Meet Cy: Your Personal AI, Identity, and Data Security Analyst, On Demand

Cy brings Cyera’s data and AI security intelligence into the flow of work, helping you uncover risk, track progress, and communicate answers clearly.

Aug 17, 2026
Partager

It’s Monday morning, and your CISO needs an answer before the leadership meeting:

Where is AI creating risk, what sensitive data is exposed, and what should we do next?

That kind of question is becoming more common and harder to answer quickly. AI is creating new ways for data to be accessed, used, and exposed at record speed. Security teams need to understand what that means for sensitive data, how it impacts the business, and where to act first.

Cyera has the intelligence to answer those questions. It maps sensitive data, identity, AI usage, and agent activity so you can reduce exposure, accelerate remediation, and prioritize risk with business context.

Cy brings that intelligence into the flow of security work. Available anywhere in the platform, Cy helps you turn complex data, identity, and AI security signals into clear answers you can act on. You can ask questions in plain language, understand what matters, and share results in the format they need — from a quick explanation to a chart, CSV, report, dashboard, or executive summary.

The result: faster time to insight, more informed analysis, and clearer communication across security, compliance, governance, and leadership teams.

Ask anything about your data and AI risk posture

Cy lets you start with a business or security question, not a complex dashboard. Ask about data and AI risk in plain language, then refine the answer by business unit, data type, system, policy, project, or output format.

For example, you can ask:

  • “Which sensitive data is accessible by Copilot?” 
  • “Which external identities have access to sensitive data?” 
  • “Which business units pose the greatest risk to customer data?”

Cy draws from the intelligence Cyera already has across sensitivity, access, exposure, policy violations, remediation, projects, and business context. The result is a faster path from question to insight, helping teams understand their environment, surface what matters, and decide where to focus next.

Get fast, correlated insights across DSPM, DLP, and AI security signals

Insider risk and AI security questions rarely depend on one signal. A team may need to understand which employees, contractors, third-party identities, or AI-connected tools can access sensitive data; whether that access is inherited, excessive, or policy-violating; and whether the same data is tied to unusual downloads, sharing, DLP activity, or remediation work.

Cyera’s unified platform already brings that context together across DSPM, DLP, and AI security. Cy makes it easier to query that intelligence in one place, so you can get to specific answers faster without manually stitching together the story.

For example, you can ask Cy:

  • “Which risky users with access to restricted data triggered the most alerts?”
  • “Show contractors with access to crown-jewel data who were also involved in recent DLP incidents.”
  • “Which sensitive data is accessible by AI-connected tools or workflows?”

Cy reports on the intelligence already available in Cyera, helping you quickly understand where sensitive data is exposed, who or what can access it, who actually did access it, and whether that access connects to DLP activity or AI usage.

Every response can become the format the moment requires: a short explanation, table, chart, CSV export, shareable HTML report, executive summary, or dashboard widget. A user can ask for a specific CSV with selected columns, sorting, and structure. They can generate a board- or audit-ready report from a single prompt.

Track remediation and risk-reduction progress over time

Security teams also need to show progress over time. Cy helps you track remediation and risk-reduction according to the metrics that matter most to their company, then turn the answer into the format they need for program tracking or stakeholder reporting.

For example, a user can tell Cy:

  • “Create a report highlighting how we reduced risk this month”
  • “Generate a trend report on the remediation status of organization-wide access to confidential data.”
  • “Create a weekly status report for PCI remediation progress.”
July 16, 2026

Cyera Platform Risk Reduction Progress

Table of Contents

  1. Executive Summary
  2. Closed Issues Analysis
  3. Open & In-Progress Issues
  4. Monthly Trend Analysis
  5. Risk Reduction Velocity
  6. Low-Hanging Fruit Opportunities
  7. Forward-Looking Guidance

Executive Summary

This report provides a holistic view of risk reduction progress within the Cyera platform. It examines the lifecycle of security issues from detection through resolution, identifies patterns in remediation velocity, and highlights opportunities for accelerating risk posture improvement.

Total Issues Detected
1,741
Issues Closed
587
▲ 33.7% closure rate %
Issues Remaining
1,154
Records Remediated
106.1M
Records Still at Risk
150.5M
High-Risk Records
55.2M
!

Key Finding

While 587 issues have been resolved (33.7% closure rate), 1,154 issues remain open with 150.5M records at risk. Critical and High severity issues account for 705 of the open backlog, exposing 55.2M records to elevated risk. Closure rates have been inconsistent month-over-month, suggesting remediation efforts are not yet operating at a sustained cadence.

Closed Issues Analysis

A total of 587 issues have been resolved to date. The majority were auto-resolved by Cyera's platform intelligence (85.2%), indicating strong automated detection-and-resolution capabilities. However, manual remediation and proactive fixes remain a small fraction of closures.

Closed Issues by Resolution Type

500
ByCyera (Auto)
55
Datastore Deleted
28
Policy Edited
2
Fixed by Remediation
2
Accept Risk

Closed Issues by Severity

587
Closed
Critical 9% High 48% Medium 43%

Key Observations:

  • ByCyera (500 issues, 85.2%): The platform automatically resolved the vast majority of issues, typically when the underlying condition was corrected (e.g., encryption enabled, access revoked).
  • Datastore Deleted (55 issues): Indicates cleanup of unnecessary or orphaned data stores — a positive signal for data minimization.
  • Policy Edited (28 issues): Policy refinements closed issues that were no longer applicable after rule adjustments.
  • Manual Remediation remains minimal: Only 2 issues were explicitly fixed through remediation workflows, and 2 were accepted as risk — suggesting an opportunity to increase proactive human-driven resolution.

Open & In-Progress Issues

There are currently 1,154 issues that remain open or in progress. The severity distribution shows a concerning concentration at Critical and High levels, which together represent 61% of the open backlog.

Open Issues by Severity

Critical 329 issues High 376 issues Medium 422 issues Low 27 issues

Open Issues by Infrastructure (Top 6)

423
S3
254
OneDrive
95
RDS
80
Google Drive
71
On-Prem File Share
63
Snowflake

Top Policies Generating Open Issues

PolicyIssues
US Social Security Number in plain text120
Credit card number in plain text (FR)98
Credit card number in plain text97
European personal data stored outside Europe69
Restricted data accessible without MFA59
Passport Number in plain text56
Encryption in transit not enforced (S3)46
No logging of access/changes (S3)46
S3 accessible from inactive role46
S3 accessible by external AWS account46

Infrastructure Concentration: AWS S3 dominates the open issue landscape (37% of all open issues), followed by Microsoft OneDrive (22%). Together these two platforms account for nearly 60% of the remaining risk surface. The policy breakdown reveals that plain-text sensitive data (SSN, credit cards, passports) is the single largest category of violations, indicating systemic gaps in data-at-rest encryption or tokenization.

Monthly Trend Analysis

The monthly trend of issues opened versus closed reveals an uneven remediation cadence. While certain months show strong closure activity (November 2025: 91 closed, February 2026: 100 closed), others show minimal progress. New issue creation has been volatile, with spikes in July 2025 (366), February 2026 (218), and March 2026 (180).

Issues Opened vs. Closed Per Month

380 285 190 95 0 Jul 2025 Sep 2025 Nov 2025 Jan 2026 Apr 2026
Opened Closed
i

Trend Interpretation

The data shows a pattern of reactive remediation: closure activity spikes after periods of high issue creation (e.g., Feb 2026 saw both 218 opened and 100 closed). However, closures have never exceeded openings in any single month during the observed period, meaning the backlog has been growing. The most recent data (April 2026: 8 opened, 8 closed) suggests a brief equilibrium, but the sample is too small to confirm a sustained trend.

Velocity Assessment: Over the 10-month observation window, approximately 1,176 issues were opened while 423 were closed (excluding earlier closures). This yields a net accumulation rate, indicating that risk reduction is currently decelerating relative to new issue discovery. The platform is identifying risks faster than they are being resolved.

Risk Reduction Velocity

Risk reduction velocity measures whether the organization is closing issues faster than new ones are being created. The current data indicates a net-negative velocity — the open issue backlog is growing over time.

Overall Closure Rate
33.7%
Avg Monthly Closures
42
Avg Monthly Openings
118
Net Monthly Deficit
-76

Velocity Gap

On average, 118 new issues are opened per month while only 42 are closed — a 2.8:1 ratio of creation to resolution. At this pace, the open backlog will continue to grow unless closure rates are significantly increased or new issue creation is reduced through preventive controls.

What this implies for risk posture: The 150.5M records currently at risk represent a growing exposure surface. While 106.1M records have been remediated through closures, the inflow of new issues (particularly in data encryption and data sprawl use cases) is outpacing the organization's ability to resolve them. The high proportion of auto-resolved issues (85%) suggests that when conditions change, Cyera detects and closes issues efficiently — but proactive, human-driven remediation is lagging significantly.

Issue Resolution Progress

34%

587 of 1,741 total issues resolved (33.7%)
587/1741 issues

Low-Hanging Fruit Opportunities

Several categories of open issues represent relatively low-complexity remediation opportunities that could yield significant risk reduction with focused effort. These "quick wins" typically involve configuration changes, policy enforcement, or cleanup of stale resources.

Medium-Severity Issues with High Impact (Quick Wins)

PolicyIssuesRecords at Risk
Encryption in transit not enforced (S3)4612.5M
S3 accessible by external AWS account4612.5M
No logging of access/changes (S3)4612.5M
S3 accessible from inactive role4612.5M
Bedrock Agent can access sensitive data3711.9M
Restricted data in non-production env301.9M
Shadow users with access to PII (M365)297.1M
European data stored outside Europe69289K
Public endpoint enabled (Snowflake)142.0M
Encryption in transit not enforced (RDS)121.3M

Highest-Impact Quick Wins

The top 4 S3-related policies (encryption, external access, logging, inactive roles) each affect 46 datastores and 12.5M records. These are infrastructure configuration issues that can often be resolved through automated remediation (e.g., enabling TLS enforcement, revoking stale IAM roles). Addressing just these 4 policy categories would remediate 184 issues and protect approximately 12.5M records.

Additional low-hanging fruit categories:

  • Ghost datastore issues (14 issues): These affect orphaned datastores that may be candidates for deletion, which would immediately resolve associated issues.
  • AI Security (Bedrock Agent access, 37 issues): Given your focus on AI security, these represent both a quick win and a strategic priority — restricting Bedrock Agent access to sensitive data through guardrails.
  • Data Sprawl (616 open issues across use case): The largest use-case category; many sprawl issues can be resolved by moving data to approved locations or applying proper classifications.

Forward-Looking Guidance

Based on the analysis of current trends, risk concentration, and remediation patterns, the following strategic recommendations are provided to maintain and accelerate risk reduction momentum.

Priority 1: S3 Infrastructure Hardening

S3 accounts for 37% of all open issues (423 issues). A focused campaign to enforce encryption-in-transit, disable inactive role access, enable logging, and restrict external account access across all S3 buckets with sensitive data would eliminate approximately 184 medium-severity issues in one sweep. These are configuration-level fixes amenable to automation.

Priority 2: Plain-Text Sensitive Data Remediation

US SSN (120 issues), credit card numbers (195 issues combined), and passport numbers (56 issues) in plain text represent the largest single policy violation category. Implementing tokenization or encryption-at-rest for these data classes would address 371 issues and significantly reduce Critical/High severity exposure.

Priority 3: AI Security Guardrails

With 37 issues related to Bedrock Agent access to sensitive data (11.9M records) and 35 issues for M365 Copilot access (10.3M records), AI tool governance is both a quick win and a strategic imperative. Implementing access guardrails for AI services would protect over 22M records from potential AI-mediated data exposure.

!

Structural Recommendation

The current 2.8:1 ratio of issue creation to resolution is unsustainable. To reverse the growing backlog, consider: (1) Implementing automated remediation workflows for high-volume, low-complexity policies; (2) Establishing a weekly remediation sprint targeting 50+ closures; (3) Deploying preventive controls (e.g., SCPs, guardrails) to reduce new issue creation at the source.

Recommended Focus Areas by Timeline:
Immediate (0-30 days): Address S3 configuration issues (184 issues, automated fix), delete ghost datastores (14 issues), and restrict AI tool access (72 issues).
Short-term (30-90 days): Implement tokenization for plain-text PII/PCI data across S3 and RDS (371 issues). Enforce MFA for restricted data access (59 issues).
Medium-term (90-180 days): Address data residency violations (69 issues), establish preventive controls to reduce new issue creation rate, and build sustained remediation cadence targeting 100+ closures/month.
Target State: Achieve a closure-to-creation ratio above 1.5:1 to systematically reduce the open backlog and bring total records at risk below 50M within 6 months.

That makes Cy useful not only for one-off answers, but for ongoing programs where you need consistent visibility into what has changed, what remains, where to focus next, and how progress is trending.

Keep useful questions for repeatable team workflows

The best Cy sessions often capture more than a single answer. They capture the scope, logic, follow-ups, and format that helped the team get to the right result. 

With Cy’s Saved Prompts, users can save a successful session as a reusable prompt. Cy captures the entire business logic from the conversation, so you can rerun proven analyses without rebuilding the prompt from scratch.

Saved prompts can be shared with other users, turning successful sessions into repeatable workflows for weekly reporting, project reviews, or future business units. Teams get consistent answers faster while making high-value analysis easier to reuse across the organization.

Grounded, governed, and trusted by design

Cy is designed for enterprise data security environments. It runs on LLMs in AWS Bedrock, with guardrails and controls designed to protect customer data. Cy is grounded in each customer’s Cyera environment, with strict tenant isolation, no training on customer data, and conversations automatically deleted after 180 days.

Cy also links back into the platform, so users can verify the evidence behind an answer. That is critical for security teams: AI-generated output is only useful when users can understand where it came from, validate the underlying data, and trust the workflow around it.

Turn AI security complexity into business clarity

AI is changing how sensitive data is accessed, used, and exposed. Cy helps teams turn that complexity into clear, quick, business-ready data by making Cyera’s intelligence accessible in plain language.

You can uncover where AI risk is emerging, understand what data is exposed, track remediation progress, and communicate results in the format stakeholders need.

The outcome: faster time to insight, stronger risk decisions, and clearer communication across security, compliance, governance, and leadership.

Book a demo to see Cy in action.

Partager