---
title: "Too Much Data Access: What’s Happening, and What Can Be Done"
description: We explore the causes and effects of unauthorized data access as well as some common solutions, including ShardSecure’s agentless data protection software.
image: https://shardsecure.com/hubfs/Digital%20image%20of%20womans%20eye.%20Security%20concept.jpeg
---

- [Home](https://shardsecure.com/)
- [Blog](https://shardsecure.com/blog)

# Too Much Data Access: What’s Happening, and What Can Be Done

![Picture of ShardSecure](https://shardsecure.com/hubfs/ShardSecure%20brand%20assets/Logo%20(2022)/Profile/ShardSecure-Logo__Profile--Purple-Inverted.svg "Picture of ShardSecure")

[ShardSecure](https://shardsecure.com) 

 February 6 2023 

![Rows of binary code superimposed over a human eye to signify the problem of too much data access in the cloud and on-prem.](https://shardsecure.com/hubfs/Digital%20image%20of%20womans%20eye.%20Security%20concept.jpeg "Rows of binary code superimposed over a human eye to signify the problem of too much data access in the cloud and on-prem.")

Too Much Data Access: What’s Happening, and What Can Be Done

It seems like every week there’s a report of a new data breach. As Apple notes in their [December 2022 white paper](https://www.apple.com/newsroom/pdfs/The-Rising-Threat-to-Consumer-Data-in-the-Cloud.pdf), “the data ecosystem has become so vast and interconnected that people are only as safe as the least secure company that interacts with any company that has access to their data.”

As it turns out, there are a whole lot of “least secure” companies. Apple gives the example of the famous SolarWinds supply chain attack in 2019, in which malicious hackers were able to gain access to as many as 18,000 organizations who used SolarWinds software. Those attackers were able to infiltrate Microsoft, Intel, the Department of Homeland Security, the US Treasury, and more.

Meanwhile, there were over 290 million victims of data breaches in the US in 2021 alone — a sizable majority of the country’s population.

Clearly, unauthorized data access is a huge problem. But why is it happening, and what can be done to stop it? We’ll explore the issue below.

## Why is there so much unauthorized data access?

In short, because there’s so much data. Data growth is happening at an exponential rate and, as the statistics reveal, shows no sign of slowing down.

- In 2020, [64.2 zettabytes of data](https://www.un.org/en/global-issues/big-data-for-sustainable-development) were created — a 314% increase from 2015.
- By 2025, an estimated [175 zettabytes of data](https://www2.deloitte.com/cy/en/pages/technology/articles/data-grown-big-value.html) will exist, half of which will be stored in data centers and half in the public cloud.
- Data generation is skyrocketing particularly in the areas of AI, machine learning, and the Internet of Things (IoT). It’s projected that there will be [over 25 billion IoT devices](https://financesonline.com/big-data-trends/) by 2030.

But it’s not just that data is growing exponentially — it’s also how the systems that manage that data are growing, and who’s being given access to them. While some new technologies like deep learning, machine learning, and novel language models genuinely do require access to vast amounts of data, access is often given inadvertently and inconsistently within companies.

According to a [2022 Cloud Security Alliance article](https://cloudsecurityalliance.org/blog/2022/12/27/minimizing-your-data-attack-surface-in-the-cloud/), systems are sometimes built quickly for companies without adequate security safeguards, with speed prioritized over safety. For companies that are blitzscaling (or even just growing a little more quickly than usual), new roles may be created without a clear understanding of what data access they do or should have.

In short, companies often don’t know how much data they have, [where it’s stored](https://www.lepide.com/blog/more-than-forty-of-companies-dont-know-where-their-data-is-stored/), or who has access to it.

## Minimizing data access in the cloud

To reduce the chances of a data breach, companies must first limit data access. One of the best options is the least-privilege approach of only granting access to the users who need it, and keeping even that access to a minimum. For instance, if read-only access is enough for a certain user, then organizations should ensure that write-only and admin access are not granted.

Other measures like MFA, biometric authentication, rapid incident response when breaches do occur, and [reducing the amount of data that’s retained in the first place](https://www.apple.com/newsroom/pdfs/The-Rising-Threat-to-Consumer-Data-in-the-Cloud.pdf) can all be helpful. Additionally, organizations can try:

- Reducing the number of systems that process sensitive data
- Addressing storage and infrastructure misconfigurations
- Isolating infrastructures that hold sensitive data
- Using privileged access management solutions
- Introducing clear policies for data retention
- Updating patches
- And more.

However, scholars and security experts agree that access controls are not sufficient to keep sensitive data safe. As one study from the [MIT Computer Science and AI Lab](https://www.w3.org/2010/api-privacy-ws/papers/privacy-ws-23.pdf) notes, “access control in itself is inherently inadequate as a framework for addressing privacy on the Internet.

### Traditional file-level encryption — and where it falls short

In the past, traditional file-level encryption was one of the best ways to keep data safe and reduce the impact of unauthorized data access. Encryption ensures that selected information is unreadable to unauthorized viewers, so even if someone does access data they shouldn’t, they won’t be able to read it.

But [file-level encryption also has downsides](https://shardsecure.com/blog/guide-modern-file-level-encryption). It typically requires the installation of agents or applications on a server or client system, which in turn brings endpoint management and incompatibilities with newer services and infrastructures. 

Agent-based file-level encryption can also slow down operations considerably, with performance lags ranging anywhere from 5% to 40%. And few traditional encryption solutions can provide the kind of strong data resilience features that ensure high availability and failover during outages and disruptions.

## ShardSecure: a modern alternative to file-level protection

ShardSecure is helping companies regain control of their data by protecting against the impact of unauthorized data access, regardless of where that data is stored.

Our plug-and-play technology maintains the confidentiality of unstructured data and metadata in specific files, folders, or storage locations. It separates data from infrastructure owners, maintaining privacy from cloud admins, local storage admins, and more. (This separation of duties also helps support compliance with cross-border regulations like the [GDPR](https://shardsecure.com/resources/white-papers/gdpr-schrems-ii) and [beyond](https://shardsecure.com/blog/beyond-the-gdpr).)

Just as importantly, ShardSecure’s solution does not require the use of agents or other resource-intensive processes, and it does not involve a performance hit. In some cases, it even improves performance. Organizations can store data anywhere — on-prem, in the cloud, or in hybrid- and multi-cloud environments — and remain well protected against the impact of unauthorized data access.

To learn more about ShardSecure’s benefits for file-level protection and advanced data security and resilience, check out our [solution brief](https://shardsecure.com/resources/briefs/advanced-file-level-protection) or visit our [resources page](https://shardsecure.com/resources) today.

### Sources

[The Rising Threat to Consumer Data in the Cloud | Apple](https://www.apple.com/newsroom/pdfs/The-Rising-Threat-to-Consumer-Data-in-the-Cloud.pdf)

[Big Data for Sustainable Development | United Nations](https://www.un.org/en/global-issues/big-data-for-sustainable-development)

[Data: A Small Four-Letter Word Which Has Grown Exponentially to Such a Big Value | Deloitte](https://www2.deloitte.com/cy/en/pages/technology/articles/data-grown-big-value.html)

[11 Big Data Trends for 2022/2023: Current Predictions You Should Know | Finances Online](https://financesonline.com/big-data-trends/) 

[Minimizing your Data Attack Surface in the Cloud | Cloud Security Alliance](https://cloudsecurityalliance.org/blog/2022/12/27/minimizing-your-data-attack-surface-in-the-cloud/) 

[More Than 40% of Companies Don’t Know Where Their Data Is Stored | Lepide](https://www.lepide.com/blog/more-than-forty-of-companies-dont-know-where-their-data-is-stored/) 

[Access Control is an Inadequate Framework for Privacy Protection | W3.org](https://www.w3.org/2010/api-privacy-ws/papers/privacy-ws-23.pdf)

## Read on

![](https://shardsecure.com/hubfs/Picture2.jpg)

June 15 2026

### [ShardSecure MCP Secure Gateway](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

[Read more](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

February 18 2026  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Unstructured Data Left Exposed: A Cloud Breach That Should Worry Every Enterprise](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

[Read more](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

November 12 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Can You Really Trust Hyperscalers with Your Data at Rest?](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

[Read more](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Acronis%20and%20ShardSecure%20unveil%20a%20groundbreaking%20technology%20partnership%20set%20against%20a%20backdrop%20of%20a%20sleek%20modern%20office%20filled%20with%20digital%20screens%20displaying%20dynamic%20data%20flows%20The%20atmosphere%20buzzes%20with%20excitement%20and%20anticipation%20illuminated%20by%20sof-1.png)

October 16 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Acronis + ShardSecure: Stronger data protection for modern threats](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

[Read more](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20portrays%20a%20hightech%20digital%20landscape%20filled%20with%20abstract%20representations%20of%20data%20security%20concepts%20At%20the%20forefront%20a%20glowing%20vault%20symbolizing%20advanced%20filelevel%20encryption%20stands%20tall%20surrounded%20by%20intricate%20patterns%20of%20fragmented%20data.png)

October 1 2025  | [Data Sensitivity](https://shardsecure.com/blog/tag/data-sensitivity)

### [Revolutionizing Data Security: How Agentless File Level Encryption Makes Stolen Data Useless](https://shardsecure.com/blog/sensitive_data)

[Read more](https://shardsecure.com/blog/sensitive_data)

![unstructured data](https://shardsecure.com/hubfs/Digital%20image%20of%20globe%20with%20conceptual%20icons.%20Globalization%20concept.jpeg)

September 15 2025  | [Cybersecurity News](https://shardsecure.com/blog/tag/cybersecurity-news)

### [Elevating unstructured data security: ShardSecure® and Entrust® Join Forces!](https://shardsecure.com/blog/entrust_partnership)

[Read more](https://shardsecure.com/blog/entrust_partnership)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/scales%20%20ransomware%20attack%20to%20pay%20the%20money%20or%20risk%20the%20attack.jpeg)

July 29 2025  | [Ransomware](https://shardsecure.com/blog/tag/ransomware)

### [CISOs on Strategic Considerations in Ransomware Response](https://shardsecure.com/blog/ransomware-fine)

[Read more](https://shardsecure.com/blog/ransomware-fine)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Image%20for%20AI%20data%20types-1.jpeg)

July 29 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [The Growth of AI is driving the Imperative of Securing Unstructured Data](https://shardsecure.com/blog/ai-unstructured-data)

[Read more](https://shardsecure.com/blog/ai-unstructured-data)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20hightech%20digital%20landscape%20showcasing%20a%20sleek%20modern%20office%20environment%20illuminated%20by%20soft%20blue%20and%20white%20lighting%20In%20the%20foreground%20a%20large%20computer%20screen%20displays%20intricate%20graphs%20and%20charts%20related%20to%20data%20security%20while%20a%20gr.jpeg)

July 22 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [How to make your SharePoint data of zero value in a zero day attack!](https://shardsecure.com/blog/sharepoint_breach)

[Read more](https://shardsecure.com/blog/sharepoint_breach)

[![ShardSecure®](https://shardsecure.com/hubfs/ShardSecure%20brand%20assets/Logo%20(2022)/ShardSecure-Logo__Horizontal--White.svg "ShardSecure®")](https://shardsecure.com/)

101 Avenue of the Americas, 9th Floor, New York, NY 10013, United States of America

[![linkedin](https://shardsecure.com/hubfs/_2023/li.svg) ](https://www.linkedin.com/company/shardsecure) [![tweeter](https://shardsecure.com/hubfs/_2023/tweeter.svg) ](https://www.twitter.com/ShardSecure) [![facebook](https://shardsecure.com/hubfs/_2023/facebook.svg) ](https://www.facebook.com/ShardSecure/) [![facebook](https://shardsecure.com/hubfs/_2023/youtube.svg) ](https://www.youtube.com/@shardsecure877)

© 2026 ShardSecure®. All rights reserved.   
[Privacy Policy](https://shardsecure.com/privacy-policy)

![websights](https://ws.zoominfo.com/pixel/62e7bb6d62a6b2008e071c83) ![](https://px.ads.linkedin.com/collect/?pid=5456580&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "ShardSecure",
    "url" : "https://shardsecure.com/blog/author/shardsecure"
  },
  "dateModified" : "2023-03-13T01:05:25.593Z",
  "datePublished" : "2023-02-06T13:00:00.000Z",
  "headline" : "Too Much Data Access: What’s Happening, and What Can Be Done",
  "image" : [ "https://shardsecure.com/hubfs/Digital%20image%20of%20womans%20eye.%20Security%20concept.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://shardsecure.com/blog/too-much-data-access",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://shardsecure.com/hubfs/ShardSecure-Logo__Horizontal--Purple-Inverted.svg"
    },
    "name" : "ShardSecure"
  }
}
```