ineffective at identifying sensitive data that doesn&#x27;t fit these parameters.</li><li><strong>Accurately classify data: </strong>Manual classification is time-consuming and prone to errors, while automated classification in legacy tools can be narrow and unreliable, leading to numerous false positives.</li><li><strong>Enforce policies effectively:</strong> Cumbersome policies and enforcement workflows can lead to users finding workarounds, rendering the legacy DLP tools ineffective.</li></ul><p>While data security posture management (DSPM) solutions have emerged to help locate and classify sensitive data, they typically lack the ability to find and classify unstructured data (e.g. business files), enforce policies and prevent data leakage. This leaves a critical gap in a company&#x27;s security program.</p><h3>A new approach to DLP and Insider Risk</h3><p>To effectively combat evolving insider threats, a new approach is needed. MIND&#x27;s modern <a href="https://mind.io/">{children}</a>offers a comprehensive suite of capabilities to protect critical data from malicious insiders:</p><ul><li><strong>Complete sensitive data discovery:</strong> MIND connects to all your data sources (SaaS apps, endpoints, on-premise file shares and emails) to identify sensitive data, regardless of format or location.</li><li><strong>Accurate and automatic classification: </strong><a href="https://mind.io/product/mind-ai">{children}</a> is a multi-layer AI engine that classifies and categorizes sensitive data with high accuracy, significantly eliminating the need for manual intervention and the flood of false positives experienced with legacy DLP tools.</li><li><strong>Effective policy enforcement:</strong> MIND enforces policies in real time, preventing data leakage and ensuring compliance with regulations. It can also interact with end-users directly (within policy) to help educate and steer them toward the right data security actions.</li><li><strong>Complete audit trail:</strong> MIND provides a detailed lineage and audit trail of all data activity, enabling security teams to monitor and investigate potential threats. It can also highlight anomalous users with a consistently high risk of data leakage for closer inspection.</li></ul><p>By combining these capabilities, MIND empowers organizations to proactively protect their data from malicious insiders without hindering productivity or stifling collaboration.</p><h3>Modern DLP made for future risks</h3><p>The threat of malicious insiders is real and growing. North Korean IT warriors are just one example of the sophisticated tactics being used to compromise sensitive data. Companies must adopt a proactive and comprehensive approach to data security.</p><p>MIND&#x27;s modern DLP solution offers a powerful combination of advanced technology and user-friendly features to protect critical data from all types of insider threats. With MIND, businesses can embrace the benefits of a global workforce without compromising their security posture. By investing in robust data protection, organizations can create a secure future for themselves and their stakeholders.</p>]]></description>
            <link>https://mind.io/blog/north-korean-it-warriors-and-the-rise-of-insider-threats-how-mind-can-protect-against-insider</link>
            <guid isPermaLink="true">https://mind.io/blog/north-korean-it-warriors-and-the-rise-of-insider-threats-how-mind-can-protect-against-insider</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Wed, 29 Jan 2025 16:08:47 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/243d927ec419499c69e8daacf6c26077559c493c-2880x1920.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Best practices for secure and safe Browser Extensions deployed by MIND]]></title>
            <description><![CDATA[<h2>Over the holidays, cybercriminals exploited a common yet often overlooked entry point: Browser Extensions</h2><h3>Vulnerability of browser extensions exposed</h3><p>In a widespread phishing campaign, attackers gained access to the source code of several <a href="https://www.reuters.com/technology/cybersecurity/data-loss-prevention-company-cyberhaven-hit-by-breach-statement-says-2024-12-27/">Google Chrome extensions</a> and injected malicious code. While not a targeted attack, this breach prompted affected companies, including data security vendors, to <a href="https://www.bleepingcomputer.com/news/security/cybersecurity-firms-chrome-extension-hijacked-to-steal-users-data/">swiftly patch their extensions</a>.</p><h3>Legitimate business tools compromised</h3><p>Browser extensions are indispensable tools, often used for legitimate business purposes. On average, a business user might have around 10-15 browser extensions installed for various productivity, security and utility purposes. However, their access to sensitive data, such as usernames, passwords and cookies, makes them an attractive target for cybercriminals. The goal of the most recent publicized attack was clear: to harvest credentials and session data for future exploitation.</p><h3>MIND's best practices for our browser extensions</h3><p>At MIND, we recognize the critical role our browser extension plays in sensitive data loss prevention (DLP) within SaaS applications and on endpoints. That’s why security is always top of mind.</p><p>Here are the best practices we employ to make sure our MIND browser extensions are safe and secure:</p><ul><li><strong>Source code review:</strong> Our source code is reviewed to ensure it’s free from malicious code injection.</li><li><strong>Privileged access controls: </strong>A very small number of people have access to our source code and we follow strict privileged access controls.</li><li><strong>Rigorous deployment workflow:</strong> The entire MIND browser extension deployment workflow is written as code and audited, and deploying a new version requires manual approval.</li><li><strong>Security awareness training:</strong> Our employees regularly engage in active phishing education and testing.</li><li><strong>Penetration testing: </strong>Routine penetration tests help us proactively identify and remediate potential security issues.</li></ul><h3>Vigilance is key to protecting customers</h3><p>While this attack highlights the dangers of phishing and compromised browser extensions, it also underscores the importance of robust security practices. At MIND, we remain vigilant, ensuring that your data stays protected, even in the face of evolving threats. <a href="https://mind.io/product/loss-prevention">{children}</a>how MIND stops data leaks on endpoints and web browsers.</p>]]></description>
            <link>https://mind.io/blog/best-practices-for-secure-and-safe-browser-extensions-deployed-by-mind</link>
            <guid isPermaLink="true">https://mind.io/blog/best-practices-for-secure-and-safe-browser-extensions-deployed-by-mind</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Tue, 07 Jan 2025 13:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/5ce05db30d3d22503dd06086b810948ebca8758d-4000x2667.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[A bold data security vision worth striving for]]></title>
            <description><![CDATA[<h2>A mindshift with breakthroughs is needed in DLP to meet its promise</h2><h3>The Next Chapter</h3><p>I joined <a href="https://www.armis.com/">Armis</a> at the start of the COVID pandemic when it was already a thriving company with a talented team and a growing customer base. Since then, Armis has grown exponentially - crossing the $200M ARR mark, expanding to 800+ employees and partnering with many Fortune 500 companies.</p><p>The journey has been rewarding, and I’m grateful for the lessons learned in shaping product strategy and driving growth. After leading product teams through this exciting phase, I’ve decided to take on a new challenge: building and leading a product organization at an early-stage cybersecurity startup with an innovative vision and strong momentum.</p><h3>Why Data Loss Prevention?</h3><p>As I considered my next move, I spent a lot of time analyzing emerging market trends and opportunities in cybersecurity. There’s no shortage of buzzwords and new acronyms in this space - many promising to address unmet needs, while others are already crowded with competing startups that struggle to differentiate themselves.</p><p>But one area stood out: <strong>data security</strong>, specifically <strong>data loss prevention (DLP)</strong>.</p><p>DLP is not a new concept. In fact, traditional data protection products have been around for years. Yet, surprisingly, many of these solutions remain complicated to implement and resource-intensive to manage. Moreover, they tend to focus more on compliance than true security.</p><p>What’s more, traditional DLP systems struggle to adapt to the way modern organizations manage and use data today. With data now dispersed across cloud environments, SaaS applications, AI-powered tools, endpoints, on-premise file shares and email, and accessed from almost anywhere, these legacy solutions simply aren’t built to handle the complexity.</p><p>On the flip side, newer entrants into the data security space often don’t go far enough. Instead of proactively preventing sensitive data leaks, many focus on issue discovery or posture management without actually blocking leaks at the source.</p><p>It was clear to me that DLP needed a major upgrade. I’m excited to tackle that challenge.</p><h3>Why MIND?</h3><p>When I first met the founders of MIND - <a href="https://mind.io/blog/why-mind-why-dlp-and-why-now">Eran</a>, <a href="https://mind.io/blog/the-hardest-problems-to-solve-are-the-most-rewarding">Itai</a>, and <a href="https://mind.io/blog/founders-blog-leading-with-optimism-and-a-dont-wait-philosophy">Hod</a> - I knew I had found something special. Their blend of deep technical expertise, successful business experience and a shared vision for a bold future was compelling. It wasn’t just about a great idea; it was about <em>execution</em>.</p><p>MIND’s approach to data security resonated with me immediately. The team not only understands the challenges of securing sensitive data in today’s fast-paced, highly distributed environment but is also committed to solving these challenges head-on. With a <a href="https://mind.io/content/[object Object]">{children}</a>, they’re building a solution that doesn’t just identify risks but actively prevents data leaks, all while being intuitive, easy to use and simple to operate.</p><p><strong>In short: MIND is developing a <a href="https://mind.io/">{children}</a> that actually works - and works for you.</strong></p><p>I’m thrilled to be joining MIND at this exciting time in its journey. I look forward to contributing to the vision of advancing DLP to meet the needs of the modern enterprise.</p>]]></description>
            <link>https://mind.io/blog/a-bold-data-security-vision-worth-striving-for</link>
            <guid isPermaLink="true">https://mind.io/blog/a-bold-data-security-vision-worth-striving-for</guid>
            <dc:creator><![CDATA[Tom Mayblum]]></dc:creator>
            <pubDate>Wed, 04 Dec 2024 17:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/affe588e3935b8066d02daeb62e1703ca03ee6e5-6144x4112.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Founders’ blog: Leading with optimism and a ‘don’t wait’ philosophy]]></title>
            <description><![CDATA[<h2>Data security hasn’t evolved for three decades, so we’re taking it to the next level</h2><p>One of the most transformative periods of my early career was the nine years I spent in the Israeli Military Intelligence Unit 8200. At the time, there was a lot happening in cybersecurity innovation, and the 8200 was at the forefront. The projects I worked on were complex and challenging—they were also groundbreaking. We were part of building very exciting new technologies.</p><p>After my military service, I worked at startups as a software engineer and product management leader, and was the first employee at <a href="https://www.dazz.io/">Dazz</a>, specializing in real-time vulnerability detection and remediation. This time in my career solidified my belief in the power of a strong team, and the importance of staying adaptable in the face of every challenge. As a co-founder of <a href="https://mind.io/">{children}</a>, these beliefs have guided me.</p><h3>Building powerhouse teams</h3><p>The majority of my years in the 8200 were spent as a team leader, and I became very adept at seeing ability and building powerhouse teams. In recruiting, there are certain qualities you look for. Of course, first everyone needs to be able to function as part of a team. This means respecting each other’s strengths and skills, communicating, and being adaptable.</p><p>Beyond that, I’ve found that the best teams have a balance of different kinds of thinkers. You can’t have a team of all humble people the same way you can’t have a team of all risk-takers. The most exciting and successful innovation happens when there’s a push-and-pull dynamic of different personality types.</p><p>I also look for people who are optimistic. It’s too easy to be discouraged in the face of adversity, especially when solving very complex problems. Being in the mindset of building things means having a clear vision and not being afraid of the past. Whatever happens, even when things don’t work as planned, the whole team has to stay optimistic and keep moving forward.</p><p>Lastly, I look for people who are driven by curiosity. Someone who’s curious and really, really hungry to learn is going to constantly find new ways to be creative. This person is far more valuable to the team than someone who thinks they’ve seen it all and knows it all. I’m always trying to nurture that spark of curiosity in the people around me.</p><h3>Always solving something</h3><p>I’m interested in a lot of different things, and I enjoy solving all kinds of problems in my head. Even something as simple as crossword puzzles, my mind will keep thinking about it until I get the answer. It’s like a natural instinct for me, I just really enjoy figuring things out.</p><p>When it comes to technology, I want to know every aspect of it. I’m curious about how it works, how it was made, and how I can break it. I’m immediately taking it apart in my mind and thinking about how to make it better.</p><h3>Embodying ‘just do it’</h3><p>My absolute favorite philosophy is ‘don’t wait.’ This mantra has guided me in both my personal and professional life. There will always be problems. But there are solutions everywhere, and you need to be able to go forward and try things. It’s important to me that I empower people with the confidence to take immediate action. As long as they know the shared vision, they’ll move in the right direction.</p><p>Sure, there will be times when you need to sit with something. You might think for a week, or more, or however long it takes while you figure out certain aspects in your mind. But then there’s a point when you need to be hands-on. Make a decision. Just go.</p><p>Sometimes the ‘aha’ moment will come when you’re planning. Sometimes when you’re building. And sometimes it will come after you’ve been working on it for some time. Whatever the problem, I try to begin with something that will give me feedback. This way you can be sensitive and respond to whatever’s happening.</p><p>There have been many situations when I didn’t know what the end solution would look like. I made a choice to move forward despite the uncertainty and figured it out. The journey is part of the process.</p><h3>Starting a company</h3><p>Many of my peers in the 8200 knew from a young age they wanted to start a company, and it was really important to their identity. I never really shared that same kind of ambition. I just knew I wanted to build things.</p><p>It took me a while to realize that starting a company was the best way to do this. It’s an incredible opportunity to start from the beginning. To build the vision, the team and the technology. Once I realized this was my path, I started to think like a founder. I watched other founders and learned from them.</p><h3>Taking on data loss prevention</h3><p>With MIND, one of the early unexpected challenges was the market we were targeting. You might think that going into an established space like data security would be easier, especially when there was such an obvious need for improvement. But that wasn’t the case. We were entering a market that hadn’t evolved for three decades.</p><p>For me, the most exciting part of starting MIND was going from zero to one. That’s where the most unknown was, where we asked the biggest questions and encountered the hardest problems. My co-founders, Eran (CEO) and Itai (CTO), and I were never discouraged by setbacks. We focused on what was important and figuring things out. We have the resources to experiment and find what’s exactly the product that will be able to take us to the next level in data security, especially in data loss prevention (DLP).</p><p>Whether it’s starting a company or building something new, if you want to do something, just do it. Don’t waste energy thinking about reasons why you shouldn’t. If it’s important, then it’s worth doing. Don’t postpone, just start.</p>]]></description>
            <link>https://mind.io/blog/founders-blog-leading-with-optimism-and-a-dont-wait-philosophy</link>
            <guid isPermaLink="true">https://mind.io/blog/founders-blog-leading-with-optimism-and-a-dont-wait-philosophy</guid>
            <dc:creator><![CDATA[Hod Bin Noon]]></dc:creator>
            <pubDate>Wed, 13 Nov 2024 14:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/c5dbabd611bc9f9dbc20b751e12bfe858cc3df70-5400x3614.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Founders' blog: The hardest problems to solve are the most rewarding]]></title>
            <description><![CDATA[<h2>The role of perseverance in making MIND</h2><p>Before co-founding MIND, I worked in cybersecurity at the prestigious Israeli Military Intelligence Unit 8200. After that, I worked at Axonius and then Torq, both remarkably innovative companies who were early in pioneering AI-driven operations. At both places I was also among the first employees, giving me rare insight and experience in building and scaling companies from the ground up.</p><h3>Building from the ground up</h3><p>At <a href="https://torq.io/">Torq</a>, I had the unique opportunity of being the first employee. Starting a company from zero is such an incredible experience. When you first come in there’s nothing—no code at all, no processes, no culture. To be accurate, there were three of us first employees who started at the same time, so we did this together. I vividly remember sitting in the room and saying, ‘ok, let’s start.’</p><p>Even before, when I was at <a href="https://www.axonius.com/">Axonius</a>, it was a similar experience because I was such an early employee. We were so small and the technology was so early. It’s incredible to see where the company is today. Now it’s a successful business with nearly 700 employees and a cybersecurity unicorn in its market.</p><p>People ask me what it’s like to start a startup. To be honest, it’s not scary to start. It’s the day-to-day that’s very intense. There are so many different things you need to be thinking about, and each of those is equally big and equally important. From hiring to marketing and sales, to obsessing over the customer. And it’s a startup, so nothing is set.</p><p>Now at MIND, I’m bringing along with me everything I learned. One thing that’s a little different is our transparency with the team. We’re very open about what’s happening with the company. We record meetings and provide summaries for everyone to see. The engineers putting the work in and building the product deserve to know why certain decisions are being made. I do my best to do right by them.</p><h3>Inspired by relentless dedication</h3><p>I’ve always believed that success is earned through hard work, perseverance and a commitment to constant improvement. From a young age I’ve been surrounded by exceptional minds. Many of my own family members are some of the smartest people I’ve ever known. Some of my closest peers from the 8200 have founded their own successful companies, and I’m inspired by their brilliance. I’ve also seen firsthand the level of discipline and effort it takes.</p><p>Being around greatness is its own kind of motivation. I think this gave me a special power: I practice, put the work in and don’t give up until I succeed. For me, mediocrity has never been an option. I’ll relentlessly work on a problem until I figure it out.</p><p>And I love it—this work ethic is part of who I am. I have an innate desire to do the hardest things. I find myself seeking out the biggest and toughest challenges, wanting to solve the unsolvable. My co-founders <a href="https://mind.io/blog/[object Object]">{children}</a> and <a href="https://www.linkedin.com/in/hodbn/">Hod</a> share this sensibility. We knew our vision for MIND was big and ambitious. We knew it would be really, really hard. But we knew we could do it.</p><h3>Learning from mistakes</h3><p>Whenever you do hard things, there will be things that inevitably go wrong. Early on in my career I learned how important it is to acknowledge failures. I’ve watched other people try to hide from failure, and they point to which factors had been out of their control. To me, that’s missing out on a crucial opportunity to learn. Don’t just say ‘oh that didn’t work so let’s do something else.’ Instead, fully own and honestly evaluate what happened. Mistakes do happen. That’s okay. Because they make us better.</p><p>The reality is, no matter how much effort you put into your work, you’re going to fail from time to time. There will always be things we can’t control. Don’t take these things for granted. Confront what you’re good at—or not good at—so you know where to ask for help. It will prevent you from repeating the same mistake, and you’ll be a better person for it.</p><h3>Finally doing data security right</h3><p>When you look at the cybersecurity industry as a whole, there are five or six categories that are essentially the core building blocks for everything else. But data security has always been an outlier because it’s extremely hard to execute. This is a really, really important domain, but it’s very challenging. Until we came along, nobody seemed interested in solving it.</p><p>Before MIND, the building blocks of data security hadn’t meaningfully changed in decades. It’s always been the same players with the same technology that was developed in the 1990s. Every data security vendor since then has been plagued with the same issues: false positives and untrustworthy results. Not to mention expensive, cumbersome, manual and draining on time and resources.</p><p>It’s no wonder CISOs have been asking themselves if it’s even worth the effort. Under the surface, meaningful innovation just wasn’t taking place. Not only was it a really difficult problem, but the domain wasn’t seen as exciting. Customers didn’t like their data loss prevention (DLP) options. Vendors weren’t evolving. And everyone just kept using the same tools anyway for compliance reasons rather than for cybersecurity and risk reduction. Meanwhile, analysts were already starting to call data security an obsolete and unsolvable category.</p><h3>The Dr. Jekyll and Mr. Hyde of AI in cybersecurity</h3><p>We saw early on that artificial intelligence would be a Dr. Jekyll and Mr. Hyde scenario in cybersecurity. On the one hand, Generative AI was increasingly being leveraged for amazing business productivity, but on the other, it was an emerging source of sensitive data leaks by employees using it. We actually saw an opportunity to innovate with next-generation AI technology to transform how DLP is done.</p><p><a href="https://mind.io/product/mind-ai">{children}</a> is the result of years of perseverance and hard work. We finally built a solution that understands sensitive data based on context. Once we taught our AI engine how to learn to accurately decipher and classify the information, we could tailor algorithms and policies, enabling the entire solution to ultimately run on autopilot.</p><p>For years, conventional DLP tools have been widely regarded as mediocre. I don’t believe in mediocrity, and organizations shouldn’t have to settle for it. That’s why we created MIND. My co-founders and I knew we could solve this problem. So we relentlessly worked on it until we figured it out.</p>]]></description>
            <link>https://mind.io/blog/the-hardest-problems-to-solve-are-the-most-rewarding</link>
            <guid isPermaLink="true">https://mind.io/blog/the-hardest-problems-to-solve-are-the-most-rewarding</guid>
            <dc:creator><![CDATA[Itai Schwartz]]></dc:creator>
            <pubDate>Tue, 05 Nov 2024 20:24:13 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/5dd7cfb43b81beb0ce711e6b2612d6bac8725ca4-5400x3614.png?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Welcome, MIND: The Breakthrough in DLP We’ve Been Waiting For.]]></title>
            <description><![CDATA[<p>I’m thrilled to announce the launch of <a href="https://mind.io/newsroom/[object Object]">{children}</a> following a $11M seed round led by <a href="https://www.ylventures.com/">YL Ventures</a> and supported by cybersecurity leaders at <a href="https://www.adobe.com/">Adobe</a>, <a href="https://www.adt.com/">ADT</a>, <a href="https://www.crowdstrike.com/">CrowdStrike</a> and FireEye. Their innovation marks the next phase of Data Loss Prevention (DLP) with real-time insights and context to accommodate today’s fast-paced workflows.<br/><br/>If you’ve been in the cybersecurity trenches for a while, you know that DLP has been stuck in a rut, with traditional solutions failing to keep pace with the evolving threat landscape and modern data environments. As someone who was there when DLP first emerged, it’s exciting to see a solution like MIND that promises to redefine and advance a very stale–but critical–industry domain.</p><h3>Minding the Gaps</h3><p>MIND isn’t just an incremental upgrade; it’s a reimagining of DLP. Traditional DLP solutions have been clinging to outdated client-server models, struggling to keep pace with the needs of today’s multicloud and SaaS environments. Designed for static, on-premises setups, these tools often miss the mark on accuracy and efficiency, resulting in frustratingly high false positives and missed threats.<br/><br/><strong>A Fresh Mindset</strong><br/>MIND bridges old DLP gaps with real-time accuracy and adaptability. That’s already a major step up. But what truly sets MIND apart is its use of <a href="https://mind.io/product/data-discovery">{children}</a>. The platform’s real-time, contextual visibility allows security teams to pinpoint data risks and respond to genuine threats with far greater precision than we’ve had before.</p><h3>Mindful Innovation</h3><p>MIND’s launch underscores the critical need for continuous innovation–even in cybersecurity’s dustiest corners. There are a lot of lessons to be learned from how their fresh thinking and application of new technology is finally breaking through persistent challenges and transforming tired, longstanding practices. MIND’s success serves as a powerful example of how core issues need constant rethinking. This proactive and forward-thinking approach is essential for staying ahead in an ever-evolving threat landscape.</p><h3>Keeping Minds Aligned</h3><p>This marks our second collaboration with <a href="https://mind.io/blog/[object Object]">{children}</a>, CEO of MIND. Our previous partnership was with Hexadite, which was successfully acquired by <a href="https://www.microsoft.com/">Microsoft</a>. Eran brings a wealth of experience from his roles at Microsoft and as a seed investor in cybersecurity. Joining him at MIND is CTO <a href="https://www.linkedin.com/in/itai-schwartz-9b893b214/">Itai Schwartz</a> and VP of R&amp;D <a href="https://www.linkedin.com/in/hodbn/">Hod Bin Noon</a>, both highly impressive technologists with particularly distinguished experience in building massively successful products from the ground up.<br/><br/>At YL Ventures, we seek out founders who are not only highly skilled but also deeply committed to tackling critical challenges. With MIND, we have found a team dedicated to advancing the field of DLP. Our partnership has been characterized by mutual respect and a shared vision, and we are excited to support this groundbreaking solution.<br/><br/>Working with Eran, Itai and Hod has been a privilege. The team’s visionary approach and dedication to enhancing data protection have been key to bringing MIND to fruition. As we continue to back MIND, we eagerly anticipate how their innovative solution will drive progress in data security and set new benchmarks for the industry. This collaboration exemplifies how visionary leadership and cutting-edge technology can transform cybersecurity and push the boundaries of what’s possible.</p>]]></description>
            <link>https://mind.io/blog/welcome-mind-the-breakthrough-in-dlp-we-ve-been-waiting-for</link>
            <guid isPermaLink="true">https://mind.io/blog/welcome-mind-the-breakthrough-in-dlp-we-ve-been-waiting-for</guid>
            <dc:creator><![CDATA[Justin Somaini]]></dc:creator>
            <pubDate>Mon, 04 Nov 2024 15:16:58 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/2578d0f1e5f2feb0751f39e8f3056c82b23994e5-7661x7189.jpg?w=800" length="800" type="image/jpeg"/>
        </item>
        <item>
            <title><![CDATA[Founders' blog: Why MIND? Why DLP? And why now?]]></title>
            <description><![CDATA[<h3>How the meeting of minds formed MIND</h3><p>Hello world!</p><p>I’ve always had an entrepreneurial spirit. Even from an early age, I knew I wanted to build something of my own. My career began in the Israeli Defense Forces (IDF) Intelligence Unit, where I oversaw critical technological defense operations. Later, I co-founded Hexadite, the pioneering startup to tackle Automated Incident Response that became known as Security Orchestration, Automation, and Response (SOAR).</p><p>At Hexadite, we created a fully automated solution that enabled organizations to automatically investigate and remediate cyber-alerts. By revealing hidden threats and helping them remediate breaches through automation, we played a crucial role in helping companies be more secure. Looking back, where our platform added the most value was from data loss prevention (DLP) alerts. I’d say more than half of the alerts the platform investigated came from DLP tools, and a majority of those were false positives.</p><p>Building a startup from the ground up is no small feat, and having worked tirelessly to build and scale Hexadite, it was exciting yet bittersweet when the company was acquired by <a href="https://news.microsoft.com/2017/06/08/microsoft-signs-agreement-to-acquire-hexadite/">Microsoft</a> in 2017. As CEO, I was responsible for choosing the right partner and negotiating the acquisition. What helped me was having deep knowledge of the industry, along with a natural instinct for knowing when timing is right.</p><p>After the sale of Hexadite, I founded and led the <a href="https://www.microsoft.com/en-us/security/business/intelligent-security-association">Microsoft Intelligent Security Association (MISA)</a> program, working closely with hundreds of security vendors, including the Microsoft Information Protection (MIP) team. I saw firsthand the challenges of data security solutions, and in particular DLP tools. Since leaving Microsoft I’ve continued to invest in cybersecurity startups with a focus on data security, which I always found extremely interesting. So when I was thinking about what to build next, I knew it would be in this space.</p><h3>Mind meld</h3><p>However, the full picture of MIND wasn’t clear until I met my co-founders <a href="https://www.linkedin.com/in/itai-schwartz-9b893b214/">Itai</a> and <a href="https://www.linkedin.com/in/hodbn/">Hod</a>. Together, we spoke with more than a hundred CISOs, and it was obvious that innovation was needed in DLP. Even to this day, false positives continue to plague conventional tools, which leads to a host of major problems for companies. They’re a drain on budgets and resources, and are becoming increasingly ineffective with today’s explosion and sprawl of data. </p><p>Plus, people are now putting sensitive data into Gen AI tools, which is a cause for concern when it comes to data security. But innovation in AI has also been good for us at MIND. The maturity of AI has enabled our technology to achieve its potential, specifically with our proprietary <a href="https://mind.io/product/mind-ai">{children}</a> engine that autonomously monitors billions of data events 24x7 in real-time, classifies and categorizes sensitive data with precision to dramatically reduce false positives and noisy alerts, and remediates issues and risks with insightful action.</p><h3>Time is now to scale</h3><p>This moment coming out of stealth is definitely sweet after 18 months of hard work developing our product, delivering value to early customers and building our go-to-market engine. Now, we&#x27;re completely ready for scale. At the beginning, building the early team was so important. Today, we have the right people and the go-to market plan. Plus we’re constantly developing the team so they can continue to build and scale.</p><p>I believe that everything happens for a reason, and everything that happens is meant to be. I’ve seen this play out many times, both in business and life. There will always be setbacks, but we need to understand these as opportunities—stepping stones to something greater. Throughout my career, this belief has been my fuel. Everyone who wants to make an impact in this world will need to do hard things. The path will never be easy, but how we walk it makes a huge difference. And today we are ready to run and help our customers truly mind what matters.</p>]]></description>
            <link>https://mind.io/blog/why-mind-why-dlp-and-why-now</link>
            <guid isPermaLink="true">https://mind.io/blog/why-mind-why-dlp-and-why-now</guid>
            <dc:creator><![CDATA[Eran Barak]]></dc:creator>
            <pubDate>Wed, 30 Oct 2024 10:00:00 GMT</pubDate>
            <enclosure url="https://cdn.sanity.io/images/3l9nidp2/production/ea049a8c044a0e5a1478b82a35794af5c8fe2d4f-3600x2409.png?w=800" length="800" type="image/jpeg"/>
        </item>
    </channel>
</rss>