Share with your CISO
Perforce’s third annual State of Data Compliance and Security Report surveyed more than 500 leaders at enterprises above $1 billion in revenue and found a striking mismatch: 98% feel confident protecting sensitive data, yet 34% have already experienced breaches or theft and 43% have failed audits. Nearly every organization has data masking mandates in place, but 84% still allow compliance exceptions. The AI layer is no safer, with 98% confidence in AI workflow protection sitting alongside 68% concern about data leaks in those same environments.
What this means for your business
The pattern here is familiar to anyone who has watched enterprise security programs for more than a cycle or two. High confidence and high breach rates coexist because policy coverage gets counted as risk reduction before enforcement actually happens. If your organization sits in the 99% with data masking mandates, the operative question is not whether the policy exists but what percentage of non-production environments it reaches without exceptions, because that 84% exception rate is where 34% of breaches are living.
The AI-specific numbers deserve their own read. Databricks and Snowflake now ranking among the top sources requiring data masking reflects how quickly analytics platforms became load-bearing infrastructure for AI training pipelines, with sensitive data flowing through them at a scale and velocity that outpaces the governance frameworks enterprises built for traditional databases. The 51% of leaders citing data quality as the top barrier to AI data protection is a quieter alarm than a breach headline, but it points to a structural problem: masked or synthetic data that degrades model quality gets overridden by developers under delivery pressure, which is precisely how exceptions proliferate. Eighty percent of enterprises plan to invest in AI data protection solutions in 2026 and 2027, which means the vendor landscape will get crowded fast and procurement decisions made in the next two quarters will anchor architecture choices for several years.
Perforce sells the Delphix platform that addresses exactly these gaps, so the survey’s framing around exceptions and non-production risk lands squarely on problems its product solves. That incentive probably sharpens the exception-rate finding more than it invents it, given that audit failure rates this high are independently verifiable through regulatory filings. The harder discipline for a CISO reviewing these findings is separating the genuine exposure signal from the product-shaped framing, and the genuine signal is this: if your exception approval process is informal, undocumented, or decentralized, your masking mandate is a paper control, and a paper control will not survive the next audit cycle or the next agentic AI deployment that touches production-adjacent data.
Concept deep-dive: Data masking in non-production environments
Data masking replaces real sensitive values, think customer names, account numbers, health records, with realistic but fictitious substitutes so developers and testers can work with data that behaves like production data without exposing live personal information. Non-production environments, development, QA, staging, are where most of the daily data access actually happens, and they typically receive less security scrutiny than production systems. When masking policies allow exceptions in these environments, real sensitive data enters the lowest-governed part of the stack.
Based on reporting from Perforce’s Latest Survey Finds Confidence vs. Reality Gap with Data Protection, originally published 2026-07-21 03:00:00.

