One Platform to Understand and Secure Your Data, Even Under Multi-Regulator Scrutiny
Download resourcesAbout this session
Brian Mathews, principal solutions engineer at Cyberhaven with over two decades in data-loss-prevention roles at Vontu, Citrix ShareFile and Netskope, argues that point tools for classification, DLP, insider risk and AI security each see only a fragment of a file's life and cannot answer what regulators actually ask: where data was, who touched it, and what evidence proves it. He traces a file's journey, from creation through transformation, export and AI-tool ingestion, to show why a unified platform built on data lineage, not a snapshot, is needed. He covers Cyberhaven research showing roughly 40 percent of data moving into AI tools is sensitive, much via copy-paste into prompts rather than file uploads, and that around a third of usage still goes through personal rather than enterprise AI accounts. He flags agentic and agent-to-agent workflows as a new threat surface at machine speed, and insider risk around new hires and departing employees, including Quebec's Law 25 penalties. A cross-border SharePoint-export example shows how one file can trigger privacy, industry and residency obligations at once, and a Q&A closes on mapping controls to frameworks and the limits of relying on users, or Microsoft Purview labels, for classification.
Data security today typically consists of a stack of point tools or disparate modules. One tool classifies data, one runs DLP, one watches insiders, and another handles AI. Meanwhile, data moves constantly between these tools, and no single tool sees the full path. Agentic AI compounds the problem. Autonomous agents with employee-level access move and transform data at machine speed, multiplying the flows a bank must see, control, and explain. Global banks feel this pressure most. Dozens of regulators across jurisdictions, each with its own definition of sensitive data, now expect proof of control throughout the data lifecycle, not a snapshot in time. That proof depends on data lineage: the record of where data originated and everything that has touched it since.
This session shows what it looks like to unify DSPM, DLP, insider risk, and AI security around a single understanding of data, grounded in lineage: where data lives, how it moves, who or what acts on it (human or agent), and how protection should adapt as data enters riskier contexts.
Key takeaways
- Unify DSPM, DLP, insider-risk and AI-security visibility around data lineage so you can show where data originated and everything that touched it, not just the final egress event.
- Monitor what users paste into AI prompts, not only what they upload as files; a large share of sensitive AI-tool exposure happens through copy-paste.
- Assume some AI usage still goes through personal rather than enterprise accounts even where enterprise licenses exist, and gain visibility into which account a session is using.
- Extend data-loss-prevention policies to agentic and agent-to-agent workflows, which can query, modify and exfiltrate data at machine speed with far less oversight than a human user.
- Do not rely solely on end users, or on a single classification pass such as Microsoft Purview labels, to mark sensitivity; classification changes over time and needs continuous re-evaluation.
Speakers

Brian Mathews is a Principal Solutions Engineer at Cyberhaven with over 20 years of experience in data protection, Data Security Posture Management (DSPM), DLP, and insider risk management. His career began at Compuware and took a pivotal turn at… Read moreRead less
Brian Mathews is a Principal Solutions Engineer at Cyberhaven with over 20 years of experience in data protection, Data Security Posture Management (DSPM), DLP, and insider risk management. His career began at Compuware and took a pivotal turn at Vontu, the pioneer of DLP, later acquired by Symantec. Brian has held key roles at Citrix ShareFile and Netskope, where he led teams helping enterprises secure sensitive data across cloud and modern environments.
Today, Brian helps organizations rethink data security for the AI era by combining DSPM, insider risk, and AI-driven approaches to understand where sensitive data lives, how it’s being used, and when that use introduces risk. Known for his engaging style, he connects deep technical insight with real-world application, empowering organizations to protect their most valuable information while enabling employees to work securely and embrace AI.

