Many organizations believe they have successfully addressed the issue of data sensitivity. However, AvePoint’s research reveals a different story. According to the company’s third annual State of AI Report, 82.7% of organizations expressed “very” or “extreme” confidence in their ability to prevent unauthorized access to AI data. Surprisingly, 72% of this confident group had already experienced incidents of unauthorized AI access within the past year.
During an interview at Black Hat, I had the opportunity to discuss this discrepancy with Dana Simberkoff, AvePoint’s Chief Risk, Privacy, and Information Security Officer. We delved into the launch of Kinetic Classification, a product unveiled on the same day.
The Issue
Simberkoff highlighted that the main problem lies not in the negligence of security teams but in the lack of proper data hygiene, tagging, and classification over the past two decades. Both humans and automated tools have struggled with effectively categorizing information. Users have tended to either underclassify data to bypass security measures or overclassify everything to simplify their own workflows.
Kinetic Classification aims to bridge this gap by continuously evaluating sensitivity as data evolves, rather than relying on outdated labels. This distinction is crucial in an AI-driven environment, where the question is not just about the confidentiality of a document but whether an AI agent should have access to it at all. “You can establish rules for agents based on these boundaries,” explained Simberkoff.
Setting AvePoint Apart
Simberkoff emphasized the distinction between AvePoint and other vendors in the industry. While many focus on asset management, AvePoint looks at what she describes as the “blood” that sustains an organization. She underscored that comprehensive protection requires a layered approach centered on context, content, and access, understanding the significance behind incidents.
The Importance of Order
Classification identifies sensitive data, while AvePoint’s recent enhancements to its Rapid Recovery system address the aftermath of security breaches. The updated system offers intelligence for prioritizing data restoration, a pre-built recovery plan wizard, and Express Recovery for Entra ID, streamlining the restoration process down to the identity layer. The goal is to replace manual triage with a structured recovery plan that can be swiftly executed under pressure.
Evidence of Success
Simberkoff pointed to AvePoint’s internal use of its own product as a testament to its effectiveness. When implementing Copilot internally, her team leveraged their classification technology to prepare, ensuring proper tagging and cleanup across SharePoint and OneDrive before deploying an AI agent. Insights from this internal deployment directly influenced product development. Additionally, AvePoint maintains customer advisory boards for continuous feedback, with a 25-year track record and long-standing customers adding a layer of trust.
The Key Takeaway
Summing up the interview, Simberkoff stressed the importance of metadata, likening it to a message for the future. She highlighted the role of classification in directing AI behavior, likening AI to Pac-Man that engulfs everything unless boundaries are established. She expressed optimism about the potential of AI in security, shifting from detection and response to prediction and prevention.
Arya Baviskar, a recipient of the Women in Cyber scholarship and Reporter at Cyber Defense Magazine, is a cybersecurity undergraduate at Northeastern University. As she gains experience in Cyber Threat Intelligence as an intern at the Cyber Security Forum Initiative, she also serves as an AI Trainer at Handshake AI, focusing on bias evaluation. Her overarching goal is to demystify complex technology for those impacted by it. Contact Arya via email at [email protected] or connect on LinkedIn at www.linkedin.com/in/aryabaviskar.

