In Plain Sight: What Your AI Can Reach That You Never Classified
Every security assessment of the last twenty years has had data classification on it, and almost every organization has quietly skipped that line. Episode five of The Blind Spot is about what happens now that AI can reach everything that was never classified.
Heather Case-Hall is a 22-year veteran of the US Army and one of the Army's first cybersecurity warrant officers, the Army's designation for technical experts in their field. She is the author of Data in Plain Sight, was named the 2026 Cybersecurity Woman Leader of the Year out of 7,000 candidates, and spends her client work where data security posture management meets reality. The book exists because her clients kept buying expensive tools, some going multiple rounds with multiple vendors, and still ended up in the same place: not understanding their data or why securing it matters.
Half of leaders are confident. All of them are wrong.
Heather has had no fewer than two hundred conversations about data in the last two years, and her math on them is the line of the episode.
"Probably 50 percent of the people I talk to are pretty confident of where their data is. And every single one of them finds themselves wrong."
The moment of discovery follows a pattern: the DSPM tool lands, then come the curse words, then the silence, because nobody knows what to do next. The morning of the recording, a client wanted to fix everything immediately. Heather's response: pause.
"We just looked at five percent of your data."
Fixing what surfaced in a proof of concept alone would be years of work. Her prescription is two sets of notes: what genuinely needs fixing right now, and how you plan to get ahead of the entire environment. That planning discipline, not the tool purchase, is the actual program. It is the same lesson our shadow AI discovery guide lands on: discovery without a pre-agreed response plan just converts ignorance into panic.
Regex cannot read context
Jason and Heather share a scar: legacy DLP. Heather ran DLP at a financial insurance institution and once blue-screened an entire organization over a comma placement. Her deeper point is structural, and it explains twenty years of alert fatigue.
"Social security numbers and Target's shelf itemization are exactly the same."
Pattern matching cannot tell them apart, and most DLP, even what sells as modern, still runs on regex and patterns. Her favorite demonstration is one word: Jordan. A basketball legend is PII. A shoe line is intellectual property. A river is a GDPR question. The same nine letters trigger completely different obligations, and only context can say which. That is her case for AI-assisted classification, done deliberately and everywhere: if you are going to do it, do it all the way, across every storage area, because the copied database that became a spreadsheet on someone's laptop has already lost its lineage. As she puts it, if businesses cannot trust the data they make decisions on, and cannot secure the data itself, they will not sustain themselves.
Do you know what your AI can reach?
Glance's AI Governance module inventories your AI systems, discovers shadow AI, and keeps the register current, with an advisor working from the same state.
The identities nobody granted
The conversation's second act is about who, or what, can reach the data. Heather calls them non-human identities, and disarms Jason by admitting they are both old enough to call them service accounts. The difference is volume and stealth.
"If we think of any tool we've updated in probably the last six months, there's an AI identity in those tools."
Adobe, the meeting note-takers, Grammarly: access granted in a background update, without anyone understanding what the grant meant. A Copilot or ChatGPT rollout is usually a deliberate, thought-out identity. The rest arrive silently, and they sit unmanaged in the environment exactly the way orphaned service accounts did two decades ago. Her governance answer is unglamorous and correct: this is change advisory board territory, AI access crosses compliance, risk, security, IT, and the business at once, and a Copilot enablement should be crawl, walk, run. It is the operational half of what we mapped in third-party AI risk assessment, and the same process failure Dave Gerry flagged in episode four: a vendor clears review, then ships AI six months later, and nobody routes it back through diligence.
Asked to choose which is worse, not knowing what data you have or not knowing who can reach it, Heather picks the data. Her example: the employee who stored a personal library of audiobooks in OneDrive, then stood up a company-paid AWS bucket to back it up. The CIO paying for those terabytes cares, and the acceptable use policy should have caught it. And if one of those downloaded books carries malware, the data problem and the access problem become the same incident.
The board funds the Lamborghini, then holds the keys
Boards are pushing data security harder than ever, Heather says, not necessarily because they understand the problem but because they read headlines. The funding arrives. Then the strangest failure mode in enterprise security shows up.
"You inherited a Lamborghini. But to drive the Lamborghini, you have to go ask permission for the key. You have to ask permission for where you're driving it. You need to ask permission for the gas."
One organization spent two million dollars on a year of a data security posture management tool, then took three months to get permission to turn on classification labels. The stated fear was legitimate, mislabeling disrupting users, but the cure was worse than the risk: a paid-for tool idling while the exposure it was bought to find sat unaddressed. Heather's counter is that label friction is a training problem, one email and a module in the security awareness program, not a three-month governance stall. The deeper fix is the one she opened with: agree on what you will do with the findings before the purchase order, so the tool never idles in the garage.
The data you cannot even see
The sharpest technical warning in the episode is about where the biggest spend is going, and where it still cannot reach. DSPM is the biggest line item she sees right now, driven by thirty-year-old organizations that moved everything to the cloud, sensitive and worthless alike, into infrastructure they no longer physically control. But the harder problem is the SaaS platforms that hold a decade of operational history.
Jira. Confluence. Salesforce. Heather's challenge to Jason: how do you think you find the data in them? There is no pool of files to point a scanner at. You cannot visualize the data, cannot scroll the attachments, cannot run a network discovery against it. You can only search, and searching requires already knowing what you are looking for. A help desk that has run on Jira for ten years is a ten-year archive of screenshots, exports, and credentials pasted in tickets that no tool can enumerate. She has been challenging DSPM vendors directly to close that gap, and notes they are working on it. Until then, the blind spot sits inside the tools the business runs on, the same class of exposure that keeps showing up in supply chain incidents.
The one question
The Blind Spot closes every episode the same way: pick a side of the table, and name the one thing you wish they understood. Heather picks the C-suite, the one riding the fence, and her answer is about translation in both directions. Upward, frame data security as business risk, because the big words mostly do not land in the boardroom, a theme straight out of episode one. Downward, talk to employees technically enough that they understand why the program exists and what the tools do. And she hands the CISO one more job: the users are not just the audience, they are part of the defending force against AI, and the C-suite is the sweet spot for arming them.
Her sign-off captures the whole thesis in one line: defeat the army by starving it. AI, friendly or hostile, feeds on whatever data it can reach. Classify it, govern who and what can reach it, and you decide what is on the menu.
Listen to the full episode
The full conversation runs about 40 minutes and is worth the time for any leader staring down a data classification backlog, a Copilot rollout, or a DSPM proof of concept. Watch or listen here:
Heather Case-Hall is the author of Data in Plain Sight and one of the US Army's first cybersecurity warrant officers. New episodes of The Blind Spot are released every two weeks. If your AI can reach data you never classified, talk to a Z Cyber advisor.
Frequently Asked Questions
Why do data security posture management (DSPM) scans surprise so many organizations?
Because confidence about where data lives is usually built on where data is supposed to live, not where it actually is. Users copy databases into spreadsheets on their own storage, help-desk platforms accumulate a decade of attachments, and migrations move sensitive and worthless data to the cloud together. In Heather Case-Hall's experience across roughly two hundred client conversations, about half of leaders are confident they know where their data is, and every one of them turns out to be wrong once a scan runs, usually within the first five percent of the environment.
Why does traditional DLP produce so many false positives?
Most DLP, including much of what is sold as modern DLP, still relies on regular expressions and pattern matching, and a pattern cannot tell a social security number from a retailer's shelf itemization code with the same digit structure. Without context, the same word can be a person, a product, intellectual property, or a geographic term with regulatory implications. That is why AI-assisted classification matters: context, not pattern, is what determines whether data is sensitive and which rules apply to it.
What is a non-human identity?
A non-human identity is an account or agent that is not a person: what an earlier generation of IT called a service account, and what now includes AI assistants and agents embedded in software. Almost any tool updated in recent months, from meeting note-takers to writing assistants to design suites, has added an AI identity with access to organizational data, often granted in an update without anyone evaluating what that access means. They need the same inventory, ownership, and review that user identities get.
What should an organization do before buying a data security or DSPM tool?
Decide in advance what you will do with what the tool finds. Heather Case-Hall's advice is to take two sets of notes from the first discovery: the things that need fixing right now, and the plan for getting ahead of the whole environment. Organizations that skip that step either panic at the first scan or, just as commonly, spend heavily on a tool and then take months to authorize actually using it, because nobody agreed up front on what actions the findings would trigger.
Who is Heather Case-Hall?
Heather Case-Hall is a cybersecurity leader, a 22-year veteran of the US Army, and one of the Army's first cybersecurity warrant officers, the Army's designation for technical experts in their field. She is the author of Data in Plain Sight, a book on understanding, classifying, and securing data before pointing AI at it, and was named the 2026 Cybersecurity Woman Leader of the Year, selected from 7,000 candidates. She is the guest on episode five of The Blind Spot, Z Cyber's podcast.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


