Close

Why Data Protection Has to Be Built In, Not Bolted On

2026

There is a moment in almost every security leader's career where they realize the tools they bought to protect the company are, themselves, the problem. Not because the tools are bad. Because there are too many of them, none of them talk to each other, and nobody can say with confidence where the sensitive data actually lives anymore.

That is the world Sanjay Castelino, President of Skyhigh Security, has spent his career trying to fix, and it is a big part of why Skyhigh just picked up a 2026 Fortress Cybersecurity Award in the Data Protection category. Castelino sat down with Russ Fordyce for the Winners' Circle podcast to talk about shadow AI, zero trust, and why he thinks data protection has been the most underserved corner of cybersecurity for years.

Here is the thing nobody quite says out loud in a boardroom. Most enterprises are running data protection as a patchwork. A tool for the web, a tool for cloud apps, a tool for private apps, a tool for the laptop that just walked out the door. Every one of those tools has its own console, its own policy language, and its own blind spots. Castelino calls this out directly, and honestly it is hard to argue with him once you hear him lay it out.

The problem nobody budgeted for

Ask any CISO what keeps them up at night these days and shadow AI is probably somewhere near the top of the list, right after they finish complaining about their fourth password reset of the week. The 2026 Verizon Data Breach Investigations Report found that unsanctioned AI use among employees roughly tripled in a single year, jumping from about 15 percent of the workforce to 45 percent, with most of those employees signing in through personal accounts the security team has zero visibility into. Source code, of all things, turned out to be the single most common type of data employees are pasting into these tools.

Castelino has watched this play out with customer after customer. Companies are consistently surprised, he says, not by the fact that employees are using AI, but by how many different AI services they are using. Everyone assumes they know. Almost nobody actually does, until they run the scan.

Why data protection got left behind

So why has data protection specifically lagged behind the rest of the security stack? Castelino's theory traces back to COVID, when remote work exploded almost overnight and companies grabbed whatever point solution solved the most urgent problem in front of them. That created what he half jokingly calls a gold rush, and gold rushes are not exactly known for producing tidy, unified architecture. Years later, companies are still paying down that technical debt, both in dollars and in the sheer operational cost of managing a dozen disconnected consoles.

The Security Service Edge category Skyhigh competes in reflects just how urgent this has become. Industry research pegs SSE market growth at roughly 20 to 25 percent a year through the early 2030s, and that is not happening because buyers are bored. It is happening because the old perimeter, the comfortable idea that sensitive data mostly stayed inside four walls, does not exist anymore.

Building it in instead of bolting it on

This is where Castelino gets genuinely animated in the conversation. Skyhigh's bet is that data protection cannot be an add-on module purchased after the fact. It has to be the design principle the whole platform is built around. Their DSPM offering, short for Data Security Posture Management, uses machine learning classifiers, OCR, and document fingerprinting to figure out where sensitive data actually lives, and then that same engine enforces policy everywhere that data travels, whether someone is in the office, on a mobile device, or working from a coffee shop three time zones away. Gartner has flagged this shift too, projecting DSPM adoption will surge past 20 percent of enterprises in 2026, up from practically nothing just a couple years earlier.

One story from the episode sticks with you. Castelino described a longtime customer, a large Brazilian financial institution, that cut incident resolution time from hours or days down to minutes after consolidating onto Skyhigh's platform, while also cutting the cost of running the solution in half. That is not a marginal improvement. That is the kind of number that gets a CFO and a CISO agreeing on something for once.

What zero trust looks like when the attacker might be an AI agent

The conversation eventually lands on zero trust, and Castelino makes a point that reframes the whole discussion. For years, zero trust was mostly about keeping outsiders from getting in. Now, with autonomous AI agents operating inside company networks at machine speed, the bigger risk might be something that already has legitimate access deciding, without any bad intent whatsoever, to go do something it should not. As Castelino put it, these are not deterministic systems the way old code was. You cannot fully predict what they will do next, which means the old assumption of trusting anything already inside the perimeter simply does not hold anymore.

That shift, from worrying about outside in to worrying about inside out and inside in simultaneously, is quietly rewriting how security architecture gets built across the industry, a trend confirmed by broader shadow AI research showing how quickly ungoverned AI use is becoming an insider risk category of its own.

The bottom line

Castelino leaves listeners with something close to a mantra: getting a lower performing security solution for a lower price is not actually a bargain, it is just a different way of losing. As AI adoption accelerates and the boundaries of where sensitive data lives keep dissolving, that principle is going to matter more, not less.

Congratulations again to Sanjay Castelino and the entire Skyhigh Security team on winning the 2026 Fortress Cybersecurity Award for Data Protection. You can hear the full conversation, including the story behind Skyhigh's secure browser controls and what surprised Castelino most about how customers actually use AI governance tools, on the Winners' Circle podcast.

Subscribe to the Winners' Circle podcast to catch every conversation with this year's award winners.

Close

Stay Up To Date

Be in the know about upcoming industry award programs, nominees, winners, finalists, and judges

Submit
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.