Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementLogical SecuritySecurity & Business Resilience

Best practices for effectively securing sensitive data

By Bart Koek
Locked data

Image via Pixabay

September 22, 2023

In today’s data-driven landscape where data is power, organizations remain hyper-focused on how to leverage their data for BI, analytics and other business-driving initiatives. In fact, recent research shows that data leaders are primarily motivated by the need for high-quality analytics insights over compliance. 

However, in response to increasingly complex data privacy regulations and cybersecurity threats, organizations have no choice but to reexamine their data policies and rein in how data is accessed, processed, analyzed and shared. Most recently, the focus of privacy regulations has veered towards safeguarding personal data specifically, forcing teams to shift their data frameworks to remain compliant and secure. 

This has created a “crossroads” in the data security conversation around how to best juggle security and compliance, while remaining competitive with data. To have their cake and eat it too, teams must take the right steps to protect their sensitive data without completely locking it down, so they can continue to harness the power of data to propel their business forward. 

It’s a tricky balancing act, but there are a few best practices data teams can follow to help effectively secure their sensitive data while enabling trusted access. Here are six tips for organizations to help achieve data security success in our current technology environment. 

Define access controls based on data classification, not the data itself

Traditionally, data access control is defined based on the data itself, and data engineers or database administrators apply rules on a table-by-table basis. Not only is this unscalable, but you can also question if they are the right people to define those rules. A better approach is to use data classification, which is the process of identifying the types of data your organization holds and applying metadata tags or attributes, as the basis for data access controls. Then, to keep up with increasingly complicated regulations like Schrems II and GDPR, another best practice is to involve the legal or compliance teams in defining access controls. By defining access controls based on data classification and engaging the right people, you create a model that can scale with your data while complying with regulations. 

Enforce data privacy controls across all data platforms and consumption approaches 

Data privacy methods that organizations implement to protect, control and manage sensitive data access are highly regulated. And while it’s important to always ensure that these controls remain compliant and legal, it’s also key that they are consistently administered across all consumption approaches and platforms. Ultimately, data access should be consistent, regardless of the platform. This is the best way to prevent potential leaks that can occur when users with varying permissions access data across different data platforms. 

Reinforce data sharing processes

Despite growing data security concerns, it is clear that data sharing is essential in today’s business landscape. As data volumes continue to grow and organizations increasingly share more data both internally and externally, teams face the challenge of keeping every single one of these exchanges secure. This is especially vital if businesses are striving to obey specific data use and licensing agreements that enable them to monetize their data products. As a result, organizations should ensure their data sharing processes are adequately reinforced to avoid any data loss or breaches. Federated models for access control management help teams to share data in a controlled way. Centrally imposed rules for regulatory compliance can be augmented with rules defined by data owners for business and contractual compliance.  

Maintain visibility into sensitive data management for regulatory compliance

To meet mandatory regulations and compliance laws for sensitive data, organizations need to have constant visibility into what type of data is in their possession, where it is being accessed and the specific rules or requirements that apply to it. Having this information is especially helpful as regulations evolve or are created. For optimal visibility into their organization’s sensitive data management practices, this requires legal teams to coordinate with the data platform team, which handles the data and applies the policies, and the business team that authors them. This visibility not only helps prove compliance with regulatory requirements, but it also makes it easier to change access controls when required.

Scale data access controls with organization needs 

Controlling who can access sensitive data becomes more complex as data volumes, users, technologies, and regulations continue to grow and evolve, especially when trying to enforce policies consistently across platforms and access requests. It is not only the data that evolves but the organization as well. New people will join, employees will get promotions, and others might change teams internally. HR departments typically have JLM (joiners, leavers, movers) processes in place, but data platforms should also have such safeguards. Why? Once a user is approved in a manual access request, they will have access to the data no matter what other teams they may join in the future. However, by leveraging attributes, you can automatically give users access to the data they need when they join and as they move through the organization. To adapt and evolve, organizations must work to scale their access controls proportionately to their expanding data needs so that all of their security and access demands are sufficiently and efficiently met. 

Implement a strong and lasting data security strategy

Finally, in order to effectively secure sensitive data, organizations need a comprehensive and ironclad data security strategy that combats security threats in increasingly decentralized cloud data environments like data lakehouses and data mesh. Again, security must be maintained across all architectures to prevent unauthorized access or non-compliance. Strategies can look very different from business to business, but most commonly involve some combination of encryption, data masking, identity access management, authentication, data backup and resilience and data erasure. 

At the end of the day, there’s no silver bullet for guaranteed data security and access success. Every organization’s approach will look slightly different and continue to evolve depending on its data and security needs of the day. However, these fundamental best practices are a good place to start and are key to establishing a powerful, resilient and scalable data security strategy for years to come. 

KEYWORDS: access control best practices data security regulatory compliance security strategies

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bart Koek is Field CTO EMEA and APJ for Immuta.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Technologies & Solutions
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Coding

AI Emerges as the Top Concern for Security Leaders

Keyboard

Marks & Spencer Hackers Tricked IT Workers Into Resetting Passwords

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

September 29, 2025

Global Security Exchange (GSX)

 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Inside of water disposal pipe

    Best practices for securing critical and public infrastructure

    See More
  • call-center-freepik1170x658v8.jpg

    Best practices for securing voice networks

    See More
  • multicolor pyramid on red orange background

    The threat landscape and best practices for securing the edge

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!