Group Purchasing
Group Purchasing

The Next Generation of Data Security

The Next Generation of Data Security (PDF, 4.67MB)Published: 06 Apr, 2026
Created by:

Thank You To Our Sponsor

The Next Generation of Data Security, published by SANS Institute in April 2026, is a product review of the Lightbeam platform, a data security posture management (DSPM) solution that unifies sensitive data discovery and classification with identity context, access governance, and privacy operations. SANS reviewed Lightbeam using a provisioned test account connected to a broad set of data sources, including cloud storage, SaaS collaboration tools, and Microsoft Copilot, to evaluate its data discovery, access governance, retention, incident response, and privacy compliance capabilities.

Key findings:

  • Lightbeam goes beyond visibility-only DSPM by linking sensitive data findings directly to identities and effective access paths, then enabling remediation actions (access revocation, redaction, account suspension) from the same workflow
  • The platform assigns a "Risk Density" score to each data source, showing the percentage of content considered sensitive — in the test environment, an Azure Blob node scored 91% risk density
  • Lightbeam can discover hundreds of unique sensitive data patterns and automatically correlate the same entity (e.g., a named individual) across multiple, otherwise-disconnected data sources
  • The platform can detect and alert on sensitive data exposed through Microsoft Copilot, including tracking which users submitted prompts that returned sensitive content
  • Access governance features let analysts identify objects with open or excessive access and revoke that access directly, with actions immediately tracked in an audit log
  • Data retention and minimization policies can be configured to automatically archive or delete files based on content type, labels, folder location, or extracted attributes like contract expiration dates
  • A "Ransomware Activity" policy type can automatically suspend user access when encrypted file activity crosses a defined threshold, without requiring manual intervention
  • The Privacy Ops module covers the full data subject request (DSR) lifecycle under GDPR and CCPA-style regulations, using an existing data identity graph to produce reports automatically rather than requiring manual data collection via tickets
  • Lightbeam automates Records of Processing Activity (RoPA) documentation and Privacy Impact Assessments (PIAs), prepopulating data sources and sensitive data types from DSPM scan results to streamline privacy compliance workflows
  • Data classification, labeling, and attribute-set definitions can be customized, and labels integrate with existing enterprise tools like Microsoft Purview and Google Labels

The review finds that data risk is rarely a function of data alone, but of the intersection between sensitive data and the identities, roles, and privileges that can access it. Lightbeam's central differentiator is treating data security, access governance, and privacy compliance as one connected workflow rather than three separate tools, which the review found reduced the time from data discovery to actual risk remediation. This identity-aware approach was found to be particularly valuable during incident response, when security teams need to quickly determine what data a compromised identity could access. This review is based on a SANS-conducted hands-on evaluation using a Lightbeam-provisioned test account rather than a practitioner survey, with reviewers directly exercising DSPM, access governance, retention, incident response, and privacy operations capabilities across a range of connected data sources.

The Next Generation of Data Security

Related Webcast

As enterprises accelerate cloud adoption and SaaS usage, sensitive data sprawl has quietly become one of the most consequential security challenges facing organizations today.

Webcast Abstract Image

FAQ

Data security posture management (DSPM) continuously discovers, classifies, and contextualizes sensitive data across cloud and SaaS environments, answering where sensitive data lives, what type it is, and who can access it. Unlike legacy DLP, which relies on predefined paths or inline inspection, DSPM platforms like Lightbeam analyze data at rest and in use, surfacing previously unknown data stores. 

Yes. Lightbeam can detect and alert sensitive data transmitted through Copilot, and it tracks which users submitted the prompts that returned sensitive information, integrating with identity stores to show department and group membership for those users. 

Lightbeam maintains a data identity graph that already maps sensitive data to specific individuals, so it can automate the production of DSR reports rather than requiring the organization to manually collect data through tickets sent across the company.

It can take direct action. Reviewed capabilities included revoking access to exposed objects, suspending user accounts automatically during suspected ransomware activity, and archiving or deleting data per configurable retention policies — all logged in an audit trail.

Because overprivileged users, service accounts, APIs, and AI agents often have far broader access to sensitive data than intended, turning routine identity misconfigurations into breach-scale events; effective data security requires mapping sensitive data to the identities and privileges that can interact with it. 

Meet Your Author

Dave Shackleford
Dave Shackleford

Dave Shackleford

Senior Instructor

Cybersecurity leader Dave Shackleford combines decades of enterprise defense, cloud security, and hands-on consulting experience to help students master real-world security operations and modern threat defense.

Read more about Dave Shackleford