Data Security
The AI era has moved data security onto the board agenda. Cyera's valuation rose from ~$1.4B to ~$6B to ~$9B to ~$12B in roughly eighteen months (the latest a $600M raise in June 2026), on the argument that enterprise AI cannot be deployed safely without knowing where sensitive data sits and which users or agents can access it. A central question is whether data security is consolidating into a single platform or remains a set of separate features.
Scope: data security
Data security protects the data itself — at rest, in motion, and increasingly in use by AI — independent of the network, endpoint, or app it lives on. The historically fragmented tool categories are converging into "data security platforms":
- DSPM (Data Security Posture Management): discovers and classifies sensitive data across cloud, SaaS, and on-prem stores, then maps who/what can access it and where it's exposed. The fast-growing, AI-era control plane — Cyera, BigID, Sentra, Dig (Palo Alto), Laminar (Rubrik), Concentric AI, Symmetry.
- DLP (Data Loss Prevention): enforces policy to stop sensitive data from leaving — email, endpoint, web, and now GenAI prompts. The legacy, often-hated category being re-platformed: Forcepoint, Symantec/Broadcom, Microsoft Purview, Zscaler, Proofpoint, Cyberhaven (data-lineage approach).
- Encryption / key management / tokenization: protects data cryptographically and controls the keys — Thales, Entrust, Fortanix, HashiCorp Vault (IBM), AWS/Azure KMS.
- Data access governance & privacy: governs entitlements, consent, and data-subject rights — Varonis (unstructured-data access), BigID, Securiti, OneTrust (privacy adjacency).
- Backup / recovery / cyber-resilience: increasingly counted as data security because ransomware made recoverability a security control — Rubrik, Cohesity (+Veritas), Veeam, Commvault.
The strategic significance: data is the one asset that doesn't move when the perimeter dissolves — so as workloads scatter across multi-cloud and SaaS, data-centric controls become the durable control point. AI super-charges this: every enterprise GenAI deployment is a data-governance problem (what can the model see? what can an agent exfiltrate?), which is exactly why DSPM re-rated from a "nice-to-have inventory tool" into the "trust layer for AI." Whoever owns the classified data map owns the substrate that DLP, access governance, and agentic-security policies all run on.
How each actor makes money and how they differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Cyera | Private (VC) | DSPM platform / leader | AI-native DSPM expanded into DLP, identity, privacy, and agentic security — "trust layer for AI"; ~$12B valuation (Jun 2026, $600M raise; ~8x in ~18 months); Frank Slootman on board; the most prominent asset in the category |
| Varonis | Public (VRNS) | Data access / unstructured | Long-standing unstructured-data access governance + behavioral analytics; transitioned to SaaS + MDDR; the scaled public pure-play in data security |
| BigID | Private (PE/VC) | DSPM + privacy | Privacy-first, deep classification of structured/unstructured incl. mainframes/data lakes; pairs DSPM with consent and data-rights workflows |
| Rubrik (Laminar) | Public (RBRK) | Resilience + DSPM | Backup/cyber-resilience leader that bought Laminar (DSPM) — "data security from backup outward"; bundles posture with recoverability |
| Palo Alto (Dig) | PANW | Platform / bundler | Bought Dig Security (2024) to fold DSPM into Prisma Cloud — DSPM as a CNAPP feature, the bundler threat to standalones |
| Forcepoint | TPG | DLP consolidator | Legacy DLP re-platformed into a data-security suite; bought GetVisibility (DSPM, 2025); PE-owned roll-up engine |
| Microsoft (Purview) | MSFT | Bundler | DLP + classification + insider risk bundled into M365/E5 — the "free with the license" threat that commoditizes baseline DLP |
| Zscaler / Proofpoint / Netskope | various / TB | Inline DLP | Data protection delivered inline through SSE/email — DLP as a feature of the traffic platform |
| Cyberhaven | Private (VC) | Data lineage / DLP | Tracks data lineage (where data came from and went) rather than pattern-matching content — a next-gen attack on legacy DLP's false-positive problem |
| Sentra / Concentric AI / Symmetry | Private (VC) | DSPM specialists | Scaled independent DSPM challengers; classic consolidation supply against Cyera and the platforms |
| Securiti | Private (VC) | Data+AI governance | Unified data command center (DSPM + privacy + AI governance); positioned for the AI-governance wave; reported strategic interest from data-platform buyers |
| Thales / Entrust / Fortanix | various | Encryption / KM | Crypto, HSM, key management, tokenization — the regulated, infrastructure-grade layer; quantum-safe migration is the next demand driver |
Data security has three camps converging on one pool. The DSPM natives (Cyera, BigID, Sentra, Concentric) won the AI-era narrative — they map and classify the data, which is the control plane everything else needs; Cyera's rapid valuation increase reflects the market betting one of them becomes the data-security platform. The legacy DLP and access players (Forcepoint, Varonis, Symantec) own the enforcement install base and the compliance workflows but carry the burden of false positives and brittle policy — their value is the install base and the enforcement rails, which is why they are buying DSPM to modernize. The bundlers (Microsoft Purview, Palo Alto/Dig, Zscaler, Rubrik) fold data security into a bigger platform — Microsoft commoditizes baseline DLP, Palo Alto folds DSPM into CNAPP, Rubrik approaches from resilience. The encryption/key-management layer (Thales, Entrust, Fortanix) is a separate, infrastructure-grade pool with its own driver (post-quantum migration).
Where data-security spend is concentrating
Signature deals & events
- Cyera's valuation run (2024–2026) — ~$1.4B → $6B (Jun 2025) → $9B (Jan 2026) → $12B ($600M raise, Jun 2026); the clearest market signal that data security is the AI era's premium control point. (Frank Slootman has sat on Cyera's board since Mar 2025 — a governance signal that predates this round, not part of it.) The bellwether the whole domain is priced against.
- Cyera → Oasis Security (~$1B, announced Jul 28 2026) — the DSPM leader's move beyond data security into non-human and AI-agent identity governance, pairing its map of what sensitive data exists with Oasis's map of which humans, machines, and agents can access it. The largest non-human-identity acquisition to date; a data-security platform extending into the identity control plane rather than a pure identity vendor consolidating the niche. See 11, 20b.
- Palo Alto Networks → Dig Security (~$400M, 2024) — DSPM folded into Prisma Cloud; the canonical bundler move that put pressure on standalone DSPM valuations and set off the "platform vs. specialist" race.
- Rubrik → Laminar (~$200–250M, 2023) — a backup/resilience leader buying DSPM to attack data security "from the data outward"; validated resilience-plus-posture convergence.
- Fortra → Lookout (data security business, 2025) and Forcepoint → GetVisibility (2025) — legacy DLP/security vendors buying DSPM/classification to modernize aging enforcement franchises.
- Concentric AI → Swift Security + Acante (2025) — sub-scale DSPM specialists combining; the consolidation template inside the long tail.
- The AI-data-governance pivot — every major data-security vendor (Cyera, BigID, Securiti, Varonis) repositioning around "secure your enterprise AI": classify what models can see, govern what agents can do. The demand catalyst reshaping the category. See AI Security.
The bear case
The data-security bull case is "data is the one asset that survives the death of the perimeter, AI makes knowing your data critical, and the DSPM control plane compounds into the durable data-security platform." The bear case has two prongs. First, DSPM may be a feature, not a platform. Palo Alto folded Dig into CNAPP; Rubrik folds posture into resilience; Microsoft Purview bundles classification and DLP into E5 at near-zero marginal cost. If the natural home for "where is my sensitive data" turns out to be inside the cloud-security platform or the M365 license, then standalone DSPM is a transient category and Cyera's $12B is a private-market valuation untested by the public bid. Second, the legacy DLP install base is large but melting — enforcement is being commoditized by the bundlers and reinvented by data-lineage upstarts, so the incumbents' install-base value erodes even as they buy growth. Falsifiable test: watch whether a standalone DSPM leader reaches durable nine-figure ARR and a public listing at a premium multiple, or whether the category gets absorbed — Palo Alto/Dig, Microsoft Purview, and the CNAPP platforms taking the net-new data-security budget. If the standalones get tucked in below their last private mark while the platforms win the spend, "data security is its own durable platform" is breaking, and the AI-era re-rating was a bubble in a feature.
→ Cross-references: Vendors, Cloud Security, Identity, AI Security, Deals & Comps, Valuation, Bear Case.
Adjacent market: the backup and cyber-resilience industry converging with data security is mapped on Data Protection & Cyber Resilience.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.