Cybersecurity at Scale: How CISOs Protect Fast-Growing Enterprise Data Assets
Fast-growing companies have a data problem that looks like success. Every new product, every new integration, every AI pilot creates more data, in more places, accessed by more identities, human and...
Fast-growing companies have a data problem that looks like success.
Table Of Content
Every new product, every new integration, every AI pilot creates more data, in more places, accessed by more identities, human and non-human. Security teams call it data sprawl. Mike Baker, VP and global CISO at DXC Technology, uses the term data sprawl to describe the growing amount of data on the move, something that accelerated first with cloud computing and now with AI.
Like other CISOs, Baker is re-examining his data protection program to ensure he and his team really understand where our data is, understand the sensitivity of the data across our estate, how it’s being accessed, and what environment the data is in.
That question, where is our data and who can access it, is now the central question for every scale-up that wants to become an enterprise.
The New CISO Mandate: From Protector to Enabler
The CISO role has expanded beyond recognition.
Like the threat landscape itself, the CISO’s role is getting bigger. They’re now responsible for data privacy, regulatory compliance, third-party cyber risk, and so much more, with 96% overseeing AI governance and risk across the enterprise.
At the same time, confidence is dropping. Proofpoint’s 2025 Voice of the CISO report found 76% of CISOs feel at risk of experiencing a material cyberattack in the next 12 months, up from 70% last year. Yet 58% admit their organization is unprepared to respond. Two-thirds experienced a material data loss in the past year, up from 46% in 2024. In the US, 70% of CISOs from organizations with 1,000 or more employees expressed concern over susceptibility to material cyberattacks, up from 68% and 48% in prior years. And 76% of CISOs report being overwhelmed by the increasing volume of threats detected from a growing number of tools on an increasing number of assets.
Gartner’s framing for 2025 is blunt: Security and risk management leaders are tasked with improving organizational resilience in a world of increasing risk.
Resilience, not just protection. That requires a shift EY describes clearly: CISOs must shift from being technical practitioners within their functions to becoming strategic enablers, Secure Creators, across the enterprise. This shift requires building deep sector and business acumen to align the cybersecurity function with organizational goals.
As leaders at ETCISO Secufest 2026 put it: CISOs must speak the language of growth, not just risk. Business acceleration and security enablement must move together.
Why Fast Growth Breaks Traditional Security
Fast-growing enterprise data assets fail for three reasons:
1. Sprawl outpaces governance. When sensitive information is spread widely, security teams might not know which repositories contain regulated data. Reducing data sprawl directly improves security by limiting the number of systems organizations must monitor and protect. With the average cost of a data breach in the United States estimated at $10.2 million, uncontrolled proliferation is a material enterprise risk.
Compliance reflects the pressure. Compliance is a top concern for 73% of respondents heading into 2024, with data governance at 53% and enterprise backup and recovery at 45%.
2. Identity is the new perimeter. The old castle-and-moat model assumed trust based on network location. Zero trust assumes threats exist both inside and outside, and therefore no entity is automatically trusted. This requires a shift from a network-centric to an identity-centric approach, where user and device identities become the focal point of security measures.
3. Tools outnumber talent. Budget increases that CISOs will receive in 2025 should prioritize addressing threats and controls in application security, people and business-critical infrastructure. Delivering revenue gains by protecting new digital businesses while keeping IT infrastructure safe on a tight budget is a proven way for CISOs to advance their careers. But tool sprawl creates its own risk. More tools, more logs, more blind spots.
The Blueprint: How Top CISOs Protect Data at Scale
Top CISOs at scale-ups that became enterprises use the same blueprint, built around five keys that elevate data security posture.
Pillar 1: Zero Trust Identity, with Data at the Center
It starts with an inside-out approach, focusing on the data itself and four critical factors: what data needs protection, where it is stored, who can access it, and how it can be accessed.
Implementation principles:
- Always authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies.
- Limit user access with just-in-time and just-enough-access, risk-based adaptive policies, and data protection to help secure both data and productivity.
- Enforce least privilege operationally: authenticate pipelines via federated identity like OIDC instead of god accounts, minimize runner permissions, and audit continuously.
The playbook leaders describe: zero-trust identity, data minimisation and a kill switch for partner integrations. The ability to cut off a partner, a service, or an agent that misbehaves without taking down the business.
Pillar 2: Data Minimization and Classification by Default
You cannot protect what you have not classified.
Leading teams implement automated data discovery that tags sensitivity at creation, not after. They enforce retention policies that delete what is not needed. Data minimization is not just a privacy tactic. It is a security tactic. Less data, fewer systems to monitor.
Pillar 3: Fusion, Not Silos
Cybersecurity challenges are sector-agnostic. Defining the strategy is important. A CISO is responsible for various factors but each function operates in silos. We need to synergize.
Top CISOs advocate for a fusion approach where data from different vectors is collated, and feedback loops are created. That means SOC, fraud, privacy, and IT operations share one telemetry fabric. AI is the force multiplier: Generative and agentic AI will start to give security operations centers the scale they’ve been missing, closing the talent shortage while attackers use AI to scale.
Pillar 4: Protect the Data Lifecycle, Not Just the Database
- At rest: Encrypt, with customer-managed keys where required.
- In transit: TLS 1.2+ and mTLS for service-to-service.
- In use: Confidential computing for sensitive workloads, DLP that scans files to ensure compliance, and controls that permit or deny upload, download, copy, or print based on identity.
- In backup: Immutable, offline, encrypted backups tested quarterly. Backup and recovery is a board-level resilience metric.
Pillar 5: Business-Aligned Metrics
CISOs who secure funding do not talk about blocked attacks. They talk about business value.
Translate security into growth language:
- Time to onboard a new enterprise customer with SSO and DLP enabled
- Percentage of sensitive data with classified owner and retention
- Mean time to revoke access for offboarded employees and non-human identities
- Cost avoided through consolidation of overlapping security tools
As EY notes, organizations must transition from being focused on asset protection to value generation for business. Many CISOs struggle because about 58% faced difficulties in conveying this to management, revealing the disconnect between cybersecurity programs and business requirements.
The 90-Day CISO Playbook for Scale-Ups
Days 1-30: Know your estate.
Run automated discovery for data repositories, shadow SaaS, and non-human identities. Map where regulated data lives. Answer Baker’s four questions: where is our data, how sensitive is it, how is it accessed, what environment is it in.
Days 31-60: Implement identity-first guardrails.
Enforce MFA, JIT access, and least privilege for top 10 critical data stores. Build the kill switch: documented, tested ability to disable partner access and revoke tokens in under 15 minutes.
Days 61-90: Operationalize fusion.
Create a single data security posture dashboard that combines DLP, cloud posture, identity governance, and third-party risk. Run a tabletop that includes a material data loss scenario. Proofpoint’s data shows two-thirds already lived it. Make sure you are not unprepared the second time.
Fast-growing enterprise data assets are not a liability. They are the business. The CISO who protects them at scale does not do it by buying more tools or saying no more often.
They do it by building a security model where business acceleration and security enablement move together, where trust is defined by identity, and where resilience is measured not by whether you get attacked, but by how quickly you continue to grow after you do.

No Comment! Be the first one.