September 17, 2026

Alera Group's CISO on Getting Instant Value from AI-Native DLP

At Black Hat 2026, Matthew Mudry tells ORION Security's Jonathan Kreiner how he skipped a burdensome data classification project altogether and moved straight into catching sensitive data with confidence.

Mary Hayes WeierContent Marketing Lead

Key Takeaways:

  • Traditional DLP relies on simple pattern matching, like stringing together nine-digit numbers, which drives high false positive rates and keeps most teams stuck in monitoring mode.
  • "We were about to undertake a big data classification exercise in the organization. And with the introduction of AI into DLP platforms, especially like ORION, that's no longer needed."—Matthew Mudry, CISO, Alera Group
  • After a proof of value, Alera Group moved from detection to prevention mode within weeks, faster than legacy DLP typically allows.
  • The manual workload has dropped sharply. Team members who once weeded out false positives full time now check the system once or twice a day.
  • Thank you! Your submission has been received!
    Oops! Something went wrong while submitting the form.

    At Black Hat 2026, ORION Security Co-founder and CTO Jonathan Kreiner sat down with Matthew Mudry, CISO at Alera Group, to talk about why traditional data loss prevention (DLP) has failed organizations for decades and what's changed.

    Watch the conversation below.

    Video: Alera Group's CISO on AI-Native DLP

    Transcript:  Alera Group's CISO on AI-Native DLP

    JONATHAN: I'm Jonathan, co-founder and CTO at ORION Security. I'm here with Matthew from Alera Group at Black Hat 2026. How's it going, Matt?

    MATTHEW: So far, so good. We're having a great time. What we generally like to do is spend our time in the vendor halls just talking to different vendors, seeing what cool new technologies there are out there, and [discovering] problems that we may not know we had and the ways we can fix them.

    MATTHEW: So it's great. I love doing this.

    JONATHAN: Yeah. And we hear many people here at Black Hat on the floor talking about replacing their DLP, their traditional DLP.

    JONATHAN: Why; what happened with traditional DLP and why do we need to replace it right now?

    MATTHEW: Yeah. So traditional DPS failed me for decades. That's a big reason why people are obviously talking about it.

    MATTHEW: Now that AI has come into the picture, it's really changed the landscape on how people approach DLP, and it's more effective right now with that technology in place. It makes DLP a solvable problem and not the headache it used to be.

    JONATHAN: Yeah, I think that AI is here in the problem and in the solution when we talk about DLP.

    JONATHAN:  Do you use many AI tools today? 

    MATTHEW: We do use a good number of AI tools today. It's ever growing, right? We're fighting AI with AI is what I like to say. But specifically with DLP, now it's taking the guesswork out.

    MATTHEW: A lot of the false positives go away. AI is better at classifying data and understanding which is sensitive and which is not, versus just stringing together nine-digit numbers and saying that’s a social [security] or a credit card number. So yeah, we are leveraging AI and it's honestly making the job a little easier in some aspects.

    MATTHEW: But obviously our bad adversaries are using AI to fight us as well. So that's making things a lot more challenging.

    JONATHAN: Yeah. And you mentioned the nine-digit number. I hear that so often, because most data today is not really structured anymore. 

    MATTHEW: Right.

    JONATHAN: So you have the same problems around unstructured data classification prevention as well?

    MATTHEW: Well, structured or non-structured, where I pivoted is when we were about to undertake a big data classification, or a big data labeling exercise in the organization. And with the introduction of AI into DLP platforms, especially like ORION, that's no longer needed.

    MATTHEW: And to my knowledge, I'm not aware of any framework or requirement or regulatory body that requires you to actually classify labeled data, but you obviously need to be aware of where your sensitive data lives and sits.

    Having AI able to recognize sensitive data with a high level of fidelity makes my data classification project go to bed. Now we could just focus on identifying where data is going and obviously coming from.

    JONATHAN: Because you can detect a credit card and verify that it is indeed a credit card. If someone like an employee buys something on Amazon, you don't want to block him, right? It's not meaningful for the company. So, what about context? Do you think this is the new way of solving DLP?

    MATTHEW: 100% the new way.

    MATTHEW: The context is so important, right? To your point, say you want to buy something on Amazon that shouldn't be blocked. But if you're going to send that [number] to somebody else, or a third party, or send a large grouping of social security numbers, credit card numbers, whatever it may be, that obviously you want to be blocked.

    MATTHEW: AI has the ability to pull in that context, making my team's job a whole lot easier.

    JONATHAN: So why did you start looking for a DLP this year, and how do you find us?

    MATTHEW: Interesting question. I wasn't actually looking for a DLP solution. I leverage Black Hat, Sagetap, a number of different things to find out about new technologies.

    MATTHEW: DLP was honestly a problem I was going to hold off for another day. And what I mean by that is I had a lot of other challenges that I was facing, and solving for DLP was something I had to push; I was planning on pushing off just because of the level of effort it took to get it done.

    MATTHEW: So again, something I was not actively looking for. I stumbled across [ORION Security] on Sagetap and was like, oh my God, wait a minute. Maybe I could solve for this a little sooner while I'm tackling these other challenges, because I don't have to put all this effort into it. So we POV’ed it, we threw it in, and we realized very quickly it was identifying sensitive information very quickly.

    MATTHEW: Not much effort was involved. We went from having a legacy DLP solution to something that was more effective and something we were able to leverage literally, instantly.

    JONATHAN: Right. Why do you think that people need to classify all the data and discover all the data before moving to a DLP?

    JONATHAN: Why do they think that it's really a way to go?

    MATTHEW: Yeah. I think it's just because if you don't classify data, you just get that huge false positive rate, right? Your return on all this data that you thought you classified correctly, and then you're hitting on nine digit numbers that are not Social Security Security numbers and other things;  credit card numbers, sensitive information, whatever it may be.

    MATTHEW: When we put in ORION and it was identifying health care information very well.

    JONATHAN:I hear a lot that because of this false positive rate, you can't really move to prevention. So that means that you have a “DLP solution,” but honestly you only have monitoring mode, right?

    MATTHEW: Yes. 

    JONATHAN: You can't really prevent the data exfiltration. 

    JONATHAN: We see that a lot — failed implementations of DLP. Do you have anything to share about that from past experiences, maybe?

    MATTHEW: Yeah, I've used two products in the past, which I won't name, but they are still out there, and it was painful. I had a team member or two literally designated to weeding out all the false positives, identifying and continuing classifying data to get as best as we could.

    MATTHEW: But the pendulum was always either too sensitive and we’re stopping things that we shouldn't be stopping, or too light, and we're not stopping all the things that we should be. So having AI really helps you find that balance and that sweet spot to catching all the sensitive information.

    JONATHAN: Yeah, instead of working case by case management, an AI agent does it on its own.

    MATTHEW: Yeah.

    MATTHEW: And my team members now are not dedicated to this. They probably look at the solution once or twice a day, or if there is some type of false positive that comes up, which is very rare, they can go on and do their day job with other things.

    JONATHAN: Right. And I think the ability to learn from these false positives and get better over time, it's another thing that is crucial to make the DLP actually work.

    MATTHEW: Yeah, it's very huge. And we very quickly built a strong level of confidence in the tool’s ability to correctly identify information. We were really able to put it in prevention mode very quickly. We went from detection for a few weeks and then we literally just started preventing quickly thereafter.

    JONATHAN: So thank you, Matt. I hope you have a great time with Black Hat here and see you again. 

    MATTHEW: Thank you.

    The DLP renaissance, as it unfolds

    Customer Stories

    Alera Group's CISO on Getting Instant Value from AI-Native DLP

    At Black Hat 2026, Matthew Mudry tells ORION Security's Jonathan Kreiner how he skipped a burdensome data classification project altogether and moved straight into catching sensitive data with confidence.

    September 17, 2026
    DLP Strategy & Trends

    CISO Talks: Top 5 Focus Areas of 2026

    We traveled coast to coast, asking 159 CISOs in 5 cities what's most important right now in data security. Here's what they had to say.

    September 16, 2026
    Guides & Explainers

    Data Leak Prevention: A Practical Playbook

    Data leak prevention works by watching where sensitive data moves and weighing the intent behind each action. Here's a practical playbook for the AI era.

    September 16, 2026