|
By Bruce Chen
Most security tools evaluate risk by looking at the file, but risk is no longer confined to files. A clause pasted into an AI prompt carries no filename. A table summarized into Slack carries no label. A screenshot dropped into a deck carries no metadata, yet none of these trip an alert, because legacy data loss prevention (DLP) was built for a world where the sensitive unit is a discrete object with a name, a location, and a policy attached to it. That world is gone.
|
By Cyberhaven
When an auditor asks who can access protected health information, cardholder data, or EU personal data, and why, most security teams cannot answer with confidence right away. Access sprawls across cloud storage, SaaS applications, shared drives, and generative AI tools faster than manual reviews can track it. Permissions get granted for a single project and never revoked. A spreadsheet gets shared broadly and forgotten.
|
By Cyberhaven
Most enterprise data loss prevention (DLP) programs get judged on a single metric: how many exfiltration attempts did it block last quarter. That framing undersells what a modern DLP program needs to do. Sensitive data now leaves through AI prompts, personal cloud accounts, and agent-initiated file transfers that a legacy blocking rule alone was never built to catch, while auditors and boards expect evidence that the program is working, not just alerts confirming it.
|
By Cyberhaven
Most organizations already have an insider risk management (IRM) program in some form. They have a tool, a dashboard, and an analyst reviewing alerts. What they often lack is a program built on the specific capabilities that turn activity logs into stopped incidents and reduced insider risk.
|
By Cyberhaven
Security teams comparing unified data security platforms in 2026 are no longer just choosing between DLP vendors. They're deciding how much of their data security architecture, discovery, classification, enforcement, insider risk, and AI governance should live in one system versus remain assembled and operated from separate tools. That decision has gotten harder. DSPM vendors are adding DLP. DLP vendors are adding posture management. Everyone claims AI coverage.
|
By Bruce Chen
A new report from Software Analyst Cyber Research (SACR), The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security, outlines a new era of endpoint security shaped by AI agents, copilots, SaaS applications, browser-based workflows, and increasingly autonomous activity. The report introduces Endpoint Control and Prevention (ECP) as a framework for understanding this shift and the new security capabilities it requires.
|
By Cyberhaven
Every AI approval a security team makes feels reasonable in isolation. A security architect signs off on a generative AI writing tool for marketing. An engineering lead spins up an agent to triage support tickets. A finance team connects a copilot to its planning software. Individually, none of these decisions looks risky.
|
By Brian Hileman
Alert fatigue in DLP and insider risk management (IRM) programs doesn't get solved by adding more analysts or writing more rules. It gets solved when the system generating the alerts can already tell the difference between routine activity and genuine risk, so the queue analysts see is short because it's accurate, not because thresholds were loosened. That distinction matters because the two failure modes look identical from the outside.
|
By Cyberhaven
Most organizations that try to write an AI security policy start with two lists. Approved tools and banned tools. But, that list is inevitably out of date within a month. Employees adopt AI features embedded in everyday software faster than any review board can evaluate them, and a blanket ban does not stop the behavior, instead it pushes people toward personal accounts and unmanaged services.
|
By Cyberhaven
Every security architecture review this year eventually lands on the same question: does the existing data security stack already cover AI, or does AI security need its own budget line? The instinct to treat this as one more tool to evaluate and buy is understandable. It is also the wrong framework for modern data security. Traditional data security and AI security answer different questions about the same data. One assumes data stays inside known applications and moves through known channels.
|
By Cyberhaven
he video outlines how Cyberhaven's Data Security Posture Management (DSPM) provides a continuously updated, context-aware inventory of data at rest.
|
By Cyberhaven
AI changed work, Cyberhaven protects it. Cyberhaven exists to protect the way enterprises actually work today: with AI agents accessing, moving, and acting on data across every workflow. In this video, we share Cyberhaven's mission and our stance on data security for the agentic enterprise.Traditional data security, built for files at rest, wasn't built for AI agents acting at machine speed. Cyberhaven traces data through its full lifecycle and adapts protection as context changes, so security keeps pace with how work actually happens.
|
By Cyberhaven
Turn every analyst into a power user. Security investigations shouldn't take 45 minutes of tab-switching and manual querying. In this 20-minute walkthrough, Cyberhaven Director of Product Management Dave Stuart demos the Analyst Plugin, and shows how a single conversation replaces the queue.
|
By Cyberhaven
In this video, you will learn the five questions every data leak investigation must answer to be defensible — what the data is, where it originated, who accessed it, where it spread, and the fastest containment step — and why the visibility gap in most security stacks makes those questions impossible to answer instantly. You will also learn how combining DSPM baseline inventory with real-time data lineage replaces the high-stress scramble with surgical containment and audit-ready proof, so you move from "I think we're safe" to "here is the proof.".
|
By Cyberhaven
In this video, you will learn why locking down source systems like your CRM, HR database, and S3 buckets leaves your real risk surface exposed, how one regulated file fragments into CSV exports, screenshots, scripts, and AI prompts that shed their security context at every hop, and why both legacy DLP and traditional DSPM fail to act on these invisible derivatives. You will also learn how lineage-focused DSPM tracks the provenance of the data payload itself — every copy, paste, and save — so you can enforce policy on fragments instead of guessing from patterns.
|
By Cyberhaven
Autonomous AI agents are running on enterprise endpoints right now, accessing files, processing sensitive data, and executing actions outside the visibility of most security programs. This is Part 1 of Cyberhaven's four-part AI Security product launch series. What this video covers: Most AI security tools were built for browsers and SaaS apps. They cannot see agents operating at the OS level, coding assistants running in IDEs and CLIs, or MCP servers executing in the background. Cyberhaven's AI Security platform was built to close that gap.
|
By Cyberhaven
Security teams cannot govern what they cannot see. This is Part 2 of Cyberhaven's four-part AI Security product launch series, focused on Shadow AI Discovery and how Cyberhaven automatically inventories every AI app and agent running across your organization.
|
By Cyberhaven
Visibility without enforcement is just an alert backlog. This is Part 4 of Cyberhaven's four-part AI Security product launch series, covering how Cyberhaven enforces risk-based controls at the data level, not the tool level, using Data Lineage as the foundation.
|
By Cyberhaven
Knowing an AI tool exists is not the same as knowing what it did with your data. This is Part 3 of Cyberhaven's 4-part AI Security product launch series, covering Agentic AI Visibility and AI Risk IQ, Cyberhaven's evidence-based risk scoring system for every AI app and agent in your environment.
|
By Cyberhaven
In this video, you will learn why agentic browsers like ChatGPT Atlas, Perplexity Comet, and Arc have turned the browser into a double agent inside your enterprise, how shadow adoption is bypassing MDM and endpoint controls in days, and why indirect prompt injection creates an attack surface your file-based DLP cannot see. You will also learn how data lineage replaces noisy content inspection with origin-and-destination tracking, so you can stop the leak without blocking the tools your business depends on.
|
By Cyberhaven
Dive into our expertly curated DLP program checklist that will align with your organization's ambitious business and catapult them forward.
|
By Cyberhaven
In this guide we demystify DLP to distill the basics of DLP program development. Learn the essentials required to create scalable data security and data protection programs.
|
By Cyberhaven
Data is leaving your company in ways that didn't exist years ago-AirDrop, generative AI, and more. Legacy DLP hasn't kept up; now it's time to invest in more forward-looking solutions.
|
By Cyberhaven
DDR makes it possible to stop data exfiltration across all channels with one product and one set of policies.
- September 2026 (6)
- August 2026 (10)
- July 2026 (21)
- June 2026 (25)
- May 2026 (29)
- April 2026 (14)
- March 2026 (11)
- February 2026 (9)
- January 2026 (11)
- December 2025 (10)
- November 2025 (6)
- October 2025 (3)
- September 2025 (6)
- August 2025 (7)
- July 2025 (10)
- June 2025 (1)
- April 2025 (8)
- March 2025 (6)
- February 2025 (2)
- January 2025 (2)
- November 2024 (1)
- October 2024 (1)
- September 2024 (5)
- August 2024 (3)
- July 2024 (3)
- June 2024 (2)
- May 2024 (1)
- April 2024 (1)
- March 2024 (2)
- February 2024 (2)
- January 2024 (2)
- November 2023 (1)
- April 2023 (1)
Cyberhaven detects and stops the most critical insider risks to your most important data.
Let’s face it, data security products never lived up to our expectations and now that the way we work is changing they can’t keep up. Cyberhaven solves these challenges so companies can finally protect their data.
Data Detection and Response:
- Understand how data flows: See what systems store different types of data and how data moves within the company to new places and people.
- Stop data exfiltration anywhere: Block important data from leaving your control via cloud, web, email, removable storage, Bluetooth/AirDrop, and more.
- Accelerate internal investigations: Quickly understand an incident to determine user intent with a complete record of events before and during an incident.
- Detect and stop risky behavior: Instantly detect when a user handles important data in a risky way, stop them in real time, and coach them.
Trace your data to protect it like never before.