Skip to main content

Plan your security journey with us.

André Kraemer

New Business | Project Manager

Schedule a free consulation

The Data Security Index 2026 and the Gap Nobody Wants to Name

The numbers look great on paper

When you read the newly published Microsoft Data Security Index 2026, you might come away thinking the world of data security is on the verge of solving itself. The report, based on a survey of 1,725 data security leaders across ten markets conducted between July and August 2025, paints a picture of an industry that is consolidating, maturing, and embracing artificial intelligence with growing confidence:

  • 86 percent of the decision-makers surveyed prefer integrated platforms over fragmented best-of-breed toolsets, citing better visibility, fewer alerts, and improved operational efficiency.
  • 82 percent have developed plans to use generative AI within their data security operations, up a striking 18 percentage points from 64 percent in the previous year’s survey.
  • 92 percent say they feel confident using GenAI to strengthen data security, compared to 86 percent a year earlier.
  • 39 percent report they are already using GenAI agents for data security purposes, with another 58 percent piloting or exploring them.

These are impressive numbers that tell an important story: data security is moving from reactive patchwork toward proactive, platform-based, AI-augmented protection. The direction is right. The ambition is right. The urgency, underscored by the finding that 32 percent of all reported data security incidents now involve the use of GenAI tools, is unmistakably right.

And yet, if you spend your days inside actual customer environments the way we do at water, the picture looks strikingly different from the one the Index describes. Not because the Index is wrong. Because the Index measures aspiration, and what most organizations need is a starting point.

The unspoken prerequisite

The Index is methodically sound. It covers ten countries, spans a range of regulated and non-regulated industries, and includes both quantitative survey data and qualitative interviews with security leaders in the US and UK. Its three core chapters follow a logical arc: from fragmented tools to unified platforms, from unmanaged employee AI usage to governed productivity, and from traditional controls to GenAI-enhanced security operations. Each chapter concludes with a clear Path Forward section that offers sensible, actionable recommendations.

The challenge is that these recommendations presuppose a level of data security maturity that the majority of organizations we encounter in DACH simply do not have. The Index recommends:

  • Data Security Posture Management as a foundation
  • Integrated platforms with continuous risk assessment
  • AI agents for automated classification and remediation

All of these are sound recommendations for organizations that already have a working classification schema, an established DLP practice, and a functioning insider risk program. For organizations that do not have these things, and in our experience that is the clear majority, these recommendations feel like being told to run a marathon before you have learned to jog.

We call this the unspoken prerequisite of the Index. For DSPM to deliver value, the data estate needs to be classified in some meaningful way. For AI agents to produce useful outcomes, the underlying environment needs to generate reliable signals. For Microsoft 365 Copilot to be rolled out without becoming a data exposure nightmare, Sensitivity Labels and DLP policies need to exist before the rollout, not after. The Index treats these prerequisites as a given. In practice, they are exactly the problem most organizations have not solved.

The self-assessment gap

There is an additional phenomenon that the survey methodology, through no fault of its own, cannot fully capture: the gap between self-assessment and reality. When we speak with CISOs and security leaders in initial consultations, we hear confident statements. They have Purview licensed. They use Sensitivity Labels. They have a DLP strategy. When we look inside the tenant, we find a different story. Three labels that nobody uses. A single DLP policy from 2020 that detects credit card numbers and nothing else. An Insider Risk Management module that was licensed two years ago but never activated. The gap between what security leaders report in a survey and what actually exists in their environments is substantial and systematic.

This is not a criticism of the leaders themselves. They are operating under real constraints: limited staff, competing priorities, vendor promises that exceed product reality, and a constant stream of new threats that forces attention to the urgent at the expense of the important. But it does mean that the survey responses in the Index likely overstate the actual maturity level, particularly in categories like DSPM adoption, where more than 80 percent report they are implementing or developing strategies. Our field experience suggests that many of these strategies exist as PowerPoint decks, not as running configurations.

What the Index gets right

None of this diminishes the value of the Index. Quite the opposite. Its three key findings all resonate deeply with what we observe in practice. The shift from fragmented tools to integrated platforms is real. The 88 percent of decision-makers who anticipate budget increases in data security and compliance are spending that money for good reasons. The top investment priorities the Index identifies, namely staying ahead of evolving data security risks at 57 percent, protecting sensitive data at 56 percent, enabling secure innovation at 53 percent, and ensuring safe employee use of GenAI at 52 percent, match what we hear in every customer conversation.

The visibility challenges the Index surfaces are equally accurate:

  • 29 percent cite poor integration with data security platforms
  • 25 percent lack a unified view across environments
  • 23 percent are dealing with disparate tools and no centralized dashboard

These numbers align almost perfectly with what we see in the field. And the growing concern around shadow AI is unmistakable: the share of employees using personal credentials to access GenAI for work rose from 53 to 58 percent year over year, and those using personal devices for GenAI work jumped from 48 to 57 percent.

The Index is, in short, an excellent map of where the leading organizations want to go. It is not, however, a guide for how to get there when you are starting from scratch. That guide is what we set out to build.

Introducing the Data Security MVP

At water, we have spent the last year developing what we call the Data Security MVP, where MVP stands for Minimum Viable Product in the lean-startup sense: the smallest, self-contained, fully functional set of data security controls that an organization can deploy in weeks rather than months, and that is designed from the ground up to serve as the foundation for every subsequent maturity step, including the AI-driven capabilities the Index describes.

The MVP is not a response to the Index. It is the prerequisite that makes the Index’s recommendations actionable. Without it, DSPM shows empty tiles. Without it, Copilot surfaces content that should never have been accessible. Without it, GenAI agents in security operations have no reliable signals to work with. With it, every one of the Index’s three themes, consolidation, secure AI productivity, and AI-enhanced security, becomes a realistic, achievable next step.

In the second article of this series, we describe the MVP in detail: its four pillars, its three-color labeling model, its three DLP policies, and its approach to Insider Risk Management. In the third and final article, we trace the maturity path from MVP to the AI-ready posture the Index envisions and confront the edge cases that no vendor slide deck will show you: Copilot and overshared SharePoint sites, autonomous agents exceeding their principal’s permissions, and the critical distinction between AI that supports and AI that decides.

The Data Security Index 2026 is a mirror worth looking into. But a mirror only shows you where you stand. It does not show you the road. The road starts with something far smaller and far less spectacular than AI agents and autonomous remediation. It starts with a label, a default, and a policy. That is what the MVP is about.

Back to all blogs

Featured blogs

water surf Newsletter