

Cybersecurity Has an Expensive Case of Paralysis. This Is How We Can Fix It.


I was sitting on a cybersecurity panel recently when the moderator asked about the biggest challenge facing enterprise security. Every panelist offered a version of the same answer: The perimeter is no longer enough. We need to protect the data itself.
That principle sits at the heart of data-centric security. The problem was not that the panelists were wrong. It was that the industry has been making this argument for 25 years.
De-perimeterization emerged in 2001. The Jericho Forum formalized the idea in 2004. John Kindervag introduced Zero Trust in 2010. By 2022, the federal government was mandating its adoption.
We are not struggling to identify the issue. We are struggling to stop admiring it.
Data-Centric Security Is a Solvable Problem
When experts genuinely disagree, paralysis is understandable. Consensus takes time, but that is not what is happening here.
The consensus around data-centric security is neither new nor narrow. De-perimeterization describes a shift away from relying mainly on traditional perimeter defenses. These include firewalls, network boundaries, and infrastructure controls.
Instead, security protections can apply directly to data, assets, users, and transactions. Those protections remain relevant regardless of where the information resides.
This isn’t fringe thinking. It has shaped security strategy for the better part of two decades.
Firewalls, intrusion detection systems, and VPNs still serve an important purpose. Nobody is arguing that these are bad tools. They’re just not sufficient.
There are now more ways to reach data than any network boundary can cover. The people who get paid the most to think about this have been saying so consistently for twenty years.
The Foundation for Data-Centric Security Already Exists
Here’s the bright side: we are not starting from zero.
The intellectual foundation is solid, and the frameworks exist. The people on those panels are right. We have a complete, well-documented, peer-reviewed diagnosis.
What we don’t yet have is the collective will to treat the patient.
That’s a hard problem, but it is not impossible to solve. The technology exists.
Data-centric security is an approach that changes what organizations protect and why. Instead of focusing only on the systems that carry data, organizations secure the data itself.
Protection stays with information whether it is at rest, in transit, or in use. The same principle applies whether data sits on a corporate server, a contractor’s laptop, or in a third-party cloud environment.
Open, vendor-agnostic standards like the Trusted Data Format make it possible to apply policy and access controls at the object level. These controls can remain with a file as it moves across systems, organizations, and cloud environments.
Why Data-Centric Security Faces Organizational Paralysis
So why aren’t we moving? A few specific reasons stand out.
Compliance Culture Masquerading as Security Strategy
Passing the audit became the goal.
Passing an audit can be genuinely difficult. However, it remains much easier than rebuilding a security posture around the data itself.
So the box gets checked, the certificate gets framed, and the posture doesn’t meaningfully change. Compliance sets a floor. Too many organizations have been treating it like a ceiling.
Organizations should treat compliance as a baseline. They should measure security by whether sensitive data remains protected beyond the systems they control.
Perimeter Investment Inertia
Organizations have spent years and significant amounts of money building perimeter defenses. Admitting those defenses are insufficient can feel like writing off a major investment.
So rather than pivot, the typical response is to add more perimeter. More tools. More alerts nobody has time to triage. More of what hasn’t worked, stacked higher.
The investment grows. The problem doesn’t shrink.
The answer is not to abandon existing defenses. Instead, organizations can gradually redirect new investment toward data-centric security controls that protect information wherever it moves.
A Workforce Built for the World We’re Leaving Behind
Many experienced cybersecurity practitioners learned to secure networks, endpoints, and infrastructure. Fewer received training focused on classifying data and applying lasting controls wherever information travels.
The leadership gap makes the problem worse.
Decision-makers often continue approving perimeter investments because that is the language their teams bring into the room. As a result, organizations fund what they understand. That keeps them tied to the security models they already know how to build.
Breaking this cycle requires targeted training for practitioners. Leaders also need enough knowledge about data security to assess and fund the transition.
How Organizations Can Adopt Data-Centric Security
There are signs of movement. Security investment is beginning to shift closer to the data.
Some organizations are already building defenses that do not collapse the moment an attacker breaches the perimeter. But slow progress is not enough.
Organizations do not need to overhaul their security architecture overnight.
A practical first step is to identify the most sensitive data and map where it moves. Teams can then apply lasting protections to that information.
Data has to move to get business done. There is no way around it.
Leaders should redirect some perimeter-security spending toward controls that stay with data. Those protections should continue working after someone shares information outside the perimeter walls.
Data-Centric Security Also Requires Investment in People
Technology alone will not complete this transition.
Practitioners need training in data classification, governance, and object-level protection. Leaders also need clear ways to measure progress.
Rather than asking only whether the organization passed an audit, leaders should ask whether protection continues after someone shares sensitive data. They should also determine whether the organization can revoke access after sharing.
The industry already knows what must change. Now it must build the skills, redirect the investment, and protect the data as though the perimeter has already failed.


