Discovering a potential breach on a Friday afternoon starts a clock.
GDPR requires notification within 72 hours, and that window doesn’t pause while analysts pull logs from disconnected systems and reconcile timestamps across tools that were never designed to work together under deadline. The problem is that only 12% of organizations can produce a comprehensive and auditable chain of custody quickly when regulators, auditors, or legal teams ask for it.
The data I’m drawing on comes from research conducted by Cybersecurity Insiders, involving more than 1,000 security practitioners at organizations of 2,500 or more employees.
Every organization in the survey has invested in data protection tooling but very few of them can answer the question a regulator actually asks. The organizations that can have almost always built their evidence trail before the incident started, not after it.
What do regulators actually ask after a breach?
Security teams have spent years getting better at detecting incidents. They can tell you when a policy triggered, which user was involved, and which system generated the alert. What is far harder is demonstrating what happened before and after that moment, across every system the data touched, in a format that holds up under scrutiny. Security and legal teams in regulated industries (such as financial services, healthcare, and telecommunications) often discover that gap only when a breach notification deadline is already running.
While your SOC wants to know when a policy triggered, which user was involved, and which system generated the alert, the governance folk want to know where the data originated, who accessed it, how it moved, and whether appropriate protections were in place at every step. Worryingly, almost 50% of organizations require significant manual effort across multiple systems to produce that evidence (or struggle to produce it at all: 27% admit that they simply can’t reconstruct a sensitive data path before GDPR’s 72-hour notification window closes).
When data changes form, the trail goes cold
The evidence problem is hardest precisely where data is most dynamic. Only 9% of organizations can reliably recognize sensitive data after it has been modified, whether renamed, reformatted, summarized by an AI tool, or pasted into a new document. A file blocked from upload to a personal cloud account can reappear minutes later as an AI-generated summary or a pasted excerpt in a collaboration tool, the original file was untouched but the sensitive content is already elsewhere.
This creates an audit trail problem that traditional approaches weren’t designed for. Confidence in tracing sensitive data drops from 25% for identifying who accessed a document to 8% for tracing AI-generated content back to its source. When a data subject request arrives asking an organization to confirm it has found all instances of an individual’s data, 9% can’t confirm categorically that they have.
Evidence as a byproduct, not a deliverable
What I find most striking here is that the organizations meeting regulatory deadlines aren’t necessarily better at detecting incidents than those that miss them. What they have done differently is building classification, lineage, and policy-event records into daily operations as a continuous output of how data is governed, not as something assembled when an incident fires.
The distinction is architectural. An organization that builds evidence into daily protection workflows has already correlated the data path, the user or agent involved, and the policy events triggered … before the regulatory clock starts. An organization that treats evidence as a post-incident task is always starting behind.
When 19% of organizations take weeks or longer to reconstruct a sensitive data path, and 8% rarely have enough data to reconstruct it at all, the gap has less to do with detection maturity than with the absence of a shared evidence layer built before the incident began.
Building continuous evidence into daily operations
Netskope One Data Security is built around this principle. Netskope One DSPM and Netskope One DLP work together to maintain persistent classification and lineage across the environments where sensitive data is stored, used, copied, and transformed. Netskope One Data Lineage tracks data movement across connected systems, from the moment a file is created and wherever it travels. And Netskope One DataSec Command Center is a centralized intelligence layer that unifies data security by correlating signals into a single workflow. Coverage extends to AI tools, private applications, and cross-application workflows, where conventional audit trails typically lose visibility.
When an analyst needs to prove what happened, the evidence trail is already connected rather than assembled on demand, because it was built through those same classification and lineage workflows. That includes data that changed form through copying, AI summarization, or rewriting, covering precisely the vectors most organizations struggle to audit today.
The 72-hour clock starts the same way for every organization: without warning. What decides the outcome is whether the evidence trail already exists, or whether someone has to build it while the clock runs.
Download the 2026 Unified Data Security Report to see the full findings on evidence readiness, data lineage, and where the audit trail breaks down.
* Cybersecurity Insiders and Netskope, 2026 Unified Data Security Report, June 2026