The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out.
As far back as 2007, Facebook was forced to reckon with mass grief when users asked the company to maintain the profile pages of the 32 victims killed by a school shooter at Virginia Tech that year. Those pages became de facto memorials for loved ones to fill with comments, and today, memorialization has become a full-fledged feature on both Facebook and Instagram. Platforms like YouTube, Pinterest, and LinkedIn—launched with likely zero strategy for a user’s death—now have procedures for next-of-kin to request that a deceased person’s account be deactivated.
Now, think about all the other ways your data can linger after death.
Every year, people accumulate more and digital stuff—email addresses, social media profiles, contact lists, domain names, subscription services, online banking accounts, and the phones, laptops, and tablets that hold it all—and every year, as that digital stuff accumulates, it compounds into ever more problems for someone else to sort out. Here, a small industry of digital estate planners have cropped up, helping families retrieve and preserve anything valuable, no matter how digital, from Spotify playlists, to poignant social media posts that mattered, to the photos stored on a phone.
And where retrieval fails, artificial intelligence has offered an attempt at comfort. The chatbot service Replika launched in 2015 after its founder uploaded a dead friend’s text messages. HereAfter AI reportedly let users upload voice recordings to power a chatbot that sounded and spoke like the deceased. Film studios have pursued the same idea for entertainment, seeking to portray deceased actors in future films.
Surprisingly, almost none of this activity is governed by law, said Tamara Kneese, author of the 2023 book “Death Glitch: How Techno-Solutionism Fails Us in This Life and Beyond.”
“By and large, there is not a great legal mechanism for protecting the privacy rights of the dead,” said Kneese. “It may not be just that a grieving loved one decides to use a bunch of your data from all of your podcasts to create a chatbot to simulate interacting with you after you’re dead, but it may be that a company chooses, in some way, to use an aspect of your personality, of your demeanor, of your voice, of your likeness after your death without anyone really being aware.”
Today, on the Lock and Code podcast with host David Ruiz, we speak with Kneese—Senior Research Scientist at Partnership on AI—about who owns a person’s data after they die, why every platform has invented its own private policy for the dead, and how the technology built to keep the dead close can vanish just as suddenly as they did.
Or worse yet, as Kneese warned for those relying heavily on certain technologies in grief:
“The company gets sold to someone else or disappears, goes bankrupt, and you no longer have that outlet or place for interaction when you’re mourning another time.”
Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year.
The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker updated the affected total from roughly 345,000 to 3,756,469 individuals.
CareCloud says an unauthorized third party accessed one of its Amazon Web Services (AWS) environments between March 10 and March 16, 2026. The intrusion caused an eight-hour disruption to one of the company’s six EHR environments before systems were restored that same evening. During a forensic investigation, CareCloud determined that the attacker claimed to have exfiltrated data from databases within that environment.
The stolen data reportedly includes both identity and medical information:
Full names, postal addresses, and dates of birth
Social Security numbers (SSNs) and driver’s license or passport numbers
Medical records and health insurance information
Bank account and financial details, plus full credit card data (including CVV) for a limited subset of victims
What affected customers should do
Anyone receiving a breach notification letter should take it seriously, given the combination of medical, identity, and financial data involved.
If you think you’ve been affected by a data breach, here are steps you can take to protect yourself:
Check the company’s advice. Every breach is different, so check with the company to find out what’s happened and follow any specific advice it offers.
Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
Watch out for impersonators. Cybercriminals may contact you posing as the breached company. Check its official website to see if it’s contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
Consider not storing your card details. It’s definitely more convenient to let sites remember your card details, but it increases the risk if a company suffers a breach.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the […]
Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”
Pithy as the phrase sounds, it is undeniably true.
Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.
So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?
That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.
These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.
As we wrote on Malwarebytes Labs:
“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”
It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.
And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.
The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.
So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.
Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.
Security Operations Centers (SOCs) are currently confronting scalability challenges on two fronts: structural and cognitive. The day-to-day reality of modern defensive operations is stark: an analyst frequently begins a shift facing a queue deeply saturated with unvetted alerts. To process a single event, the analyst must open the alert, pivot to a secondary console to complete an investigation, manually enrich an IP address, copy a file hash into a third interface, and cross-reference an asset inventory that may not have been updated in months. Following this, they must author and refine queries, waiting for overloaded databases to return historical context.
The actual work of assessing the investigation’s results and moving to decision-making and action has not even begun. This is the administrative burden of the modern SOC. The true threats are not just those that attempt to bypass defenses, but the critical operational hours lost before an active mitigation attempt is even initiated. While analysts are highly trained professionals, the relentless requirement to perform manual data aggregation inevitably leads to exhaustion.
Misdiagnosing the Bottleneck: The Upstream Data Problem
Threat actors operate at machine speed, utilizing automation to pivot laterally across networks in a matter of seconds, frequently disappearing before defensive teams can even log into their terminals. Expecting human defenders to counter automated threat vectors by manually aggregating bad data is an architectural failure.
Every SOC inherits a highly fragmented data ecosystem. Telemetry is continuously generated by diverse sources, including firewalls, cloud workloads, identity providers, endpoint sensors, and legacy systems. This telemetry arrives in disparate dialects, varying formats, and highly inconsistent levels of fidelity. Before AI tools can accurately reason about a potential threat, or an analyst can initiate a logical investigation and run a playbook response, this raw telemetry must be synthesized.
Historically, organizations analysts take on these complex synthesis processes, manually normalizing data points across different vendor schemas. This represents a key misallocation of human intelligence. The asymmetry in modern security operations is not merely a discrepancy in speed; it is an imbalance in how security teams are forced to allocate their finite time. When operators spend the majority of their shifts wrangling data instead of actively investigating threats, the foundation of the SOC itself is inadequate. To achieve defensive velocity, organizations must recognize that fixing the data foundation is the mandatory prerequisite for improving all downstream security functions.
Architecting the Data Foundation with Singularity AI Data Pipelines
Addressing the upstream data problem requires the implementation of advanced data pipelines capable of resolving enterprise data chaos before it impacts the detection engine. Frameworks such as SentinelOne’s® Singularity AI Data Pipelines serve as this foundational layer, engineered to ingest telemetry from every source and in every format without requiring months-long integration projects or heavy manual engineering.
Modern pipelines utilize AI to normalize raw telemetry into standardized formats, specifically aligning with the Open Cybersecurity Schema Framework (OCSF). This structural alignment transforms fragmented logs into structured data that is immediately actionable. It eliminates the need for analysts to construct complex regular expressions during critical incidents simply to reconcile how two different software vendors format data, such as usernames or a timestamp.
Efficient data ingestion also requires dynamic, in-flight optimization. Not all telemetry possesses the same analytical value, and storing all generated logs in highly indexed, expensive storage tiers is financially and operationally untenable. Data pipelines optimize data streams by filtering out extraneous noise, trimming excess volume, and routing specific logs based on dynamic criteria. High-value security events are routed and indexed for rapid search retrieval, while lower-priority compliance or operational logs are routed to more cost-effective tiered storage. The result is a substantial reduction in infrastructure costs, a higher signal-to-noise ratio, and a structured data foundation that is completely prepared the moment an investigation is required.
When underlying data pipelines automatically enrich that log with identity and asset information, revealing (for example) that a specific financial director’s laptop in a remote office is communicating with a known botnet, the output transitions from a raw data point into a definitive starting point. Crucially, this enrichment occurs systematically before the human operator ever interacts with the alert. Solving this data problem end-to-end is a primary reason SentinelOne was recognized in the IDC MarketScape for AI SIEM.
Accelerating Detection via Singularity AI SIEM
When a clean, structured data foundation is properly established, the performance of downstream security tools accelerates. Modern detection engines, such as the Singularity AI SIEM, leverage indexless architectures to manage enterprise-scale telemetry. Because the data is normalized and optimized prior to ingestion, these platforms can execute petabyte-scale queries with minimal latency, ensuring investigative results are delivered before the analyst’s attention wanes.
Within this architecture, detection logic is executed continuously against a stream of clean, correlated telemetry. This transforms an ocean of disparate event logs into readable, centralized dashboards that provide immediate situational awareness. The quantitative benefits of this approach are substantial. With AI SIEM, organizations are already executing their queries 70% faster. Adding AI Data Pipelines further augments this workstream, providing cleaner data for AI to run at optimal efficiency. These improvements represent the direct result of ensuring that the data arriving at the SIEM is inherently fit for purpose.
AI SIEM remains a single, comprehensive SKU with customers automatically receiving integrated pipeline functionality for everyday data optimization rather than treating it as a premium add-on. For every unit of paid Data Ingest capacity, customers can process twice that volume through Data Pipelines. A customer with 500 GB/day SIEM entitlement can push 1 TB/day through the pipeline at no additional cost.
Transitioning to Agentic Reasoning Layers with Purple AI
The establishment of a structured data pipeline unlocks the capability for true agentic reasoning within the SOC. Unlike traditional rule-based automation, which executes static responses to predefined triggers, technologies like SentinelOne’s Purple AI operate as a dynamic investigative layer.
When an initial alert is generated, an agentic reasoning system does not simply pause and wait for human triage. It autonomously launches an investigation, comprehensively maps the potential blast radius of the incident, and synthesizes a clear, logical recommendation for containment. Then, the analyst logs into the console and is presented with a fully formed situational briefing rather than a blank investigation screen.
More importantly, an agentic AI layer possesses the capacity to evaluate broader adversarial campaigns rather than isolated security events. In isolation, a minor registry key modification, a singular file write, or a brief outbound network connection may not meet the threshold for a critical alert. Legacy security tools often fail to connect these disparate, low-signal events. However, Purple AI can assemble these seemingly unrelated activities into a cohesive narrative, exposing the overarching strategy of the attacker before a major breach occurs.
This level of autonomous intelligence is strictly dependent on the underlying architecture. Advanced AI algorithms cannot derive accurate conclusions from unparsed, low-quality telemetry. The analytical integrity of the agentic layer is entirely contingent on the principle of data quality; systems like Purple AI require clean, structured data to function effectively, avoiding the fundamental issue of “garbage in, garbage out”.
Governed Hyperautomation and the Human-in-the-Loop
The final component of a modernized, agentic SOC is the deployment of Hyperautomation to execute defensive responses. To counter threats effectively, organizations must deploy automated workflows capable of executing decisions at machine speed. These no-code workflows can be configured to trigger autonomously based on AI triage verdicts, the disclosure of new high-severity vulnerabilities, or specific incoming alerts. By automating the mitigation phase, the SOC evolves from an environment strictly dedicated to passive observation into a dynamic system that actively neutralizes threats.
However, the implementation of automated response mechanisms must be rigorously governed. Executing changes to enterprise infrastructure carries inherent risk. To mitigate this, automated workflows must integrate critical approval steps, ensuring that highly consequential actions are paused until human authorization is provided. The analyst retains the ultimate authority, defining the precise parameters of what processes may run automatically and what workflows require manual judgment.
Redefining the Analyst Mandate via Autonomous Security Intelligence
The strategic objective of integrating data pipelines, agentic reasoning, and Hyperautomation is not the removal of the human operator. Instead, the overarching goal is the restoration of the analyst’s primary function: exercising expert judgment.
By offloading repetitive tasks to technological systems, organizations systematically remove operational friction. The data layer filters out irrelevant noise, allowing the analyst to clearly see the threat. The AI investigation layer removes the administrative grind of data collection, allowing the analyst to focus purely on analytical thinking. Finally, the automated response layer eliminates procedural delays, ensuring the analyst’s decisions are executed rapidly enough to matter. This creates an intelligence fabric, known as Autonomous Security Intelligence (ASI), where data, investigation, and response function concurrently as a single, unified system.
Under this model, the operational output of a single analyst is exponentially multiplied, allowing one unburdened professional to accomplish the work of ten while still owning every critical decision. While the alert queue will perpetually require attention, the fundamental nature of the work fundamentally changes. The timeline of a manual initial triage to active investigation compresses from a multi-hour ordeal into a matter of minutes. The data arrives clean, the investigation runs automatically, and the response mechanisms are prepared. The hours previously consumed by administrative waiting are directly reallocated to strategic decision-making.
Conclusion
When defensive systems are finally architected to operate at the speed of the modern threat landscape, the role of the human operator transforms. Analysts are no longer forced to act as passive passengers, grateful to be carried by fragmented tools. They are elevated to the role of pilots, operating with full situational awareness, retaining their judgment, and actively directing the defensive posture of the organization. This is the paradigm of the agentic SOC, and it is entirely predicated on the foundation of clean, structured data.
Contact us today to learn more about how SentinelOne is leading the way forward with Agentic SOC.
ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026 Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company
Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.
In a filing with the Securities and Exchange Commission (SEC), iRhythm revealed it was contacted by someone on June 9 who claimed to have stolen sensitive information, including proprietary data, patient PHI, and other personal information. That person demanded payment in exchange for not publishing the data.
iRhythm provides ambulatory cardiac monitoring and analysis (for example using the Zio patch) and has reportedly processed over two billion hours of heartbeat data from more than twelve million patients.
In the filing, the company said the data was obtained through social engineering and is from “certain third-party-hosted business applications”, without revealing any further details about the amount of data.
On its own website, iRhythm also doesn’t disclose much about the nature of the stolen data, but does seem to imply no financial data was affected:
“We have not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, we do not store or retain individual financial account information or payment card information.
As we actively investigate, we will notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.“
However, the SEC filing adds that iRhythm determined that the incident is significant, “in light of the volume of the potentially affected data.” Together with the extortionist’s claims that they have patients’ medical data, that makes the breach one worth noting if you have used iRhythm’s services.
Even without payment data, healthcare breaches have serious downstream effects:
Attackers can craft highly convincing emails, texts, or calls that reference specific procedures or monitoring episodes (for example, “about your recent Zio patch recording”) to trick patients into sharing more data or paying fake bills.
The breached data can be used to create a fake identity, insurance fraud, or medical identity theft.
Exposure of cardiac and other health‑related information can be deeply sensitive and may have employment/insurance ramifications, especially if data is posted publicly or sold to data brokers.
Healthcare breach data tends to circulate for years, and victims may face sporadic fraud and phishing attempts long after the headlines fade.
How to stay safe
If you’ve used iRhythm’s services, keep an eye on your post, email, and patient portals for official breach notifications from iRhythm or your healthcare provider.
In the US, breaches of protected health information that meet certain criteria must be reported to patients and regulators. iRhythm has promised to “notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.”
To stay out of the hands of phishers and scammers:
When you receive a communication about the data breach, verify through other channels that it really came from iRhythm. Go directly to iRhythm’s official website or patient portal, or call a known phone number to confirm the communication is genuine.
Be extra suspicious of emails or texts that claim to offer compensation, refunds, or other financial consequences related to this incident.
Change passwords for your iRhythm‑linked portals and your cardiology or hospital patient portals, especially if you reused those passwords elsewhere.
Log into your health insurer’s portal and check claims on a regular basis.
If you see anything suspicious, report it immediately to your insurer and provider and ask them to flag your account for possible identity theft.
Do not provide personal or financial information over the phone just because the caller knows details about you which they may have obtained from the stolen data.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
As organizations rush to adopt AI, they are discovering that traditional, siloed security tools cannot keep pace. The data is too vast, the infrastructure is too interconnected, and runtime environments are too dynamic. Security leaders are confronting a hard reality: AI cannot be secured with point solutions — it is just too broad.
To scale AI with confidence, enterprises must move beyond check-the-box controls and adopt a holistic, machine-speed defense that secures the entire AI lifecycle. This means protecting the data that fuels and is accessed by models, the cloud infrastructure that runs them, and the workloads and AI systems operating at runtime as a single, unified, and immutable system.
As AI capabilities accelerate, a critical question is emerging in the market: Does AI reduce the need for cybersecurity, or fundamentally increase it?
The answer is clear. With current infrastructure architectures, AI is not a replacement for security. It is a multiplier for risk. Models ingest massive volumes of data and agents can sprawl uncontrollably. It depends on complex cloud infrastructure and operates continuously at machine speed. Each stage of the AI lifecycle introduces new attack paths and new failure modes.
Today, SentinelOne is announcing the expansion of its AI Security platform with new Data Security Posture Management (DSPM) capabilities, model red teaming, validation and guardrails (by Prompt Security), MCP Security (by Prompt Security), AI-SPM, AI Workload Protection, and AI end user protection. This milestone advances our broader vision, delivering a unified platform that secures AI end to end, from data accessed, all through runtime execution and model input and output. This is complete security, visibility, and governance over Al usage throughout its entire lifecycle.
The Foundation: Securing AI at the Data Layer
AI security starts with data, not because data is abundant, but because mistakes made at this stage are irreversible. AI models also don’t just process the data they ingest, they memorize it. If sensitive PII, credentials, or proprietary information enter a training pipeline, that data can become baked into a model’s weights, creating a permanent security liability that is nearly impossible to remediate later.
This risk is amplified by scale. Industry projections estimate that the global datasphere, the unstructured data stored in cloud object stores and increasingly fed into AI pipelines, will reach 10.5 zettabytes by 2028. This data is not just storage. It is the fuel that trains, fine-tunes, and powers AI systems. This is why data security is the first mile of AI security.
With the introduction of these new DSPM capabilities, SentinelOne enables organizations to establish a “safe-to-train” gate before data ever reaches an AI pipeline. These capabilities provide deep visibility into cloud-native databases and object stores, allowing teams to discover unmanaged or forgotten data sources, classify sensitive information with policy-driven precision, and prevent high-risk data from being used in training or inference workflows.
Singularity Cloud Security’s integrated DSPM discovers cloud object stores and databases and classifies sensitive data that could find its way into AI training pipelines.
However, visibility alone is not enough. AI pipelines ingest data at massive scale, making them an attractive vehicle for malware delivery and pipeline poisoning. In addition to identifying and redacting sensitive data, SentinelOne actively scans cloud storage at machine speed to prevent malicious content from ever reaching AI models or applications. By securing data at ingestion all before training begins, organizations eliminate entire classes of AI risk that cannot be fixed downstream. This is the foundation for trusted AI adoption.
The Infrastructure Layer: Securing the Systems That Run AI
Securing AI data is necessary, but it is not sufficient. Data does not exist in isolation. Rather, it lives on cloud infrastructure and in AI environments where infrastructure becomes a critical failure point.
AI workloads introduce a uniquely high-risk combination of high-value data, high-privilege access, and high-performance compute. AI factories, training clusters, managed AI services, and inference endpoints often require broad permissions and continuous access to cloud object stores. Without strong infrastructure controls, attackers can pivot from exposed data into model logic, model weights, or downstream applications. This is where cloud infrastructure security becomes inseparable from AI security.
Traditional Cloud Security Posture Management (CSPM) provides essential hygiene across the cloud estate by identifying misconfigurations, excessive permissions, and policy drift. In AI environments, however, security teams also need visibility and control that is specific to how models are built, deployed, and accessed.
AI-Security Posture Management (AI-SPM) extends infrastructure security directly into the AI layer. By treating AI systems as first-class assets, AI-SPM provides a unified inventory of training jobs, development notebooks, managed AI services, and inference endpoints across the environment.
Together, CSPM and AI-SPM allow security teams to understand how data, infrastructure, and AI systems are connected. They can trace attack paths from misconfigured storage to over-privileged training containers, detect unmanaged AI assets, and prevent adversaries from moving laterally from the cloud foundation into model logic. This infrastructure layer is what connects secure data to secure runtime and it is essential for protecting AI at scale.
Singularity Cloud Security measures compliance posture over time against multiple global AI regulations including the EU AI Act.
The Runtime Layer: Protecting AI In Production
AI security cannot stop when a model finishes training. The moment AI systems move into production, they begin interacting with real users, real data, and real business processes, making runtime protection a critical part of the AI security lifecycle.
At runtime, AI workloads operate continuously and at machine speed. Models and agents execute inside cloud workloads that must be protected against exploitation, unauthorized access, and lateral movement. Any compromise at this stage can immediately impact business operations, data integrity, and customer trust.
This is where runtime workload protection becomes essential. Cloud Workload Protection Platforms (CWPP) provide real-time visibility and enforcement across the compute environments running AI models, ensuring that workloads are monitored, hardened, and protected without degrading the performance required for high-velocity inference.
By extending protection into runtime, security teams ensure that AI systems remain secure not only during development and deployment, but throughout their operational life. This completes the AI security lifecycle from data ingestion, through infrastructure, to production execution.
Prompt Security and AI Red-Teaming: Continuously Validating Trust
Securing AI at runtime goes beyond protecting the workloads that execute models. It also requires validating how models behave when they are used (and misused) in the real world.
Prompts are the primary interface to AI systems and they represent a powerful new attack surface. Malicious or malformed prompts can be used to bypass controls, extract sensitive information, manipulate model behavior, or trigger unintended actions in downstream systems. These risks cannot be addressed solely through static controls or one-time reviews. This is where prompt security and AI red-teaming become essential.
By continuously testing AI systems with adversarial prompts and simulated attacks, organizations can identify behavioral weaknesses before they are exploited in production. AI red-teaming helps validate that models behave as intended under real-world conditions, exposing prompt-level vulnerabilities, unsafe outputs, and policy bypasses that would otherwise go undetected.
When combined with runtime protection, this approach ensures that AI systems are not only secure in how they are built and deployed, but also resilient in how they respond — even as models evolve, prompts change, and new attack techniques emerge.
This continuous validation loop is critical for maintaining trust in production AI systems and closing the final gap in the AI security lifecycle.
A Unified Fabric for AI Security
The transition to AI is ultimately a trust shift. Organizations will only move AI from experimentation to production if they can trust the data that trains models, the infrastructure that runs them, and the systems that govern how AI operates at runtime. Securing AI therefore cannot be fragmented. It requires a unified platform that treats data, infrastructure, and runtime as a single, connected system with shared context and continuous visibility across the entire AI lifecycle.
By integrating data security, cloud infrastructure posture management, AI-specific posture management, and runtime workload protection, SentinelOne delivers end-to-end AI security from data ingestion through runtime execution. This approach does more than reduce risk. It enables velocity. When security is built into the foundation, organizations can deploy AI faster, meet evolving regulatory requirements more easily, and innovate with confidence.
Secure the data.
Secure the infrastructure.
Secure the runtime.
This is how AI moves from risk to real-world impact. Contact us or book a demo to see how SentinelOne secures AI end to end — from data ingestion to runtime execution.
Data, in all its shapes and forms, is one of the most critical assets a business possesses. Not only does it provide organizations with critical information regarding their systems and processes, but it also fuels growth and enables better decision-making on all levels.
However, like any other piece of company equipment, data can degrade over time and become less valuable if organizations aren’t careful. What’s even more dangerous is that neglecting data hygiene can expose organizations to a number of security threats and regulatory compliance issues.
Understanding data cleanliness
Data cleanliness, also called data hygiene, is the process of ensuring all organizational data maintains accuracy and consistency regardless of where it’s stored and how it’s used. To achieve this, organizations need to ensure their data is regularly checked against six core characteristics:
Accuracy: Free from errors
Completeness: No missing values or incomplete records
Consistency: Maintains format across different systems and platforms
Validity: Follows pre-defined rules or standards
Uniformity: Uses correct data inputs, measurements and naming conventions across all datasets
Timeliness: Up-to-date and relevant
To effectively manage each of these components, organizations can use a variety of data management tools and solutions. These automated systems leverage data profiling and cleansing processes to help detect anomalies as they appear and help organizations resolve them.
Why maintaining clean data is so important
Ensuring organizational data remains free from errors and can be a trusted source of critical business information is essential to ensuring both operational efficiency and resiliency. Considering the amount of digital sources most organizations rely on today, there are several ways that businesses can lose sight of how their data is collected, stored and accessed.
“Organizations today are challenged with a number of issues when trying to maintain the integrity of their critical data,” Evelyn Kim, a program director with IBM Security, says. ” Data is growing exponentially in more formats and locations causing organizations to lose visibility and control over their sensitive data. We see organizations grappling with shadow data (undiscovered or unknown data) that pose significant risks. Generative AI also presents new risks to data — both from a need to have enough of the right data for gen AI use and from ensuring data is not tampered with.”
Security risks associated with unclean data
While the importance of data integrity may seem limited to helping to support smoother business operations, it is actually a core element of ensuring a strong cybersecurity posture. Below are some of the inherent security risks that can occur if good data hygiene is neglected over time:
Cybersecurity threats
With the proliferation of data, data classification, especially of sensitive data, is even more critical to security. Understanding where sensitive data resides is a key step in monitoring data stores and databases to prevent breaches and detect cyberattacks to reduce the impact and damage across critical networks and connected systems.
The effectiveness of modern security tools and technologies also relies on accurate data. Without establishing a reliable baseline for normal business activity, these security solutions lose their ability to identify suspicious user patterns. They can lead to false positives and inadequate threat detection.
Compliance failures
Data cleanliness plays a crucial role in helping organizations meet various regulatory requirements. “Highly regulated industries tend to have significant data governance/security concerns. We typically see financial services, healthcare, manufacturing and utility/energy sectors leaning heavily on data security investments to assist with their compliance efforts,” states Kim.
Without accurate and complete compliance reporting data, organizations open themselves up to significant compliance violations and associated financial penalties. This can also lead to long-term legal repercussions that can damage a business’s reputation and impact customer loyalty.
Maintaining a clean data environment
Data cleansing isn’t something that organizations schedule throughout the year or complete as a one-time project. It requires an ongoing commitment and the ability to integrate data quality practices into every stage of the data lifecycle. From initial data collection and entry to storage, processing and analysis, organizations should follow numerous proactive data maintenance steps, including:
Establishing clear data governance policies: Businesses should establish clear roles and accountabilities in their organization when it comes to data entry, validation and updating procedures. This also includes following strict compliance guidelines on how to properly handle data in and out of transit.
Investing in data quality solutions: Organizations should research and implement next-generation tools that provide automated data cleansing activities in real-time while handling deduplication and validation processes systematically. These tools help identify and address data quality issues proactively, freeing up time and resources for internal teams.
Adopting a security-first culture: Establishing a business culture that prioritizes data security and integrity is essential. This involves initiating training sessions for employees on the importance of following strict data management standards as well as implementing strict access controls, data encryption and monitoring solutions.
Keep your data healthy
Data is what keeps modern organizations running. However, if you’re not careful, the value of this asset will diminish over time and lead to a number of business consequences. By prioritizing data cleanliness, organizations can uncover the true potential of their critical data, allowing them to make better decisions while creating more resilience in their security and compliance initiatives.
Rhode Island is grappling with the fallout of a significant ransomware attack that has compromised the personal information of hundreds of thousands of residents enrolled in the state’s health and social services programs. Officials confirmed the attack on the RIBridges system—the state’s central platform for benefits like Medicaid and SNAP—after hackers infiltrated the system on December 5, planting malicious software and threatening to release sensitive data unless a ransom is paid.
Governor Dan McKee, addressing the media, called the attack “alarming” and urged residents to take immediate precautions to protect their information. Compromised data includes Social Security numbers, banking details, addresses and dates of birth. “This breach is a stark reminder of the vulnerabilities in government IT systems,” McKee said. “We are working with Deloitte and law enforcement to contain the damage and restore public trust.”
Timeline of the attack
The cyberattack began on December 5, when Deloitte, the developer and maintainer of RIBridges, alerted state officials to suspicious activity. Initially, it was unclear whether sensitive data had been accessed. Over the following days, Deloitte implemented additional security measures while investigating the breach.
On December 10, hackers provided a screenshot of file folders as proof of their access, prompting Deloitte to confirm that the RIBridges system had been compromised. Further analysis revealed a high probability that the stolen files contained personally identifiable information (PII). By December 13, Deloitte identified malicious code within the system, leading the state to shut down RIBridges to mitigate further damage and begin remediation.
How the attackers gained access
While the exact infiltration method remains under investigation, early findings suggest that the attackers exploited vulnerabilities in the system’s architecture, likely through phishing emails targeting administrative accounts or unpatched software weaknesses. The malware deployed by the cyber criminals enabled unauthorized access and allowed the attackers to exfiltrate data unnoticed for several days.
This breach has highlighted persistent security challenges in government IT systems, which often struggle to keep pace with evolving cyber threats. RIBridges, developed in 2016 under the Unified Health Infrastructure Project (UHIP), has faced years of technical and operational issues, including public criticism for its vulnerabilities.
Impact on residents and state operations
The breach has far-reaching implications for Rhode Island’s residents and government services. Programs impacted include Medicaid, SNAP, Temporary Assistance for Needy Families (TANF) and health insurance purchased through HealthSource RI. The RIBridges system’s offline status has forced the state to resort to manual processing for December benefits and January payments, creating delays and disruptions for thousands of families.
State officials have contracted Experian to provide free credit monitoring to affected residents and set up a dedicated call center to offer guidance. McKee also urged residents to take proactive steps, including freezing their credit, updating passwords and enabling multi-factor authentication.
Comparisons to other state-level ransomware attacks
Rhode Island is not the first state to be targeted by a ransomware attack on its central systems. In 2019, Texas faced a coordinated ransomware assault that impacted 22 local entities, including state-run agencies, though its centralized IT infrastructure mitigated the spread. Similarly, Colorado’s Department of Transportation suffered a ransomware attack in 2018, which disrupted operations and required weeks to fully resolve.
These incidents underscore the growing threat of ransomware to state governments. Unlike attacks on local municipalities, state-level breaches can potentially disrupt critical systems serving millions of residents, amplifying the stakes for government cybersecurity teams.
What comes next?
The FBI and other federal agencies are assisting in the investigation, while Deloitte works to remediate the vulnerabilities and restore RIBridges. Meanwhile, negotiations between the state’s representatives and the cyber criminals are ongoing, though officials have not disclosed the ransom amount or whether they intend to pay it.
“That conversation is going on directly with Deloitte and the cyber criminals. That’s how this process works, we’re learning a little bit about it,” McKee said. “But we’re being notified of the progress on it, and ultimately, it does end up with that decision with me.”
The attack has reignited calls for stronger cybersecurity measures in government IT systems. Experts recommend adopting zero trust security models, conducting regular vulnerability assessments and increasing investments in cybersecurity infrastructure to prevent future breaches.
“This breach is a wake-up call,” says Brian Tardiff, Rhode Island’s Chief Digital Officer. “We need to ensure that our systems are resilient against increasingly sophisticated cyber threats. The stakes are too high to do otherwise.”
To learn how IBM X-Force can help you with anything regarding cybersecurity including incident response, threat intelligence, or offensive security services schedule a meeting here.
If you are experiencing cybersecurity issues or an incident, contact X-Force to help: US hotline 1-888-241-9812 | Global hotline (+001) 312-212-8034.
Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.
But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.
Understanding the 6 dimensions of data cleanliness
It doesn’t matter where your company data is sourced — without addressing its quality and accuracy, you won’t be able to rely on it. To create the right data cleanliness policy, you’ll need to understand its different dimensions. These include:
Accuracy: Identifies to what extent data can be trusted and is free from errors. This requires specific validation protocols and compliance with data collection standards.
Completeness: Signifies whether or not collected data provides clear answers to certain questions. It involves evaluating any missing data attributes and recognizing any apparent gaps.
Consistency: Checks that data is properly mirrored when stored in multiple databases and represented by a percentage of matched values.
Validity: Refers to data adherence against predefined rules or formats. It helps eliminate the violation of logical constraints or data type restrictions.
Uniqueness: Makes sure all data types reference the same units of measure or support formats to remove the possibility of information overlapping or duplication across data sets.
Timeliness: Represents the degree to which data remains up-to-date. This ensures data is accessible when it’s required so it can be used properly.
Once you have a grasp on these six core elements, you’re ready to move forward with crafting your data cleanliness policy.
The first step to take when creating a data cleanliness policy is to define all appropriate business objectives. Any specific data sets or systems and the intended use of the information within them should be clearly outlined.
This step also involves considering often-overlooked data, including unused software logs, outdated emails and former customer records. If this information is forgotten about, it can lead to security issues down the road when they are left in unsecured locations.
Step 2: Classify data assets
With your policy scope defined, you’ll need to take inventory of all relevant data sources. Data assets can include various databases spread across multi-cloud environments, locally stored spreadsheets or any other areas where data is stored.
Classifying all data assets is another way to minimize forgotten data from compiling and creating high-value targets for cyber criminals. During this process, you’ll also want to categorize data based on its relative sensitivity or regulatory requirements. This will make it easier to implement the right access controls and data retention policies.
Step 3: Establish data quality standards
The data quality standards you develop for your policy should be measurable and easy to understand. To achieve this, you’ll need to lay out specific criteria for each data type, including the acceptable formats data should be in and any validation rules you have in place.
With your metrics in place, you’ll be able to regularly monitor their performance over time. Many times, regulatory requirements will stipulate that data needs to meet certain accuracy and completeness benchmarks. Having these trackable metrics in place provides the transparency needed to ensure these regulations are continuously being met.
Step 4: Assign roles and responsibilities
Establishing clear accountabilities is essential when managing organizational data. Your data cleanliness policy should define the various roles in your organization, including specifying who can access data and what levels of permission they have.
Controlling the amount of individuals who can access, modify or delete data is one of the most important elements of ensuring data integrity over the long term. It helps you to mitigate the danger of insider threats as well as establish clear lines of accountability if and when anomalies are located in data sets.
It is also common to make use of a data governance team that can help to implement and enforce various policy initiatives. These teams can reduce the likelihood of data inconsistency and help support various data security protocols in place.
Step 5: Implement data cleansing procedures
In the event that data issues are discovered, your policy should also cover necessary data correction procedures. This can include standardization, normalization or deduplication of data stored across systems.
Another supporting element of this process is having clear data retention and disposal policies in place. This helps to reinforce best practices when it comes to data lifecycle management. It also minimizes a digital attack surface, making it less likely that sensitive information is left in a vulnerable storage state, and helps to minimize damages in the event of a successful cyberattack.
Maintain healthier organizational data
Being able to rely on the accuracy and consistency of your company data is critical. Not only does data integrity play an important factor in improving the value of your technology investments, but it also helps to strengthen your cybersecurity posture.
By following the steps above, you’ll be able to draft a data cleanliness policy that allows you to maintain healthier organizational data while extracting its full value.