|
By Cyberhaven
AI has changed how work gets done. Agents can plan tasks, query enterprise repositories, invoke tools, write code, call application programming interfaces (APIs), and take actions across connected systems. As they work, they create, copy, fragment, transform, and share data across workflows. A perimeter and a one-time authorization decision do not provide enough control for this operating model. An agent can chain permissions, tools, integrations, and data sources while completing a task.
|
By Nishant Doshi
AI didn't replace the old ways data leaves a company. It added new methods on top and gave insiders a way to chain them together. You only see the chain if one sensor watches humans and AI together. If you spend enough time around CISOs / data security/ insider risk practitioners who have run these program for a decade you won't hear that AI is the only thing that matters.
|
By Cyberhaven
Ask five security leaders what "data security for generative AI" covers and you'll get five different answers. Some may point to an existing DLP rule for ChatGPT, while others would point to an AI acceptable use policy. Some operate under the assumption that their DSPM vendor already handles genAI security. The confusion isn't about effort, as most teams are actively trying to get ahead of GenAI risk.
|
By Franklin Nguyen
There is a difference between watching data go into an AI tool and knowing what is inside it. Most security tools do the first. Few do the second. Employees now keep contracts, source code, and customer records inside their AI workspaces, in chats and projects that build up for months. Cyberhaven's integration with Claude's Compliance API brings that content into view for Claude Enterprise, and ties it back to where it came from.
|
By Cyberhaven
Teams evaluating whether to replace or extend an existing DLP stack often run into the same question: Is this actually a different category of tool, or just DLP with an AI feature bolted on? The two security categories overlap enough to cause real confusion in a buying cycle, and many may think that once will, by extension cover the other.
|
By Franklin Nguyen
New AI tools appear every day. The novelty and utility they bring, along with the constant pressure to be more productive, pull employees toward them to get work done faster. The intent is good but the effect can range from problematic to damaging, because while there are rules in place for sanctioned tools, there are none for the ones that quietly show up in between.
|
By Cyberhaven
Departing employees still email files to personal accounts and copy them to USB drives. Now they also paste sensitive content into ChatGPT, Claude, or Gemini to summarize a codebase, draft a portfolio piece, or package a project before their last day. Neither channel has replaced the other. The attack surface has simply gotten wider, and most security teams are still staffed and tooled for the channels they already know how to watch.
|
By Bruce Chen
Most security tools evaluate risk by looking at the file, but risk is no longer confined to files. A clause pasted into an AI prompt carries no filename. A table summarized into Slack carries no label. A screenshot dropped into a deck carries no metadata, yet none of these trip an alert, because legacy data loss prevention (DLP) was built for a world where the sensitive unit is a discrete object with a name, a location, and a policy attached to it. That world is gone.
|
By Cyberhaven
When an auditor asks who can access protected health information, cardholder data, or EU personal data, and why, most security teams cannot answer with confidence right away. Access sprawls across cloud storage, SaaS applications, shared drives, and generative AI tools faster than manual reviews can track it. Permissions get granted for a single project and never revoked. A spreadsheet gets shared broadly and forgotten.
|
By Cyberhaven
Most enterprise data loss prevention (DLP) programs get judged on a single metric: how many exfiltration attempts did it block last quarter. That framing undersells what a modern DLP program needs to do. Sensitive data now leaves through AI prompts, personal cloud accounts, and agent-initiated file transfers that a legacy blocking rule alone was never built to catch, while auditors and boards expect evidence that the program is working, not just alerts confirming it.
|
By Cyberhaven
he video outlines how Cyberhaven's Data Security Posture Management (DSPM) provides a continuously updated, context-aware inventory of data at rest.
|
By Cyberhaven
AI changed work, Cyberhaven protects it. Cyberhaven exists to protect the way enterprises actually work today: with AI agents accessing, moving, and acting on data across every workflow. In this video, we share Cyberhaven's mission and our stance on data security for the agentic enterprise.Traditional data security, built for files at rest, wasn't built for AI agents acting at machine speed. Cyberhaven traces data through its full lifecycle and adapts protection as context changes, so security keeps pace with how work actually happens.
|
By Cyberhaven
Turn every analyst into a power user. Security investigations shouldn't take 45 minutes of tab-switching and manual querying. In this 20-minute walkthrough, Cyberhaven Director of Product Management Dave Stuart demos the Analyst Plugin, and shows how a single conversation replaces the queue.
|
By Cyberhaven
In this video, you will learn the five questions every data leak investigation must answer to be defensible — what the data is, where it originated, who accessed it, where it spread, and the fastest containment step — and why the visibility gap in most security stacks makes those questions impossible to answer instantly. You will also learn how combining DSPM baseline inventory with real-time data lineage replaces the high-stress scramble with surgical containment and audit-ready proof, so you move from "I think we're safe" to "here is the proof.".
|
By Cyberhaven
In this video, you will learn why locking down source systems like your CRM, HR database, and S3 buckets leaves your real risk surface exposed, how one regulated file fragments into CSV exports, screenshots, scripts, and AI prompts that shed their security context at every hop, and why both legacy DLP and traditional DSPM fail to act on these invisible derivatives. You will also learn how lineage-focused DSPM tracks the provenance of the data payload itself — every copy, paste, and save — so you can enforce policy on fragments instead of guessing from patterns.
|
By Cyberhaven
Autonomous AI agents are running on enterprise endpoints right now, accessing files, processing sensitive data, and executing actions outside the visibility of most security programs. This is Part 1 of Cyberhaven's four-part AI Security product launch series. What this video covers: Most AI security tools were built for browsers and SaaS apps. They cannot see agents operating at the OS level, coding assistants running in IDEs and CLIs, or MCP servers executing in the background. Cyberhaven's AI Security platform was built to close that gap.
|
By Cyberhaven
Security teams cannot govern what they cannot see. This is Part 2 of Cyberhaven's four-part AI Security product launch series, focused on Shadow AI Discovery and how Cyberhaven automatically inventories every AI app and agent running across your organization.
|
By Cyberhaven
Visibility without enforcement is just an alert backlog. This is Part 4 of Cyberhaven's four-part AI Security product launch series, covering how Cyberhaven enforces risk-based controls at the data level, not the tool level, using Data Lineage as the foundation.
|
By Cyberhaven
Knowing an AI tool exists is not the same as knowing what it did with your data. This is Part 3 of Cyberhaven's 4-part AI Security product launch series, covering Agentic AI Visibility and AI Risk IQ, Cyberhaven's evidence-based risk scoring system for every AI app and agent in your environment.
|
By Cyberhaven
In this video, you will learn why agentic browsers like ChatGPT Atlas, Perplexity Comet, and Arc have turned the browser into a double agent inside your enterprise, how shadow adoption is bypassing MDM and endpoint controls in days, and why indirect prompt injection creates an attack surface your file-based DLP cannot see. You will also learn how data lineage replaces noisy content inspection with origin-and-destination tracking, so you can stop the leak without blocking the tools your business depends on.
|
By Cyberhaven
Dive into our expertly curated DLP program checklist that will align with your organization's ambitious business and catapult them forward.
|
By Cyberhaven
In this guide we demystify DLP to distill the basics of DLP program development. Learn the essentials required to create scalable data security and data protection programs.
|
By Cyberhaven
Data is leaving your company in ways that didn't exist years ago-AirDrop, generative AI, and more. Legacy DLP hasn't kept up; now it's time to invest in more forward-looking solutions.
|
By Cyberhaven
DDR makes it possible to stop data exfiltration across all channels with one product and one set of policies.
- October 2026 (3)
- September 2026 (10)
- August 2026 (10)
- July 2026 (21)
- June 2026 (25)
- May 2026 (29)
- April 2026 (14)
- March 2026 (11)
- February 2026 (9)
- January 2026 (11)
- December 2025 (10)
- November 2025 (6)
- October 2025 (3)
- September 2025 (6)
- August 2025 (7)
- July 2025 (10)
- June 2025 (1)
- April 2025 (8)
- March 2025 (6)
- February 2025 (2)
- January 2025 (2)
- November 2024 (1)
- October 2024 (1)
- September 2024 (5)
- August 2024 (3)
- July 2024 (3)
- June 2024 (2)
- May 2024 (1)
- April 2024 (1)
- March 2024 (2)
- February 2024 (2)
- January 2024 (2)
- November 2023 (1)
- April 2023 (1)
Cyberhaven detects and stops the most critical insider risks to your most important data.
Let’s face it, data security products never lived up to our expectations and now that the way we work is changing they can’t keep up. Cyberhaven solves these challenges so companies can finally protect their data.
Data Detection and Response:
- Understand how data flows: See what systems store different types of data and how data moves within the company to new places and people.
- Stop data exfiltration anywhere: Block important data from leaving your control via cloud, web, email, removable storage, Bluetooth/AirDrop, and more.
- Accelerate internal investigations: Quickly understand an incident to determine user intent with a complete record of events before and during an incident.
- Detect and stop risky behavior: Instantly detect when a user handles important data in a risky way, stop them in real time, and coach them.
Trace your data to protect it like never before.