Most security budgets are still built on a quiet assumption, which is that with enough investment we can keep attackers out. After two decades in this field, including time as a CIO who owned the consequences, I no longer believe that assumption survives contact with the data. Breaches are not going down. The honest planning posture is that a serious compromise is a matter of when, not if, and that the variable actually within your control is not whether attackers get in but how much they can reach once they do.
That variable has a name. Blast radius. And IBM's breach economics show it is the most leveraged thing a security leader can manage.
The data points to containment, not prevention
IBM's 2025 Cost of a Data Breach report put the global average at 4.44 million dollars and the US average at a record 10.22 million. The averages hide the real lesson, which lives in the spread. In the 2024 report, breaches involving data spread across multiple environments, on-premises and cloud and SaaS at once, cost more than 5 million dollars and took 283 days to resolve, the longest of any category. Breaches involving shadow data, meaning data sitting in stores nobody was managing, occurred in 35% of cases, cost 16% more, and took over a quarter longer to identify.
Read those numbers as a single sentence. The more places your sensitive data lives, and the less you know about where it is, the more a breach costs and the longer it bleeds. That is the blast-radius problem, quantified. Meanwhile the threat keeps widening. Verizon's 2025 Data Breach Investigations Report found ransomware present in 44% of breaches, up from 32%, and the share of breaches involving a third party doubled to 30%.
Prevention spending has plateaued in effectiveness. The asymmetric return is now in reducing what is exposed when, not if, an attacker gets in.
You cannot lose what you do not have
The cheapest data to protect is the data you never collected, or have already deleted. That used to be a privacy argument. It is now a security control with regulatory teeth.
GDPR has always required data minimization, which means personal data must be adequate, relevant, and limited to what is necessary, and kept no longer than necessary. What is new is enforcement of over-retention as an offense in its own right. In early 2026, France's data protection authority fined a major telecom 42 million euros after finding it had retained millions of records without justification for an excessive period, and that the over-retained data enlarged the blast radius of a breach affecting tens of millions of subscribers. In the US, California's privacy regulator made data minimization the subject of its very first enforcement advisory and called it a foundational principle. Nineteen states now have comprehensive privacy laws on the books.
NIST states the point plainly in its guidance on protecting personal data: the likelihood of harm from a breach is greatly reduced if an organization minimizes the amount of personal data it uses, collects, and stores. The most under-used security control in most enterprises is the delete key. Over-retained data carries no business value and full breach liability.
Encrypt now for the breach you will have in 2030
Minimization shrinks the target. Encryption and tokenization shrink what an attacker gets even after reaching it. Tokenization removes the real sensitive values, such as card numbers and identifiers, from most of your systems entirely, which is why it collapses both PCI scope and breach exposure at the same time. Format-preserving encryption, standardized by NIST, lets you protect structured data without breaking the applications that depend on its shape. None of this is new. It is under-applied.
A second clock is running that most roadmaps ignore. Adversaries are already harvesting encrypted data today to decrypt later, once quantum computers mature. This harvest-now, decrypt-later threat is not science fiction for data with a long shelf life. Financial records, health data, and trade secrets stolen now may still be sensitive when the cryptography protecting them fails. NIST finalized the first post-quantum cryptography standards in 2024, and national authorities have set migration deadlines around 2035. Any data you encrypt today with a multi-decade confidentiality requirement belongs on a path to post-quantum protection.
These are not three separate initiatives. Tokenization, format-preserving encryption, and post-quantum migration form one continuous data-protection roadmap, sequenced by the shelf life of what you are protecting.
Data protection is the foundation under safe AI
Every AI initiative ultimately runs on data, which makes data both the prize and the liability. IBM's 2025 data found that one in five organizations suffered a breach tied to shadow AI, with a cost premium of roughly 670,000 dollars, and that 97% of organizations with a breached AI system lacked proper access controls. Security vendors that monitor AI usage report that a large and rising share of the data flowing into AI tools is sensitive, and that most of it moves through non-corporate accounts where security cannot see it.
You cannot govern AI you cannot see, and you cannot protect tomorrow's data with yesterday's cryptography. Data protection is not a workstream sitting beside your AI strategy. It is the foundation underneath it.
Where to start
Three priorities. First, find your data, especially the shadow data, because the 35% of breaches that involve unmanaged stores are by definition stores you would not have thought to protect. Discovery comes before everything else. Second, minimize aggressively: shorten retention, delete what has no purpose, and treat every field you collect as a liability you have chosen to carry. Third, apply encryption and tokenization according to the shelf life of the data, and put anything with a long confidentiality horizon on a post-quantum path now.
You will not prevent every breach. You can decide, well ahead of time, how small the blast radius will be when one happens. That decision sits at the heart of data protection, and it is one of the highest-return choices a security leader can make.