#Data Security

Every story tagged Data Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

12 stories · open in the command center

  • Security & PrivacyAndroid PoliceChandra Steele2m

    Sunbird app relaunches for blue bubble messaging but at what cost?

    Sunbird, an Android messaging app that enables blue bubble iMessage compatibility, has relaunched after previous security vulnerabilities forced its removal from the Play Store, positioning itself as a superior alternative to Apple's RCS implementation despite introducing third-party security and data privacy risks. The app's return signals growing enterprise and consumer demand for cross-platform messaging parity, but IT leaders must weigh this against the security implications of routing sensitive communications through an unproven intermediary service. Organizations should establish clear policies regarding third-party messaging applications and their compatibility with corporate security frameworks, as employee adoption of such tools could introduce data exfiltration and compliance risks.

  • Security & PrivacyCIO Online4m

    Control is the feature: The real AI risk is the lawyer you told not to use it

    Organizations that prohibit AI tools or blindly procure enterprise solutions without understanding them are creating hidden risks and liability exposure; instead, IT and legal leaders must build organizational competence by requiring teams to understand how AI systems handle sensitive data, establish clear governance boundaries, and maintain human oversight of all outputs. The strategic imperative is shifting from binary choices (ban or buy) to controlled adoption with technical literacy, enabling faster, safer use of AI while maintaining confidentiality and professional accountability.

  • Security & PrivacyTechMemeKyle Alspach2m

    Data security startup Cyera agrees to acquire Oasis Security, which provides non-human identity security, in a deal valued at about $1B (Kyle Alspach/CRN)

    Cyera's $1 billion acquisition of Oasis Security signals the strategic importance of non-human identity security in comprehensive data protection strategies, as organizations increasingly recognize that API keys, service accounts, and machine identities pose significant security risks alongside human user management. This consolidation indicates that IT leaders must expand their identity and access management (IAM) programs beyond traditional human-centric models to address the growing attack surface created by cloud-native architectures and automated systems. The deal reflects market maturation around securing the full identity ecosystem, suggesting that organizations managing complex multi-cloud environments will face competitive pressure to implement non-human identity governance as a critical component of their security posture.

  • Security & PrivacyHacker News3m

    Your Kids' School Bus Is About to Become a Roaming Surveillance Vehicle

    School bus stop-arm camera systems are being repurposed as mobile license plate readers to continuously track vehicles and sell data to law enforcement, creating a significant expansion of warrantless mass surveillance infrastructure across 24+ states. This development represents a critical governance gap where technology deployment is outpacing regulatory frameworks, exposing organizations and citizens to potential privacy violations and liability risks. For IT leaders, this signals the urgent need to establish data governance policies, privacy impact assessments, and vendor management protocols to prevent similar surveillance capabilities from being embedded in organizational assets and supply chains.

  • Security & PrivacyCIO Online4m

    Securing the AI workflow: A guide to safe document automation and governance

    Organizations face critical security risks as employees increasingly use unvetted AI tools to process sensitive documents outside IT governance and compliance controls, with 63% lacking AI governance policies. IT leaders must implement security-first document AI platforms that combine centralized governance, encryption, role-based access controls, and data residency compliance to eliminate shadow AI while maintaining productivity. This shift is essential to prevent intellectual property exposure, regulatory violations, and data breaches while enabling safe, controlled AI adoption across the enterprise.

  • Security & PrivacyHacker News3m

    Chopped, Stored, Secured – The Story of the Hash Function

    Hash functions, originating from Arnold Dumey's 1956 work on mathematical data transformation, have evolved from simple memory indexing techniques to critical security mechanisms that protect sensitive data through irreversible one-way functions. Cryptographic hashing—which stores transformed data rather than plaintext—is fundamental to modern security practices like password protection, but its effectiveness depends on mathematical properties like preimage resistance and finite field operations that make reversal computationally infeasible. For IT organizations, understanding hash function implementation and staying current with cryptographic standards is essential to protecting organizational data and meeting compliance requirements in an increasingly threat-aware environment.

  • Security & PrivacyTechMemeNectar Gan2m

    China adds data and algorithms to its trade secret rules, as part of Beijing's efforts to prevent tech leaks amid intensifying strategic competition with the US (Nectar Gan/Bloomberg)

    China has expanded its trade secret protections to explicitly include data and algorithms, creating significant compliance and operational challenges for technology companies operating in or with ties to Chinese markets. This regulatory shift reflects escalating US-China technological competition and signals that IT organizations must implement stricter data governance, intellectual property protection, and employee access controls to avoid legal exposure in China. For multinational tech leaders, this development necessitates a reassessment of data localization strategies, cross-border data flows, and R&D security protocols.

  • Security & PrivacyTechMemeKentaro Takeda2m

    Grab says it commits to "Taiwan's data security and public trust", after reports of Grab's collaborations with China's Huawei and Alibaba sparked concerns (Kentaro Takeda/Nikkei Asia)

    Grab, a major Southeast Asian tech platform, faces geopolitical and data sovereignty risks following reports of collaborations with Chinese companies Huawei and Alibaba, prompting the company to publicly recommit to Taiwan's data security standards. This incident highlights the critical business and reputational implications for multinational tech companies operating across geopolitically sensitive markets, underscoring the need for IT leaders to carefully evaluate vendor relationships and data handling practices across jurisdictions. For CIOs, this underscores the importance of implementing robust data residency policies, supply chain transparency requirements, and regional compliance frameworks to mitigate similar risks.

  • Security & PrivacyCIO Online7m

    Connected vehicles, disconnected security: Why connectivity architecture now matters most

    Connected vehicles now generate massive data volumes (25GB/hour by 2030) across complex, multi-party ecosystems involving cloud platforms, third-party apps, and mobile networks, creating significant security blind spots where data traverses unpredictable pathways with limited visibility and control. Data portability regulations and universal connectivity are forcing a fundamental rethink of connectivity architecture, but most industry focus remains on data monetization rather than securing the fragmented data flows that span multiple providers and geographic boundaries. CIOs must shift from traditional endpoint-focused security models to architecting end-to-end visibility and control across the entire connected vehicle ecosystem, as each integration point introduces new attack vectors that traditional defenses cannot adequately address.

  • Cloud & InfrastructureCIO Online2m

    The key role of hybrid cloud in digital sovereignty and innovation

    Digital sovereignty is rising on enterprise agendas due to regulatory compliance and data security concerns, but CIOs need not abandon hyperscalers entirely—a hybrid cloud strategy enables organizations to move compliant workloads to specific jurisdictions while leveraging public cloud efficiency for others. By embedding sovereign principles into a trusted software supply chain rather than starting infrastructure from scratch, IT leaders can achieve sovereignty by design while maintaining agility and innovation velocity. CIOs should begin by assessing their current state across operations, technical assurance, and open-source capabilities to determine the pragmatic path forward.

  • Security & PrivacyCIO Online7m

    The AI data governance gap that keeps getting worse

    Organizations are rapidly deploying AI systems without adequate data governance, creating untracked copies of sensitive customer data scattered across development environments, third-party services, and contractor machines—exposing the enterprise to significant compliance violations, data breach risks averaging $4.88M, and regulatory penalties under GDPR and the EU AI Act. The problem stems from organizational silos where security, privacy, and data engineering teams each assume governance responsibility belongs to another function, leaving no single owner accountable for whether production data should leave protected boundaries during AI development. IT leaders must establish clear governance frameworks and ownership models to manage the proliferation of data copies throughout AI pipelines before regulators enforce stricter penalties.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple pushes back against Canadian bill that could force companies to weaken encryption

    Apple and Meta are opposing Canadian Bill C-22, warning that its broad investigative powers could enable the government to compel companies to weaken encryption or install backdoors—a precedent that threatens the security and privacy capabilities that enterprise users depend on. This marks the continuation of a global pattern of regulatory pressure on encryption, following similar disputes in the UK and echoing the San Bernardino case, which signals an escalating challenge to corporate security infrastructure across jurisdictions. For IT leaders, this legislation portends increasing regulatory fragmentation where different countries may impose conflicting security requirements, forcing organizations to either maintain multiple security postures or accept weakened protections globally.

Browse all tags