Cybersecurity strategy is being reshaped by a simple but increasingly unavoidable reality: data now moves far more freely than the systems designed to protect it.
As organisations increasingly operate across cloud platforms, software-as-a-service (SaaS) tools and highly distributed collaboration environments, traditional security boundaries — networks, devices and even access or identities — no longer define where risk begins or ends. Information is created, shared and reused across systems that are dynamic, porous and often outside a single organisation’s direct control.
In a recent blog post for global data-centric security software provider archTIS Ltd (ASX:AR9, OTCQB:ARHLF), Kurt A. Mueffelmann, president and chief strategy officer of archTIS U.S. Inc., argues that this shift is driving a fundamental change in how digital security is architected. Rather than treating data as something protected indirectly by networks or user permissions, Mueffelmann says security is increasingly being rebuilt around layers of protection at the level of the data itself — an approach closely aligned with Zero Trust principles.
“This progression — from knowing where data exists to governing how it is accessed and used — represents a critical layer of value creation within Zero Trust architectures,” Mueffelmann wrote.
Crucially, this is no longer a theoretical framework or emerging trend. Zero Trust — built on the assumption that breaches are inevitable and that trust must be continuously verified — is now being locked in through regulation, enforced by emerging policy mandates, and the sector bolstered by institutional investment.
Zero Trust moves from framework to obligation
Zero Trust has been discussed for years as a best-practice model, but adoption was often uneven, incremental or confined to specific use cases. What has changed, as Mueffelmann outlines, is the shift from voluntary adoption to enforced implementation.
In November 2025, the US Department of Defense (DoD) issued a directive requiring all DoD components, military services and combatant commands to achieve “Target Level Zero Trust” enterprise-wide by September 30, 2027. The language was unambiguous: compliance was described as “non-negotiable”, with quarterly reporting requirements and escalation mechanisms in place for any delays.
The mandate signals that Zero Trust is no longer just an architectural preference — it is becoming a baseline requirement for large, complex and heavily-regulated organisations. Once that threshold is crossed, security spend shifts from discretionary programs to core infrastructure, with long-term implications for procurement and capital allocation.
“Zero Trust is moving from conceptual frameworks to operational reality, with data at its core,” Mueffelmann said.
Why data is becoming the control plane
Mueffelmann’s central argument is that Zero Trust cannot be implemented effectively without a data-centric foundation – that is, with data itself layered with protective mechanisms, not just the systems that store it.
While identity and network controls remain necessary, they are no longer sufficient once data is accessed, shared or replicated.
“Network boundaries are increasingly porous, and identity, while essential, is no longer sufficient on its own,” Mueffelmann wrote. “What remains constant across every environment is the data.”
A data-centric security model treats information as the primary object of protection. Sensitivity, context and policy are bound to the data, allowing access and usage to be governed continuously — not just at the point of entry. This approach aligns directly with Zero Trust’s assumption of a breach, ensuring that trust is not granted once and then forgotten, but continuously evaluated.
From an architectural perspective, this represents a shift in what effectively becomes the “control plane” of security, Mueffelmann says. Instead of relying on static perimeters, security policy follows the data wherever it resides or is shared.
From visibility to governance and enforceable control
According to Muefflemann, a “shift from visibility to governance and control” has also been shaping both enterprise demand and valuation.
“Early data security tools focused on discovery and classification — critical capabilities that established awareness of risk but stopped short of resolving it,” he wrote.
“Today, enterprises are increasingly focused on how policy is applied, governed and enforced once sensitive data is identified,” he added. “This has created demand for capabilities that sit between discovery and enforcement — ensuring security intent is translated into consistent, real-world outcomes.”
As organisations mature in their Zero Trust adoption, attention is shifting from knowing where data exists to controlling how it is accessed, shared and governed in practice. That includes aligning access decisions with policy intent, handling exceptions, coordinating approvals and maintaining auditability — all without disrupting productivity.
This transition is particularly important in regulated, sovereign and mission-critical environments, where security outcomes must be demonstrable and enforceable, not just well documented.
Capital is following architecture, not hype
Recent private-market activity reinforces this view, Mueffelmann says.
He points to a US$400 million investment Blackstone led in Israeli cybersecurity company Cyera in late 2025, valuing the business at around US$9 billion. While the headline number attracted attention, Mueffelmann argues the more important signal was what the valuation represented: “strong institutional conviction that data-centric security now sits at the core of modern cybersecurity and Zero Trust architectures.”
“This was not simply a bet on a single company,” he wrote. “It was a validation of an entire security paradigm.”
For public-market investors, this raises a broader question. Valuations in private markets are increasingly being assigned based on capability and strategic relevance, rather than operating history or listing venue. That dynamic is creating a widening gap between how private capital prices exposure to data-centric security and how comparable execution capability may be valued in listed markets.
Regulation is compressing adoption timelines
Mandates like the DoD’s Zero Trust deadline in 2027 are accelerating this shift by compressing adoption timelines. When compliance becomes compulsory rather than aspirational, organisations are forced to move beyond pilots and proofs of concept. Architectural decisions harden, procurement cycles accelerate and security spend becomes embedded in long-term budgets.
From an investment perspective, this matters because regulation reduces the risk that data-centric security is a passing theme. Instead, it positions it as structural infrastructure, underpinned by policy, accreditation and compliance requirements.
“Large-scale institutional investments of this nature are not driven by short-term enthusiasm,” Mueffelmann wrote. “They reflect long-term conviction in structural change.
“Regulatory complexity, data sovereignty requirements and the continued expansion of digital collaboration ensure that data-centric Zero Trust security will remain a foundational enterprise requirement for years to come.”
Where archTIS fits in a data-centric Zero Trust landscape
Within this evolving landscape, archTIS has focused on security at the data layer, particularly in environments where collaboration, sovereignty and policy enforcement intersect.
Rather than stopping at visibility, the company’s approach centres on contextual access control and continuous enforcement — enabling organisations to govern how sensitive information is accessed and shared across complex, multi-party environments.
“The company has consistently prioritised protection at the data layer, applying contextual access controls and continuously enforcing policy across collaboration and information-sharing environments,” Mueffelmann said.
“Critically, archTIS operates at the intersection of policy intent and execution, enabling organisations to move beyond visibility toward enforceable, auditable control,” he added. “This positioning aligns directly with the architectural layer now attracting significant institutional capital and premium valuation frameworks elsewhere in the market.”
As Zero Trust continues its transition from framework to obligation, the ability to operationalise data governance — rather than simply describe it — is becoming a defining capability.
A structural shift, not a short-term cycle
The convergence of regulatory mandates, architectural change and capital allocation suggests data-centric Zero Trust security is not a short-lived trend.
Rising geopolitical tension, increasing regulatory complexity and the continued expansion of cloud-based collaboration all point to a future in which protecting the perimeter is no longer enough. Protecting the data — persistently, contextually and enforceably — is becoming the baseline.
For investors, the opportunity lies in understanding where value accrues as Zero Trust moves from aspiration to requirement, and as data becomes the true foundation of modern cybersecurity.