I had a conversation a few weeks ago that I haven’t stopped thinking about. A large enterprise customer. Good team, reasonably mature security posture, the kind of organization that had already had the internal conversation about data governance and felt good about where they landed.

Then a third-party supplier they worked with got breached.


Not the customer. The supplier.

But the data that got exposed was the customer’s data. And the moment that happened, it stopped being the supplier’s problem and became the customer’s problem, completely. Breach coach, insurance, forensic review, notification obligations — they ran the entire incident lifecycle for a breach that occurred on a network they never controlled and never audited in real time.

I want you to sit with that for a second, because it’s not an edge case anymore. It’s the default condition of doing business in 2026.

For twenty years, the security industry built its entire stack around one idea: keep the bad guys out. Firewalls, endpoint protection, DLP, all of it aimed outward, all of it assuming that if we could just secure the perimeter, the data inside would be safe. That mental model made sense when the perimeter actually meant something. It doesn’t anymore. Your data isn’t sitting quietly inside four walls waiting for someone to break in. It’s already out. It’s with your vendors, your partners, and increasingly, it’s being pulled apart, tagged, and reorganized by AI tools that move faster than any human team can review.

Here’s what I think most organizations still haven’t fully absorbed: you can no longer draw a line between “our risk” and “their risk.” If your data lives on someone else’s infrastructure, and it will, their incident is your incident. Full stop. The customer in my story didn’t have a technology gap. They had a governance gap. Nobody had mapped out what happens, step by step, the moment data outside their direct control gets touched.

This is where I think the industry keeps getting the sequencing backwards. Everyone jumps straight to technology. New tool, new dashboard, new AI-powered discovery platform that promises to tell you where all your sensitive data lives. And to be fair, those tools have gotten remarkably good at the discovery part. The problem is what happens after discovery. Customers run these tools, get a mountain of results back, and then look at each other and ask: now what do we do with this?

That’s not a technology problem. That’s a program problem. Before you buy another tool, you need an answer to one question: do you have a data classification schema that’s actually enforced, not just documented? Most organizations I talk to fall into one of three buckets. Some have never tried. Some have a schema on paper that nobody actually follows. And some have it dialed in and know exactly what to do with what they find. If you don’t know which bucket you’re in, that’s the first thing to figure out, before anything else.

Once you have that foundation, the next question is whether you have an actual program for what happens when things go wrong, not just a tool that flags problems. What’s the response? Who owns it? What are the guardrails? That’s the layer almost nobody has built, and it’s the layer that would have changed the entire experience for that customer.

I’ll be honest about where I think this industry has failed the people trying to solve this. We’ve spent two decades treating data loss prevention as something that disrupts the business — the tool that blocks the email, that stops the file share, that makes everyone’s job a little harder in the name of security. That reputation is deserved, and it’s also exactly backwards. A governance program that’s actually built and enforced doesn’t slow the business down. It’s the thing that lets the business move fast without wondering what happens the day a vendor three steps removed from you gets breached.

Here’s where I think we’re headed, and where I think the best security leaders are already operating. The four walls are gone and they’re not coming back. AI is only going to accelerate how fast data moves and how many places it ends up. The organizations that will handle this well aren’t the ones buying the most tools. They’re the ones who treat data governance the way we’ve always treated incident response: as a program, with owners, with steps, with a plan that exists before the moment you need it, not after.

So here’s my challenge to you. Pull up your last three vendor or partner relationships that touch sensitive data. For each one, ask yourself honestly: if they got breached tomorrow, do you know exactly what happens next, or would you be building that plan in real time while everyone above you is asking questions you don’t have answers to yet?

If you don’t know the answer, that’s not a technology gap. That’s the conversation we should be having.
Ready to get started?
Ready to learn more more – Schedule a call today!