Features Hub

Data Privacy Day: Top 5 ways CISOs can protect endpoint data

Wed 28 Jan 2026 | Andy Ward

Techerati promotional graphic featuring Andy Ward, SVP International at Absolute Security, highlighting Data Privacy Day and five ways CISOs can protect endpoint data.

Data Privacy Day is a reminder that protecting sensitive information and data depends on both strong security practices, having effective and updated solutions in place, and everyday responsibility across the entire organisation.

As businesses continue to operate across offices, home, and hybrid environments, and as distributed PC fleets continue to expand, the risks to data that resides on endpoints has grown significantly.

Ensure Cyber Resilience Across Endpoint Security Controls

Maintaining always-on, operational security controls across diverse endpoint environments has become increasingly difficult. Research shows that 22 per cent of the time, critical endpoint security controls fail to maintain acceptable protection and performance standards. This failure rate is measurable across leading Endpoint Protection Platforms (EPP), Security Service Edge (SSE) solutions, and Vulnerability and Patch Management platforms.

When these vital solutions silently fail, the risk of ransomware infections, data breaches, and operational disruption increases. Ensuring that controls remain operational and can auto repair themselves is essential to defending against modern threats and to ensuring the organisation’s Cyber Resilience isn’t weakened at the endpoint.

It is dangerous to assume that your edge defenses are functioning as expected, at all times. With AI increasingly used by cybercriminals to accelerate constant attacks, even a brief period where endpoints are left unprotected can result in a breach, compromise, or worse, extended downtime.

Keep Patching Up to Date

Outdated or inconsistent patching practices continue to expose organisations to unnecessary risk. Essential patches for PCs running Windows 10 and 11 are often delayed by nearly two months, far longer than recommended by authorities such as the Cybersecurity and Infrastructure Security Agency (CISA).

These delays leave known vulnerabilities unaddressed and give attackers more time to exploit them. Strengthening patching routines, automating updates, and ensuring continuous compliance are now essential steps in maintaining a resilient security posture and reducing exposure at the endpoint.

Build a Culture of Data Privacy and Security

Technology alone cannot protect sensitive information. For organisations to stay resilient against evolving cyber threats, employees also need to understand and act on data privacy and protection protocols.

This requires more than annual training, and rather through organisations promoting a culture of accountability and awareness that reduces the risk of breaches. Organisations can reinforce secure behaviours such as strong password hygiene or handling sensitive data through regular communication, clear policies and scenario-based training.

When people understand the role they play in safeguarding data, the likelihood of accidental breaches decreases significantly. A strong culture of privacy and security empowers employees to make safer decisions to ensure the organisation’s overall resilience remains strong.

Have Remote Access to Stop Cybercriminals

With work-from-anywhere still a reality across many organisations, centralised security teams must maintain clear visibility over endpoint fleets and device health, with the ability to freeze or shut off devices remotely, security teams can prevent lateral cybercriminals from expanding their presence through lateral movement when breaches do occur.

This is critical, particularly as 73 per cent of CISOs identify remote devices as the biggest weakness in their organisation’s cyber resilience posture. Os identify remote devices as the biggest weakness in their organisation’s cyber resilience posture.

Without the ability to isolate a device remotely, a single compromised laptop can quickly become a gateway for attackers to move deeper into networks and to access sensitive data stored on them.

As many cyberattacks begin at the endpoint, not the firewalls or servers, real-time visibility and the ability to take decisive action regardless of the device location is critical for any CISO seeking to build a resilient organisation.

Rapid Endpoint Continuity Restoration

Cyber incidents are inevitable. According to Absolute Security’s The Resilient CISO eBook and 750 CISO survey, in the past 12 months alone, 55 per cent of CISOs reported their organisation had experienced a cyberattack, ransomware infection, compromise, or data breach that rendered mobile, remote, or hybrid endpoint devices inoperable.

When threats strike, organisations need a fast and reliable way to restore compromised devices remotely, even when Windows PCs have been rendered inoperable by ransomware, system crashes or software failures.

Modern Cyber Resilience requires the ability to recover devices even when the operating system is damaged or inaccessible, ensuring teams can respond at scale without physical access. This ensures that endpoint data remains protected, as recovery restores the security controls that safeguard information and prevents sensitive data from remaining exposed on devices that can’t be accessed or secured.

Once recovered, devices must return to a secure, compliant state so operations can continue safely.

This level of rapid restoration reduces downtime, limits business disruption and helps organisations maintain operational continuity in the face of increasingly damaging cyberattacks, making endpoint recovery a critical enabler of true Cyber Resilience.

Join Cloud & Cyber Security Expo

4-5 March 2026, ExCeL London

From Threat to Trust – Secure Your Stack, Protect Your Business.

Join CISOs, Architects, and Risk Leaders tackling Zero Trust, post-quantum encryption, and AI threats at the UK’s most comprehensive security event.

Experts featured:

Send us a correction Send us a news tip

Subscribe for News in Your Inbox