Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Securing data in the AI era

As businesses increasingly rely on cloud-driven platforms and AI-powered tools to accelerate digital transformation, the stakes for safeguarding sensitive enterprise data have reached unprecedented levels. The Zscaler ThreatLabz 2025 Data@Risk Report reveals how evolving technology landscapes are amplifying vulnerabilities, highlighting the critical need for a proactive and unified approach to data protection.

Drawing on insights from more than 1.2 billion blocked transactions recorded by the Zscaler Zero Trust Exchange between February and December 2024, this year’s report paints a clear picture of the data security challenges that enterprises face. From the rise of data leakage through generative AI tools to the undiminished risks stemming from email, SaaS applications, and file-sharing services, the findings are both eye-opening and urgent.

The 2025 Data@Risk Report sheds light on the multifaceted data security risks enterprises face in today’s digitally enabled world. Some of the most noteworthy trends include:

  • AI apps are a major data loss vector: AI tools like ChatGPT and Microsoft Copilot contributed to millions of data loss incidents in 2024, particularly social security numbers.
  • SaaS data loss is surging: Spanning 3,000+ SaaS apps, enterprises saw more than 872 million data loss violations.
  • Email remains a leading source of data loss: Nearly 104 million transactions leaked billions of instances of sensitive data.
  • File-sharing data loss spikes: Among the most popular file-sharing apps, 212 million transactions saw data loss incidents.

AI applications: A new data loss hotspot

Generative AI tools such as ChatGPT and Microsoft Copilot are revolutionizing how enterprises work—but not without consequences. These platforms accounted for 4.2 million data loss violations, revealing how personal identifiers, intellectual property, and financial data are routinely at risk.

SaaS ecosystems: Simplifying workflows, complicating security

More than 872 million data loss incidents were flagged across SaaS platforms. Popular applications such as Microsoft 365, Salesforce, and Google Workspace, which have the largest share of violations, highlight the tension between collaboration and compliance.

Email: A legacy risk with perennial consequences

Despite newer tools and platforms, email remains at the forefront of data loss. Microsoft Exchange and Gmail collectively saw 104 million transactions containing billions of data loss incidents. The most common leaks included medical data, social security numbers, and source code.

File-sharing platforms: Productivity with a heaping side of risk

File-sharing giants like Google Drive, Microsoft OneDrive, and Dropbox logged 212 million transactions that involved data loss. Sensitive information—ranging from proprietary source code to financial records—flowed unchecked in billions of individual violations across these transactions.

While the report reveals massive volumes of data loss across the most popular applications, it also provides a roadmap for organizations to act decisively before data leaks or exfiltration happen. By adopting a unified, AI-driven approach to data security, businesses can turn these risks into opportunities and secure data across every channel, wherever it resides.

Best practice recommendations from the 2025 Data@Risk Report include:

  • Use AI to discover and classify your data: Implement a Zero Trust Architecture (ZTA), enabling advanced data loss prevention (DLP) policies across endpoints and networks, and leveraging AI-powered platforms to identify risks in real-time. By taking these steps, enterprises can safeguard their data while enabling productivity and innovation to thrive.
  • Understand your data loss channels: Map out all the channels through which data flows within and outside your organization—email, SaaS apps, AI tools (e.g., Microsoft Copilot), BYOD, cloud storage, and physical storage devices. Each channel presents unique risks and requires tailored security controls.
  • Lean on your Zero Trust Architecture: Transition from a perimeter-based security model to a ZTA that enforces least-privileged access. Use identity-based access control, granular policies, and Secure Access Service Edge (SASE) to inspect all internet traffic, segment networks, and minimize your organization’s attack surface.
  • Secure GenAI and AI tools with granular controls: For generative AI tools like ChatGPT and Microsoft Copilot, enforce granular controls on user sessions, such as input or output restrictions. Block unsafe prompts that might expose sensitive data during user interactions. Additionally, monitor anomalies in user behavior (e.g., excessive queries) and flag or block activities that violate data security policies.

As enterprise AI transforms workflows and accelerates innovation, the challenges of managing and securing data grow in parallel. From sensitive prompts leaked in generative AI tools to data loss across SaaS platforms, email, and endpoints, Zscaler offers best-in-class tools to secure data in this rapidly evolving landscape, providing visibility, control, and Zero Trust protection for enterprise applications worldwide. This allows enterprises to:

  • Find sensitive data across endpoints, inline, and cloud with AI-powered auto data discovery and classification.
  • Protect data in motion with full TLS/SSL inspection and inline DLP for web, email, BYOD, and GenAI apps.
  • Secure data at rest in clouds and on endpoints with unified policy, sharing controls, and device posture.
  • Simplify operations with unified end-to-end incident response using a single, integrated console with Workflow Automation.

Protecting enterprise AI apps from data loss

Zscaler also delivers a full suite of best-in-class products to secure generative AI tools like ChatGPT and Microsoft Copilot.

  • AI app visibility: As employees rapidly adopt AI tools like ChatGPT and Microsoft Copilot, Zscaler ensures enterprises never lose visibility over sensitive inputs or outputs.
  • Smart input prompt blocking: Zscaler uses AI/ML-driven URL filtering and policy enforcement to categorize AI app activity and automatically block unsafe or unapproved input prompts.
  • Deep visibility into AI workflows: Innovative categorization of user prompts lets security teams track, analyze, and make educated decisions about AI application security. For instance, Zscaler policies can:
    • Monitor for sensitive user data (e.g., social security numbers) in real time.
    • Block prompts related to intellectual property leakage.
  • Secure collaboration via isolation: Prevent accidental data transfers in AI applications, without stifling productivity:
    • Browser isolation for AI tools: Zscaler’s Browser Isolation technology allows employees to interact with AI tools securely by rendering applications in an isolated virtual browser.
      • Clipboard usage, file uploads, and downloads can be restricted while still enabling prompts.
      • Prevent accidental data exfiltration when employees interact with generative AI apps, such as ChatGPT or OpenAI-powered interfaces.
  • Safe pixel rendering: By rendering applications as “pixels,” Zscaler ensures sensitive information never physically leaves the organization’s control, even during remote use.
  • Securing Microsoft Copilot: With Microsoft Copilot set to revolutionize enterprise productivity, Zscaler eliminates risks tied to sensitive data misuse, misconfigurations, and third-party access.
    • Inline data leak prevention for prompts: Zscaler scans OneDrive files and Copilot functions in real time, mapping data connections to ensure security standards. Prevent excess permissions and proactively block sensitive files from exposure.
    • Fix misconfigurations in SaaS settings: Zscaler continuously monitors configurations to resolve oversharing risks.
    • End User Behavioral Analytics (EUBA): Using AI-driven behavioral analytics, Zscaler identifies anomalies not only from Copilot users but also from any connected third-party SaaS integrations.

There has never been a more critical time to rethink your enterprise’s approach to data security. The 2025 ThreatLabz Data@Risk Report offers a comprehensive look at where risks lie, what drives them, and how organizations can respond effectively to secure their sensitive data in today’s rapidly evolving, AI-driven ecosystem.

For a full list of best practices, download the 2025 Data@Risk Report.


Read More from This Article: Securing data in the AI era
Source: News

Category: NewsJune 30, 2025
Tags: art

Post navigation

PreviousPrevious post:Ron Insana on why CIOs can’t wait for certainty in an unpredictable economyNextNext post:IT lobbyists exploit EU AI Act uncertainty as deadline looms

Related posts

The biggest mistakes CIOs make in the boardroom — and how to avoid them
May 15, 2026
What is CMMI? A model to optimize development processes
May 15, 2026
How AI is transforming software development
May 15, 2026
From cautious to scaling: SAP customers span the AI readiness spectrum
May 15, 2026
AI 시대 CIO, ‘생존 시험대’ 올랐다…조직 혁신·AI 역량이 성패 좌우
May 15, 2026
앤트로픽, 클로드 에이전트 과금 전환…‘무제한 AI’ 시대 막 내리나
May 15, 2026
Recent Posts
  • What is CMMI? A model to optimize development processes
  • The biggest mistakes CIOs make in the boardroom — and how to avoid them
  • How AI is transforming software development
  • From cautious to scaling: SAP customers span the AI readiness spectrum
  • AI 시대 CIO, ‘생존 시험대’ 올랐다…조직 혁신·AI 역량이 성패 좌우
Recent Comments
    Archives
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.