MSSP, Data Security, Governance, Risk and Compliance, SOC, SIEM

For MSSPs, Data Governance Fails Without Enforcement Beyond the Perimeter

While organizations have made progress in understanding where sensitive data lives, a bigger problem for them starts once the data moves outside the enterprise. File sharing, email, SFTP, APIs, and partner collaboration are still where policy breaks down. The partnership between Kiteworks and Concentric AI is aimed at addressing that gap.

Discovery does not equal control

DSPM and DLP tools do a solid job of identifying sensitive data and assigning risk. But those insights often stop at the perimeter. Once information is shared externally, enforcement becomes inconsistent or manual, and audit trails get fragmented. That disconnect is what this integration is trying to close.

David Byrnes, VP of Global Channels at Kiteworks, is clear that this is not about ripping and replacing existing controls. He told MSSP Alert, “Kiteworks complements rather than replaces existing DSPM and DLP investments. It acts as a downstream enforcement layer that ingests your existing data classifications and extends protection to external exchanges via email, file sharing, SFTP, APIs, and collaboration channels where traditional tools lose visibility,” Byrnes said.

How enforcement follows the data

Concentric AI’s platform discovers and classifies sensitive data using semantic context, applying labels tied to regulatory and business risk. Kiteworks consumes those labels and automatically enforces controls when data is shared externally. That can include encryption, access restrictions, download controls, watermarking, and time-limited access, all applied without manual intervention.

Byrnes framed this as finishing the architecture rather than consolidating it. “This layered approach protects your investment by leveraging the sensitive data labels and risk scores you've already implemented through tools like Concentric AI, then ensures those classifications are consistently enforced when data travels beyond your perimeter to partners, vendors, and external collaborators,” he said.

“Customers should think of Kiteworks as completing their data security architecture rather than consolidating it, closing the critical gap between internal discovery and external exchange while delivering unified governance across the entire data lifecycle.”

For security and compliance teams, the value is less about new dashboards and more about fewer handoffs. Classification decisions automatically translate into enforcement actions. Audit trails are generated as data moves, not reconstructed later. That reduces both exposure and the day-to-day friction between security teams and business users who need to share information to keep operations moving.

How MSPs and MSSPs can package it

For service providers, the joint capability lends itself to a governance-led offering rather than a point security service. Byrnes suggests positioning it as a managed program rather than a tool resale.
“The clearest packaging approach is a Managed Data Governance & Compliance Service that positions the Concentric AI and Kiteworks integration around a ‘Discover, Classify, and Enforce’ value proposition,” he said. “This broader framing appeals beyond security teams to compliance officers, risk managers, and business leaders who care about regulatory outcomes.”

That model supports recurring revenue through policy tuning, compliance reporting, SOC and SIEM integration, and ongoing governance reviews. It also shifts the MSP or MSSP into a more strategic role.
“This positioning elevates the MSSP from technical service provider to strategic partner delivering measurable business outcomes like audit readiness, breach risk reduction, and unified compliance across frameworks like NIST CSF, GDPR, HIPAA, and CMMC,” Byrnes added. By tying discovery and risk insight directly to external sharing controls, Kiteworks and Concentric AI are addressing one of the most persistent weaknesses in modern data security programs.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds