CyberDefenseMagazine

AvePoint: Industry Highlights from Black Hat 2026


Most organizations think they’ve solved the data sensitivity problem. AvePoint’s research says otherwise. In the company’s third annual State of AI Report, 82.7% of organizations said they were “very” or “extremely” confident in their ability to prevent unauthorized AI data access. Yet 72% of that same confident group had already experienced an AI-related unauthorized access incident in the past 12 months.

I sat down with Dana Simberkoff, AvePoint’s Chief Risk, Privacy and Information Security Officer, at Black Hat to unpack that gap, and to talk about Kinetic Classification, the product AvePoint launched on that very same day.

The Problem

The core issue, Simberkoff said, isn’t that security teams are careless. It’s that basic data hygiene, tagging and classifying information properly, has been underfunded for two decades, and both humans and automated tools have historically been poor at it. Users tend to either underclassify data to work around security barriers, or overclassify everything just to simplify their own lives.

Kinetic Classification is built to close that gap by continuously reassessing sensitivity as data changes, rather than relying on a one-time label that quickly goes stale. That distinction matters more than ever in an agentic AI environment, where the real question isn’t just whether a document is confidential, but whether an AI agent should be allowed to touch it at all. “You can build rules for agents around what they can and can’t access,” Simberkoff said, “based on those types of boundaries.”

How It’s Different

Simberkoff draws a clear line between AvePoint and much of the rest of the floor. “A lot of vendors here are looking at asset management, looking at the bones, the skeleton,” she said. “What AvePoint is looking at is the blood, what keeps you alive.”

As she put it, no single security solution solves everything; real protection requires a layered approach built around context, content, and access, understanding not just what happened, but what it means and why it matters.

Order Matters

Classification tells you what’s sensitive. AvePoint’s other big announcement this week, upgrades to its Rapid Recovery system, is about what happens next, once something’s already gone wrong. The new intelligence layered into Rapid Recovery includes recommendations that pinpoint the most critical data to restore first, a wizard that lets teams pre-build and sequence a recovery plan before disaster ever strikes, and Express Recovery for Entra ID, extending that prioritized restoration down to the identity layer. The idea is to replace the days of manual triage that typically follow a breach with a recovery plan a team can simply execute under pressure.

The Proof

AvePoint’s strongest evidence, according to Simberkoff, is that the company runs on its own product. When AvePoint rolled out Copilot internally, her team used their own classification technology to prepare for it, cleaning up and properly tagging content across SharePoint and OneDrive before opening the door to an AI agent. The lessons learned from that internal rollout fed directly back into the product roadmap. AvePoint also maintains customer advisory boards for ongoing feedback, and the company’s 25-year track record, along with customers who’ve stayed a decade or more, adds a layer of institutional trust that’s hard to manufacture.

 The One-Sentence Takeaway

 Simberkoff’s answer to what a CISO should take from this interview: “Metadata is a love note to the future.” She’s been making that case for two decades, and her explanation for why it still matters is one of the more memorable analogies I heard all week. AI, she says, behaves like Pac-Man: it will consume everything in its path unless something builds the walls that tell it where it can’t go. Classification is how those walls get built.

Her broader outlook on the industry has also been sticking with me. Simberkoff said that she sees a real promise of AI in security; rather than detecting and responding, we can move towards predicting and preventing. Despite two decades in an industry defined by risk, her closing note was one of genuine optimism: it’s an exciting time to be in security, and there’s real opportunity in that, even amidst the complexity.

About the Author

Arya Baviskar is a Women in Cyber scholarship winner and Reporter at Cyber Defense Magazine. She is an undergraduate student at Northeastern University studying cybersecurity. As she approaches her second year in university, she is training in Cyber Threat Intelligence as an intern at the Cyber Security Forum Initiative. Additionally, she is an AI Trainer at Handshake AI, evaluating LLMs for bias and safety. What ties her experiences together is a consistent focus on making complex technology more transparent and accessible to the people that it affects. Arya can be reached online at [email protected] or through her LinkedIn: www.linkedin.com/in/aryabaviskar.

 



Source link