adesso Blog

Imagine this: it is a Wednesday morning in April 2026. At 9.14 am, a major German insurance company receives a security alert. A dataset containing over 80,000 customer records – health data, claims histories, credit ratings – is publicly accessible in plain text via a misconfigured cloud storage service. What makes the case so explosive is the forensic analysis: the storage was not set up by attackers. Six weeks earlier, a claims handling specialist had copied the files into a private ChatGPT account to speed up the drafting of standard replies. The AI tool stored the content in a public workspace. Nobody noticed – until a security researcher stumbled across the data by chance and reported it.

This case, too, is fictional. The mechanism is not. It is called Shadow AI: the unauthorised use of public AI services with company data. And by 2026, it has become the fastest-growing driver of data breaches.

Whilst part one of this series showed why digital identity has become the last line of defence, part two focuses on the actual target of every attack: your data. Three forces are converging here – the uncontrolled exposure of data through Shadow AI, the response to this in the form of Data Security Posture Management, and the massive regulatory pressure from the NIS 2 Implementation Act, which has been in force in Germany since December 2025 and holds company directors personally liable.

The most important points first

  • Shadow AI is the most costly data risk factor in 2025. According to IBM, incidents involving unauthorised AI use result in damage costs that are, on average, US$670,000 higher than those of regular data breaches – and now account for 20 per cent of all breaches.
  • Traditional Data Loss Prevention is no longer sufficient. Data Security Posture Management (DSPM) automatically classifies, tracks and protects sensitive data in decentralised cloud environments. Gartner expects 20 per cent adoption by 2026.
  • AI-SPM closes the AI gap. It monitors models, prompts and training data and prevents sensitive content from inadvertently finding its way into language models.
  • NIS-2 makes cybersecurity a top priority. The BSI registration deadline expired on 6 March 2026; fines can reach up to 10 million euros or 2 per cent of global annual turnover, and senior management is personally liable.

Shadow AI – the blind control panel of cloud security

The uncoordinated use of public AI tools by employees has evolved from a marginal phenomenon into a systemic risk by 2025. The IBM Cost of a Data Breach Report 2025 paints a sobering picture: 20 per cent of all data breaches investigated now involve ‘shadow AI’ – that is, the use of unauthorised AI services with company data. The cost per incident averages US$670,000, which is above the global average of US$4.44 million.

The picture is even more devastating when it comes to governance: 97 per cent of companies that suffered an AI-related incident had no adequate access controls for their AI models. 63 per cent simply have no AI governance policy. And only 17 per cent have technical controls that can actually prevent sensitive data from being uploaded to public AI tools – the rest rely on training, warning emails or nothing at all.

The situation at the application level is no better. According to the Menlo Security Report 2025, 68 per cent of employees use generative AI via personal accounts for work-related tasks. 57 per cent actively enter sensitive company data, ranging from source code to financial metrics.

Data Security Posture Management – Visibility as the new standard

Traditional Data Loss Prevention (DLP) – that is, rule-based filters designed to prevent the outflow of sensitive data – reaches its structural limits in dynamic cloud environments. Today, data no longer resides in a single, centrally controlled system, but across dozens of cloud services, databases, AI tools and shadow repositories. Static rules come into play too late here.

This is precisely where Data Security Posture Management (DSPM) comes in. It is the discipline that automatically detects and classifies sensitive data in cloud environments, tracks its lifecycle and assesses risks in real time. Gartner expects that by the end of 2026, around 20 per cent of all organisations will be using DSPM platforms – with Europe leading the way with a market share of around 25 per cent. The DSPM lifecycle consists of four steps: Discovery identifies forgotten databases and shadow repositories; Data Lineage tracks the flow of data; Risk Assessment evaluates exposure; and Remediation automatically corrects permissions.

AI-SPM – the extension for the AI era

DSPM alone is no longer sufficient once AI models come into play. Language models (Large Language Models, LLMs) are classic black boxes: they consume enormous quantities of training data and prompts, without it being possible to transparently reconstruct afterwards what was contained within them or what reappears as output.

AI Security Posture Management (AI-SPM) is the specialised solution to this challenge. It reveals which data feeds into training and inference processes, whether sensitive customer information ends up in prompts, and whether models are vulnerable to data leakage, prompt injection or model stealing. Platforms such as Microsoft Purview provide building blocks for this approach within the Microsoft 365 ecosystem; specialist providers extend this coverage to multi-cloud and multi-model environments. As documented by Reco.ai 2025, in more than half of the AI-related security incidents investigated, data flows were neither documented nor monitored.

Forensic Reality in 2025 and 2026

The need for these concepts is particularly evident in the documented incidents of the last 24 months. In the 2024 Snowflake data breach, attackers used stolen login credentials from hundreds of customer accounts that had not enabled MFA – leading to the forensic realisation that central cloud databases can no longer be defended without strict identity verification. In the third quarter of 2025, global corporations were defrauded of tens of millions through deepfake-based bank transfer scams similar to the opening scene. And in 2026, a wave of ransomware strikes small and medium-sized enterprises (SMEs) in the DACH region, particularly in the manufacturing sector. The Eye Security trend report on Cybersecurity in the DACH region notes: phishing and compromised email accounts remain the main points of entry – the impact is dramatically exacerbated by a lack of data classification.

NIS-2 makes cloud security a top priority

What was previously a technological necessity is now also a legal obligation under the NIS-2 Implementation Act (NIS2UmsuCG). The Act came into force on 6 December 2025, and the deadline for registration with the Federal Office for Information Security (BSI) expired on 6 March 2026. According to estimates, around 30,000 German companies fall under the regulation – including insurance companies, energy suppliers, healthcare providers, logistics firms, the manufacturing sector and digital infrastructure providers.

In terms of content, NIS-2 requires ten areas of action for risk management – ranging from contingency plans and supply chain security to encryption strategies. Incidents must be reported in stages: an early warning within 24 hours, an initial report after 72 hours, and a final report within one month. For critical infrastructure operators, fines can reach up to 10 million euros or 2 per cent of global annual turnover – whichever is higher.

The key departure from the old way of doing things is that IT security can no longer be delegated to the IT department. Senior management itself must approve and monitor risk management measures and take part in compulsory cyber-security training. In the event of breaches, they are personally liable – in the worst-case scenario, with unlimited liability from their private assets. The full list of requirements can be found on the OpenKRITIS portal and in the Federal Law Gazette.

DORA as a second regulatory lever for the financial sector

Banks, insurance companies and financial service providers are facing a second set of regulations: the EU’s Digital Operational Resilience Act (DORA) has been binding since January 2025 and requires mandatory cyber resilience testing, prescribed ICT risk management and strict oversight of third-party IT providers. Any organisation needing to comply with both sets of regulations cannot avoid adopting an integrated approach to identity and data protection.

Use Case: DSPM roll-out in 90 days at a medium-sized insurance company

A typical project scenario illustrates how these requirements fit together in practice. Starting point: A medium-sized German insurance company with three cloud tenants, several hundred SaaS applications and countless Power BI workspaces, which have historically been set up without centralised control. No one can say exactly where personal health data is stored.

In the first month, the discovery phase identifies just under 12,000 sensitive data objects outside the documented storage locations – including policy data in an unused test storage environment and claims files in a public Power BI report. In the second month, the DSPM classifies the findings and links them to identities and access paths, making the risk exposure measurable. In the third month, automated remediation workflows kick in: critical permissions are revoked, exposed storage locations are closed, and dangerous configuration drifts are rectified. After 90 days, a complete picture of the data landscape is available for the first time – verifiable in accordance with the NIS 2 documentation requirements.

The convergence of parts one and two provides the complete picture of modern cloud security: identity as the last line of defence, data as the actual target, and NIS-2 and DORA as regulatory levers at executive management level. Anyone who still believes in 2026 that they can get by with traditional DLP and ad hoc IAM tools risks not only data breaches but also personal liability. With the Cyber Resilience Act, the next wave for connected products is set to begin in 2027. An adesso Cloud Security Health Check will show you, in 14 days, where shadow AI, DSPM gaps and NIS 2 risks intersect within your organisation.

When was the last time you checked where your most sensitive data is actually stored? Get in touch – we’ll shed light on the shadows.


Security

A competitive advantage rather than a vulnerability

This is how cyber security becomes an enabler of sustainable digital sovereignty – rather than a hindrance to your innovation.

Read more


Picture Marc Iridon

Author Marc Iridon

Marc Iridon is a Microsoft security expert and has more than seven years of experience in the cyber security industry. He specialises in data security. A key aspect of his work and expertise is the protection of identities in the cloud environment and the implementation of data protection measures.

Category:

AI

Tags:

Security

Cloud