Index / Fundamentals

Data at Rest, in Motion and in Use

kind
Explainer
domain
Data
stage
Fundamentals
read
2 min
assumes
No prior programme in place

The three states determine which controls are even possible. Most programmes cover one and assume they have covered the problem.

The distinction sounds academic and determines what you can actually do. Each state offers different visibility, different controls and different costs.

At rest

Data sitting in storage: file shares, databases, cloud repositories, endpoints, backups.

What you can do here. Discovery — find where sensitive data actually is. Classification. Encryption. Access control. Retention and deletion.

Why it is the most neglected. It produces no alerts and no dashboard. Nothing happens, so nobody notices the absence of controls.

Why it matters most. Every incident starts with data existing somewhere accessible. Reducing what exists, and who can reach it, prevents more than any detection rule. The quarterly extract saved to a shared drive in 2019 is a larger exposure than anything moving today.

The highest-value action: find and delete copies nobody needs. It is unglamorous, it is not a product purchase, and it removes risk permanently rather than detecting it.

In motion

Data crossing a boundary: email, web upload, file transfer, API calls, cloud sharing.

What you can do here. Inspection, blocking, alerting, encryption in transit.

Why it dominates programmes. It generates events, which produce dashboards, which produce the feeling of a working programme.

The limitation. Encryption means much of it is opaque without inspection you may not want to deploy. And cloud-to-cloud movement never crosses your network at all, so the traditional control point sees nothing.

In use

Data open on an endpoint: displayed, edited, copied, pasted, printed.

What you can do here. Endpoint agents observing file operations, clipboard, removable media, printing.

Why it is necessary. It is the only state where you see actions that never touch the network — copying to a USB drive, pasting into a browser, printing.

The cost. Highest privacy impact of the three, since the agent sees everything the person does on the device, and highest operational cost.

What a single-state programme misses

At rest only: you know where data is and nothing about where it goes.

In motion only: the common case. You see traffic through monitored channels and remain blind to what sits in unmanaged copies, and to cloud-to-cloud movement.

In use only: you see endpoint activity and miss data leaving via services accessed from a browser without a local file operation.

A sensible sequence

Start at rest. Inventory and access reduction cost the least, need no product, and remove risk rather than observing it. Most organisations skip this and buy inspection.

Then in motion, on the two channels that carry your volume. Usually email and cloud sharing.

Then in use, selectively. Removable media and print first, which have clear controls and low ambiguity. Broader endpoint monitoring later, with the governance to justify it.

The framing to bring to a budget conversation

A request to fund inspection is a request to observe data leaving. A request to fund discovery and access reduction is a request to have less data leave.

The second is cheaper, less contentious with employees, and reduces the population of possible incidents. It also does not demo well, which is why it is consistently underfunded.

If you have budget for one thing this year, the boring one is the better investment.