-
The Third Annual State of Data Compliance and Security Report: 2026 Edition
- A Letter from the Authors
- High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up
- Why Data Protection Breaks Down in Practice
- How Organizations Are Responding to Growing Data Risk
- Key Takeaways: What It Takes to Protect Data at Scale and AI Speed
- Respondents Snapshot: Segments, Industries, & Job Titles
- Key Terms to Know
Report > The Third Annual State of Data Compliance and Security Report: 2026 Edition
How Organizations Are Responding to Growing Data Risk
Most Organizations Take a Portfolio Approach to Protecting Sensitive Data
We wanted to look at the techniques organizations are using today to understand how they’re addressing these challenges. What we found is that most organizations are combining multiple approaches, the most popular being:
86%
Static data masking
60%
Dynamic data masking
51%
Synthetic data
Which of the following techniques does your organization use for protecting sensitive data in non-production environments? Select all that apply.
| Category | |||||
|---|---|---|---|---|---|
| Static data masking | 86 | ||||
| Dynamic data masking | 60 | ||||
| Synthetic data | 51 | ||||
| Tokenization | 33 | ||||
| Data subsetting | 29 |
Each of these methods plays a different role.
Static masking is widely used to protect full datasets in non-production. When done right, it should reflect realistic, yet compliant, data.
Dynamic masking is often used in analytics and reporting, where there is a need to selectively mask and unmask data according to users’ roles. It is often native to modern data platforms.
Synthetic data is used to generate new datasets that do not exist in production for software development and AI use cases. It is inherently PII-free.
Back to top
Static Masking Remains the Most Trusted Foundation for Data Protection
When we asked which methods meet specific needs, static data masking stood out as the strongest across all criteria.
- Provides irreversible protection (65%)
- Meets SLAs to data consumers when protecting large-scale data sources (57%)
- Is cost efficient (64%)
- Prevents sensitive data breach or theft (62%)
- Provides data realism (60%)
- provides referential integrity within and across databases (63%)
What solution(s) meet your organization's needs if you require a data protection method that...
| Category | Provides irreversible protection | Meets SLAs to data consumers when protecting large-scale sources | Is cost efficient | Prevents sensitive data breach or theft | Provides data realism | Provides referential integrity within and across databases |
|---|---|---|---|---|---|---|
| Static data masking | 65 | 57 | 64 | 62 | 60 | 63 |
| Dynamic data masking | 30 | 41 | 36 | 38 | 38 | 36 |
| Synthetic data | 42 | 34 | 27 | 30 | 36 | 34 |
| Data subsetting | 15 | 19 | 22 | 16 | 19 | 18 |
| Tokenization | 13 | 17 | 19 | 21 | 16 | 17 |
These findings reinforce static masking as a foundational and proven approach to achieve compliance and security. Organizations rely on static masking to protect sensitive data at scale, especially in non-production environments where full datasets are commonly used.
Static Masking Is Preferred for Protecting Data Across Many Use Cases
We also asked enterprise leaders which data protection approach they consider to be the most purpose-fit for protecting data for specific use cases, and again, they showed a strong preference for static data masking.
45% selected static masking for software development and testing, 32% for data analytics workflows, and 30% for integration and unit testing.
Static masking is the best option for maintaining data relationships across databases. That is why it works so well for testing (especially integration testing) and data analytics, whose results depend on the quality and referential integrity of data.
Which Solution do you consider the most purpose-fit approach to protect data for the following use cases?
| Category | AI/ML workflows | Data analytics workflows | Integration and unit testing | Software development and testing | Software development and testing when no production data exists |
|---|---|---|---|---|---|
| Static data masking | 27 | 32 | 30 | 45 | 38 |
| Dynamic data masking | 8 | 27 | 28 | 21 | 24 |
| Synthetic data | 56 | 14 | 12 | 13 | 22 |
| Data subsetting | 6 | 15 | 14 | 10 | 8 |
| Tokenization | 1 | 12 | 15 | 10 | 8 |
| Don't know | 1 | 0 | 0.5 | 0 | 0 |
While static masking provides the strongest foundation for protecting real datasets, it is often complemented by synthetic data to address additional use cases. Combined, these approaches give teams compliant, high-quality data for full testing coverage and AI workflows.
Back to top
Synthetic Data Is Still Evolving as a Protection Method
While synthetic data is widely used, based on the solutions available at the time of the survey, fewer respondents identified it as sufficient for certain core data protection requirements compared to more established methods.
We see this as a reflection of where the market is today. Synthetic data is still a maturing category, and the available solutions at the time of the survey may not have fully met enterprise leaders’ expectations for data protection.
Additionally, many organizations are using synthetic data mainly to support development speed rather than as a primary compliance control.
As the market evolves and newer, more advanced solutions become available, we expect these perceptions to continue to shift. For now, most organizations view synthetic data as part of a broader approach. It complements other, more established protection methods.
Back to top
Beyond Security, Scalability and Usability Shape Solution Choice
Unsurprisingly, 43% of respondents said security is the most important factor when evaluating a data protection solution.
But beyond this obvious most important criterion, the next most important ones included:
24%
Scale and speed
23%
Ease of use and user experience
These criteria determine whether a solution can be used consistently and easily across large, complex environments without impacting speed of innovation.
A solution must protect data effectively, but it must also keep up with the pace of development and analytics — including increasingly automated, agentic workflows.
What are the most important criteria you use to evaluate a data protection solution for your organization? Select up to two.
| Category | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Security | 43 | |||||||||||
| Scale/speed | 24 | |||||||||||
| Ease of use/UI | 23 | |||||||||||
| Cost efficiency | 18 | |||||||||||
| Data quality | 16 | |||||||||||
| Sensitive data discovery | 15 | |||||||||||
| Ease of onboarding | 11 | |||||||||||
| Integration with data delivery | 11 | |||||||||||
| Automation | 10 | |||||||||||
| Support for specific data sources | 9 | |||||||||||
| Support for multiple use cases | 5 | |||||||||||
| Other | 15 |
"As data refresh cycles accelerate and data consumption explodes, protection must move at the same speed. Because security that only works on paper isn’t security, it’s inertia."
Speed and Scale Require Better Data Delivery
Security alone isn’t enough. Teams need fast, reliable access to high-quality data to keep up with modern development and AI demands. Our 2026 Test Data Management Report for AI-Ready Enterprises reveals where workflows are breaking down, what enterprises are doing about it, and how to lay out a roadmap for agentic development.
Enterprises Must Protect Data Across Both Legacy and Modern Systems
Organizations are also managing an increasingly diverse set of data sources. In non-production environments, data must be protected across both traditional systems and modern platforms.
The most common sources organizations wish to mask are no surprise: Oracle (47%), Microsoft SQL Server (42%), Microsoft Azure data sources (31%), and SAP (28%).
Analytics data platforms are also a priority, including Databricks (25%) and Snowflake (18%), indicating a need to protect sensitive data in other non-production environments like AI, ML and analytics.
This data reflects the reality of enterprise environments today. Data is not confined to a single system or architecture. It spans on-premises systems, cloud platforms, and analytics environments, all of which must be protected consistently.
This underlines the need for solutions that enable organizations to apply a single compliance policy across multiple data systems.
What data sources does your organization need to mask when used in non-production environments? Select all that apply.
| Category | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Oracle | 47 | ||||||||||||||
| Microsoft SQL Server | 42 | ||||||||||||||
| Microsoft Azure sources | 31 | ||||||||||||||
| SAP | 28 | ||||||||||||||
| Databricks | 25 | ||||||||||||||
| Snowflake | 18 | ||||||||||||||
| Salesforce | 15 | ||||||||||||||
| Microsoft Dynamics | 14 | ||||||||||||||
| Unstructured text data | 5 | ||||||||||||||
| Workday | 3 | ||||||||||||||
| Microsoft Fabric sources | 3 | ||||||||||||||
| Guidewire | 2 | ||||||||||||||
| Unstructured visual data | 1 | ||||||||||||||
| Trizetto | 1 | ||||||||||||||
| Murex | 0.5 |
A Complex Enterprise Landscape Requires Flexible, Scalable Protection Strategies
In our opinion, these findings point to a complex landscape.
Organizations combine multiple methods to meet different needs across environments and use cases.
In practice, this includes:
- Using static masking for large-scale non-production protection.
- Applying dynamic masking in some analytics and access control scenarios.
- Leveraging synthetic data for testing and AI use cases.
This portfolio approach reflects the need to apply the right protection method to the right use case, based on specific data, performance, and requirements. It highlights the advantage of unified platforms that bring multiple approaches together — along with data delivery, governance, and centralized control — to apply consistent protection while supporting speed and scale.