Skip to content Skip to footer

Featured Use Cases

Do you know where your sensitive data is?

An organisation stores large volumes of sensitive …

Stop your IP and Design files from being stolen?

A defence subcontractor retains your design drawings in an archive …

Stopping your confidential files from being stolen?

A senior employee resigns and spends their final week downloading …

How are you measuring your AI risk today?

An employee uploads a customer spreadsheet into an AI …

More Use Cases

How to Protect Data Even After a Breach or Theft

Applies persistent file encryption…

ITAR Compliance and Sovereign Data Encryption

Enables ITAR-compliant handling of controlled…

Secure External Collaboration with Persistent File Encryption

Enables secure collaboration with suppliers…

Securing Construction Drawings and Project Files

Keeps construction drawings, specifications…

Securing Engineering Files and CAD Data

Applies persistent in-use encryption to…

Sensitive Data Discovery and Classification

Finds and classifies PII, PCI, PHI, and …

Insider Risk Detection and Data Loss Prevention

Detects insider threat behaviour in real…

See GuardWare data-centric security in action

Core Solutions
ASSESSOR

Executive-ready risk assessment with a ranked remediation plan

DISCOVER

Identify and classify sensitive data across your environment

INSIGHT

Detect and stop risky data handling, including AI tools 

PROTECT

Encrypt and control critical files everywhere

Supporting Solutions
ASSESSOR Lite

Fast risk snapshot for M365 in 24 hours

DISCOVER PCI

Lightweight PCI DSS scoping scan

INSIGHT Lite

M365 monitoring and early risk signals

PROTECT Design

Protect CAD and IP workflows across partners and supply chains

What If Your Data Could Protect Itself? A Data-First Security Playbook

Picture of GuardWare
GuardWare

If your organisation was breached tonight, could you tell your board exactly what sensitive data was taken? Could you tell the regulator? Could you prove it? 

For most organisations, the honest answer is no, and that gap is exactly what GuardWare put to an expert panel in their webinar, “What If Your Data Could Protect Itself?” GuardWare CEO and co-founder Rizwan Mahmood was joined by Lloyd Hewitt, Microsoft’s Director of Business Strategy for Worldwide Public Sector Defense and Intelligence, to unpack why data-first security is becoming non-negotiable, and what a practical framework for it actually looks like. 

Below are the key ideas from the conversation. If you want the full discussion, including live audience polls on how confident security leaders really feel, you can watch the complete webinar here:

Why the Old Security Model Keeps Failing 

Most organisations have invested heavily in perimeter defence, endpoint detection, identity management, and patching. Yet breach after breach shows the same pattern: a single mistake undoes years of investment. 

Rizwan points to recent, recognisable examples: the Medibank and Optus breaches, both traced back to one compromised login, and a more subtle case: a supplier to the NSW Reconstruction Authority accidentally uploaded flood victims’ data to ChatGPT. No firewall or perimeter tool was ever going to stop that. 

“We keep on having this concept around thinking that we will bring a bigger wall, or a stronger secure location, secure environment, secure box,” Mahmood said. “But all the stats are proving is that it’s not really working.” His conclusion: security teams are trying to protect something they don’t fully understand. Before you can protect data, you have to know what you have, where it lives, and what’s actually at risk. 

That’s the essence of a data-first security strategy: instead of assuming you can block every way in, you assume something will eventually get through, and make sure the data itself is worthless to whoever gets it. 

The Visibility Problem Hiding Behind Every Breach 

Lloyd Hewitt sees this pattern constantly in defence and public-sector environments. Most organisations believe they have good visibility over their sensitive data; in reality, he says, that visibility is usually partial, siloed, and outdated. 

Visibility degrades fastest in the places nobody’s watching: legacy file stores that survived multiple system migrations, data copies scattered across spreadsheets and screenshots, shared collaboration platforms where governance hasn’t kept pace, and “shadow IT” environments spun up to get a job done under time pressure. Sensitive data spreads laterally through an organisation, rarely maliciously, just as an operational reality. 

Hewitt offered a striking counterpoint from Ukraine’s response to the 2022 invasion. Facing the real risk of physical infrastructure destruction, the Ukrainian government rapidly moved its critical national data sets into the public cloud, where they were distributed, encrypted, and backed up across multiple locations. Even as physical infrastructure was destroyed, Ukrainian authorities retained the ability to understand what data existed, where it was, and who could access it. 

“The lesson is not that the cloud is magically safer,” Hewitt explained, “but that modern security improves when data is visible, governed, and protected consistently.” It’s also worth noting how attacker tactics have shifted since nation-state actors increasingly target the supply chain, not just government systems directly, hitting financial institutions and IT providers along the way. 

Encryption In Use: Why “Hackers Don’t Hack Anymore, They Log In” 

Encryption at rest and in transit is now standard practice; hard disks, databases, and network traffic are routinely encrypted. The problem, Rizwan argues, is what happens the moment data comes out of those secure pipes. 

“I normally joke about this: hackers don’t hack anymore. They log in,” he said. Once an attacker has valid credentials, through phishing, a leaked password, or an insider, they become, in the system’s eyes, an authorised user. The same is true of a malicious or careless insider. At that point, perimeter and identity controls have already done their job and failed to matter. 

The remaining line of defence is encryption in use: keeping a file encrypted even while it’s actively being worked on. A CAD/CAM design file, a PDF, a video, source code, all encrypted independently in memory while someone edits them, not just when they’re sitting idle on a disk. If an attacker does get in and exfiltrates the data, what they walk away with is unusable. It doesn’t matter whether that file ends up on a USB stick, a personal phone, or an unsecured cloud folder; it’s still encrypted. This is the technical foundation GuardWare has built its platform around, and the reason the company is such a strong advocate for encryption in use as a category. 

Compliance Isn’t the Same as Secure 

The panel was direct about a common industry blind spot: ticking a compliance box does not mean an organisation is actually secure. 

“I’ve been an auditor in a past life,” Rizwan said, “and so many times people have come to me and said, ‘Can you just do a check-the-box kind of exercise, just give us something?'” Compliance certificates have too often been used as proof of security rather than evidence of it, and regulators are closing that gap fast. 

Frameworks like CPS 234 (which governs Australia’s superannuation and financial services sector) and reforms to the Australian Privacy Act are shifting the post-breach conversation from “did you try hard enough?” to “can you actually prove you were in control?” Regulators now expect evidence that controls existed before a breach, were risk-aligned to the data itself (not just the system), and were tested and operating, not assumed. As Hewitt put it, a data-first approach “doesn’t make the breach disappear, but it changes the conversation from why you didn’t know, to you knew what mattered, you protected it, and you can prove it.” 

Where to Start Without “Boiling the Ocean”

For organisations sitting on hundreds of terabytes of unstructured data across legacy systems and multiple clouds, the scale of the problem can be paralysing. The panel’s advice: don’t try to fix everything at once, and don’t do it alone. 

Anchor on outcomes and risk rather than data volume. Ask which data is most sensitive, which business processes are most exposed, and which use cases, AI copilots, partner collaboration, engineering IP, and customer data introduce the most risk. That narrows an enterprise-wide problem into a starting lane you can actually execute against. 

Rizwan’s practical framework: start with the data nobody in the organisation will argue about protecting- PII, PCI, or healthcare data driven directly by regulation- because you’ll have the backing of the regulation itself to justify monitoring, controlling, or quarantining it. Get a quick, visible win, then move to the next data type: finance, HR, engineering designs tied to defence or critical infrastructure. Tackle it piece by piece, iteratively, rather than as one enormous, never-finishing data governance project. 

Most importantly: focus encryption in use on the “crown jewels” the data that would genuinely damage the business if exposed, not everything. And treat data classification as an ongoing conversation with end users, not a one-off governance committee exercise. Reclassification, Rizwan notes, is one of the most commonly neglected parts of any data governance program. 

Why DSPM Has Suddenly Become a Category 

Rizwan Mahmood also pointed to a broader industry shift: the rapid emergence of Data Security Posture Management (DSPM) as a distinct category. “This didn’t exist three years agomost of these platforms didn’t even exist,” he said. Organisations that have already implemented a data classification scheme are now realising classification alone doesn’t solve the problem; they need to understand what that data actually is, where it lives, and how it’s used in practicewhich is exactly the gap DSPM platforms, including GuardWare’s, are built to close. 

Zero Trust Doesn’t Mean Dropping Your Other Defences 

A late-webinar audience question raised a common misconception about zero trust. Hewitt was clear: adopting a zero trust philosophy doesn’t mean abandoning perimeter securityyou still need it. What zero trust adds is protection against insider threats and, critically, the kind of lateral data leakage that happens when information moves outside an environment through everyday, legitimate operational means. Data-first security and zero trust aren’t competing strategies; they protect against different failure modes. 

Backed by Government, Trusted by Microsoft 

GuardWare’s approach isn’t theoretical. Founded in 2021, the company was awarded a $7 billion collaboration agreement in 2024 with UNSW, backed by the Defence Trailblazer program, to help secure Australia’s defence supply chain- work that spans far beyond office documents and PDFs into the full range of engineering and unstructured file formats defence organisations rely on. The objective was to secure information in use so that, even if a file ended up with a supplier or in a remote cloud environment, its owner could still revoke access to it at any time. That technology now underpins GuardWare’s commercial product, delivered in partnership with Microsoft.  

Want the full conversation, including the audience polls on how confident security leaders really are about their own data visibility? Watch the complete webinar, “What If Your Data Could Protect Itself?”, here:

To talk to GuardWare about a data discovery exercise or the GuardWare Assessor offer,

Download Data Risk Assessment Report..

Download Data Discovery Assessment Report..

Webinar

The Insider Threat You Can't Fire: Cybersecurity in Education.

Jun 24, 2026 12:00PM AEST