The Next Generation of Data Security, published by SANS Institute in April 2026, is a product review of the Lightbeam platform, a data security posture management (DSPM) solution that unifies sensitive data discovery and classification with identity context, access governance, and privacy operations. SANS reviewed Lightbeam using a provisioned test account connected to a broad set of data sources, including cloud storage, SaaS collaboration tools, and Microsoft Copilot, to evaluate its data discovery, access governance, retention, incident response, and privacy compliance capabilities.
Key findings:
- Lightbeam goes beyond visibility-only DSPM by linking sensitive data findings directly to identities and effective access paths, then enabling remediation actions (access revocation, redaction, account suspension) from the same workflow
- The platform assigns a "Risk Density" score to each data source, showing the percentage of content considered sensitive — in the test environment, an Azure Blob node scored 91% risk density
- Lightbeam can discover hundreds of unique sensitive data patterns and automatically correlate the same entity (e.g., a named individual) across multiple, otherwise-disconnected data sources
- The platform can detect and alert on sensitive data exposed through Microsoft Copilot, including tracking which users submitted prompts that returned sensitive content
- Access governance features let analysts identify objects with open or excessive access and revoke that access directly, with actions immediately tracked in an audit log
- Data retention and minimization policies can be configured to automatically archive or delete files based on content type, labels, folder location, or extracted attributes like contract expiration dates
- A "Ransomware Activity" policy type can automatically suspend user access when encrypted file activity crosses a defined threshold, without requiring manual intervention
- The Privacy Ops module covers the full data subject request (DSR) lifecycle under GDPR and CCPA-style regulations, using an existing data identity graph to produce reports automatically rather than requiring manual data collection via tickets
- Lightbeam automates Records of Processing Activity (RoPA) documentation and Privacy Impact Assessments (PIAs), prepopulating data sources and sensitive data types from DSPM scan results to streamline privacy compliance workflows
- Data classification, labeling, and attribute-set definitions can be customized, and labels integrate with existing enterprise tools like Microsoft Purview and Google Labels
The review finds that data risk is rarely a function of data alone, but of the intersection between sensitive data and the identities, roles, and privileges that can access it. Lightbeam's central differentiator is treating data security, access governance, and privacy compliance as one connected workflow rather than three separate tools, which the review found reduced the time from data discovery to actual risk remediation. This identity-aware approach was found to be particularly valuable during incident response, when security teams need to quickly determine what data a compromised identity could access.
This review is based on a SANS-conducted hands-on evaluation using a Lightbeam-provisioned test account rather than a practitioner survey, with reviewers directly exercising DSPM, access governance, retention, incident response, and privacy operations capabilities across a range of connected data sources.