CISO Talks: Data Visibility Tops the CISO Wish List
When we asked CISOs coast to coast what would most improve their data security, visibility was the top answer. Here's where CISOs are having the biggest challenges with data visibility, and what's working.

Key Takeaways:
- Data sprawl is driving risk. CISOs describe sensitive data scattered across dozens of repositories and copies. IBM found 35% of breaches involve this kind of unmanaged "shadow data," with breaches taking an average of 291 days to identify.
- Knowing where data lives isn't enough. CISOs say they can find and label sensitive data but can't see where it goes. Visibility now has to cover data in motion, not just data at rest.
- Automation and continuous discovery are working. CISOs report results from automated classification, discovery that runs continuously instead of once, and alerts that let employees fix their own mistakes.
Welcome to the CISO Talks series. In the opening article, we shared how 159 security leaders answered when we asked, “What is the one thing that would most improve your organization’s data security posture?”
The answer: visibility and detection.
At CISO Executive Network roundtables we attended from coast to coast, security leaders described environments carrying decades of accumulated data across file servers, home drives, cloud storage, and SaaS applications created by disparate teams.
Now add the rapid spread of AI tools in the workplace, and seeing where sensitive data lives and where it’s headed can feel like driving Route 66 in a thick fog.
But the conversations weren't only about the fog. Many of the same leaders shared what's helping them see through it.
.png)
‘Too Many Data Repositories’
At our Las Vegas roundtable, a security architecture director at a large industrial and scientific manufacturer put it this way: “It’s not even too much data, it’s too many data repositories.”
It was a common sentiment on the tour. At the Great Lakes gathering in Columbus, a CISO for a regional healthcare system lamented data scattered across Box, Dropbox, OneDrive, Google Drive, and AI data lakes. In Boston, a CISO talked about the sprawl left behind by acquisitions: legacy file servers and home drives, each with its own naming conventions.
Then there are the copies. A CISO at a large health insurer described what his team uncovers as its visibility improves: “We’ll find the same file in literally 50 different locations.”
That kind of sprawl has consequences. IBM’s 2024 Cost of a Data Breach research found that 35% of breaches involved data stored in unmanaged sources, or “shadow data.” Those breaches took an average of 291 days to identify and contain, and cost $5.27 million on average.
The Corporate Junk Drawer
Data also becomes harder to manage simply because organizations keep so much of it for so long.
“We’re treating our data like a junk drawer,” a security operations director at a regional healthcare organization told one group. “Everybody’s keeping stuff they shouldn’t keep.”
A security leader at the Boston roundtable described a basement still filled with banker boxes of documents. Ask employees to get rid of old information, he said, and the response is predictable: “No, no, no, I might need it someday.”
For some companies, that question applies to decades of information. A privacy officer at an engineering and scientific consulting firm said his organization still has records dating to the 1960s. They were eventually scanned so they could be stored digitally. Digitization solved the storage problem. It did not answer the larger question of what should still be kept.
One roundtable moderator argued that the common term "data retention" sounds like an instruction to keep something. He prefers "data minimization" or "data destruction," which puts the emphasis on a different question: If the organization no longer needs the data, why continue carrying the risk?
A consultant at the Great Lakes roundtable offered a practical way to get that conversation started. Tie stored data to the owner's cost center and show them it hasn't been accessed in years. It's easier to let go of data when you can see what it's costing you.
Data in Movement Must Be Visible
For years, data visibility has largely focused on discovery: finding sensitive data, classifying it, and understanding where it resides. Those capabilities remain essential, but today’s environments demand visibility beyond the repository. Because data moves constantly.
So security teams need to answer two questions: Where is our sensitive data, and where is it going?
A security leader who oversees AI and data security at a large insurer described hitting exactly that wall. "We've scanned and labeled everything. Okay, now what?" A bank CISO in Boston said his team has "decent visibility into who has access to what, but what we really don't have is how it's being used." And a director of information security at a large law firm, where nearly everything is sensitive, said he wants tools that think "less about the type of data and more about source and destination."
Now add the rapid spread of AI tools in the workplace, and seeing where sensitive data lives and where it’s headed can feel like driving Route 66 in a thick fog.
A company can spend enormous effort building an inventory of sensitive data and still miss the moment when an employee sends a copy to a personal account, uploads it to an unapproved application, or gives an AI tool access to information it shouldn't have.
CISOs also made clear they don't expect employees to close that gap for them. Years of manual classification have shown the limits of relying on people to consistently tag information, follow naming conventions, and put every file in the right place.
At the Great Lakes roundtable, a healthcare technology CISO said he wants automated discovery and classification that happens on the fly, so his team spends less time chasing data and more time deciding what to do with it. In Las Vegas, a financial services CISO said his team is starting automated tagging at the moment data is created, so protections apply automatically. His team drafted the criticality levels, and legal signed off on them.
The good news is that classifying data in movement is already possible.
What's Working
Several leaders shared practices that will help them see more and act faster.
Treat discovery as continuous. An IS director at a software company said his team had run discovery as a periodic exercise and found the results went stale almost immediately. "By the time we're done, it's very likely out of date," he said. "We need a tool that identifies new data consistently."
Turn detection into a nudge. A CISO at a major auto insurer described a control his team is testing for sensitive emails sent to personal webmail accounts. Instead of silently blocking the message, the system quarantines it and tells the sender it looked suspicious, with a link to a portal where they can release it themselves. The goal is for employees to police themselves. A roundtable host shared a similar story from another member: a simple "do you really want to send this?" prompt that also notified the sender's manager made incidents "plummet."
Use exercises to find what tools miss. A senior director of security at a Boston software company runs incident response tabletop exercises every month. One of them revealed cloud storage buckets holding personal data for only part of each day. "Within that eight-hour window, I can have a data breach," she said.
A head of cyber at a Las Vegas resort takes a sharper approach. His team finds an area with weak data security, runs a targeted red-team exercise, and routes the report through outside counsel. He called it "a controlled breach that we can tell the story with."
One caution came through, too. A CISO at a Western law firm said his team had deployed classification and monitoring tools, and "alert fatigue has become a real thing." More visibility helps only when the signal is accurate enough to act on.
What Data Visibility Looks Like
Taken together, the conversations pointed to a broader definition of data visibility, one that connects what the data is, where it is, who's moving it, and how it's moving. Those signals give security teams a better chance of distinguishing routine business activity from movement that creates risk.
The practical steps line up with what CISOs described. Shrink the footprint by eliminating data the organization no longer needs. Automate how sensitive data is identified and classified, including while it's moving. And watch for the moment data leaves, not just where it sits.
In 2026, clearing the fog means seeing where sensitive data lives and where it's headed.
About the CISO Talks series: In summer 2026, ORION Security joined CISO roundtables in Boston, Columbus, Minneapolis, Las Vegas,and San Diego, hosted by CISO Executive Network, a peer-to-peer networking group. The 159 security leaders who attended spoke candidly about security gaps, what's getting funded, and what needs fixing. CISO Talks shares what we learned from those conversations. Attendee names and companies are not shared.
Read the first article in the series: CISO Talks: Top 5 Focus Areas of 2026
Want better visibility into your sensitive data? See how ORION Security shows where it lives and where it's going. Book a demo.

.png)
