iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AI-assisted security analysis can only connect activity that its systems can see and interpret. Danelle Au’s argument is that defenders need high-fidelity data linked across systems and enriched with operational context—not merely more alerts. But broader visibility can expose sensitive business information, so data control, privacy, and sovereignty have to be designed alongside collection.
Why does AI-driven security depend on complete data?
Security events often make sense only in relation to other events. An endpoint alert, a cloud upload, and an external email may look like separate issues when each is examined alone. Connected with identity, timing, and the file’s history, they may form a more useful picture for an analyst or an AI system.
In her August 27, 2026 opinion article for SecurityWeek, Danelle Au argues that security products filter and normalize telemetry before it reaches a SIEM, leaving “roughly 10–20%” of the environment’s generated data. That figure is Au’s estimate: the article does not provide a study or method establishing it as a general industry measurement. The broader point is that a system cannot reason from events it never receives, or from records stripped of details needed to relate them.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
This is a persuasive architectural thesis, not proof that collecting every available data source will improve security. Data quality, provenance, linkage, retention, and governance all affect whether additional information helps.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How can activity across systems change the interpretation?
Au illustrates the problem with a hypothetical employee-exfiltration sequence: a departing employee downloads a competitive-analysis document, uploads it to personal cloud storage, then emails it externally. This is an example, not a reported incident.
Separate data-loss prevention (DLP) or cloud access security broker (CASB) alerts might each capture one step. To investigate the sequence, a team could need to establish who accessed the document, whether its contents or lineage connect the events, how the user’s behavior changed over time, and whether the timestamps fit a coherent chain. The value lies not just in collecting more alerts, but in being able to query and connect relevant evidence.
What kinds of information might provide context?
Au’s proposed picture reaches beyond conventional security logs. She names network, operational technology (OT), Internet of Things (IoT), SaaS, cloud, human and non-human identity data, as well as business content such as source code, customer records, and financial models. These are possible sources of context, not a universal collection mandate.
Recommended Free Tools
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Different sources answer different questions. Identity records can help associate an action with an account or service; network and cloud events can show where activity occurred; operational data can reveal how systems are used; and business content may help determine the significance of a file or record. The usefulness of each source depends on whether it is reliable, appropriately linked, and necessary for a defined security purpose.
- Telemetry: Preserve the relevant event details and their provenance rather than treating a normalized alert as the whole record.
- Context: Relate events to identity, assets, time, and business activity where doing so is justified.
- Queryability: Retain enough lineage and history to investigate how a conclusion was reached.
- Governance: Apply purpose limits and access controls, especially when business content or sensitive records are involved.
Why is completeness not simply a matter of collecting more?
Broad collection can increase exposure as well as visibility. If a security environment includes “crown jewels” such as customer information, source code, or financial models, organizations need to decide where data and analysis reside, who may access raw inputs and outputs, what models are used, and which authorities could compel access. Au treats privacy and data sovereignty as complements to completeness, not reasons to ignore security needs.
Those are architecture and governance questions, not legal conclusions. Au’s article mentions regimes including GDPR, the U.S. CLOUD Act, DORA, and HIPAA, but does not establish how any one applies to a particular organization or design. Applicability depends on facts such as jurisdiction, data type, processing, and contractual arrangements; organizations should assess those questions with appropriate legal and privacy expertise.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What does public testimony add to the data-quality argument?
A 2024 U.S. House hearing provides relevant context, but it does not independently verify Au’s telemetry estimate. In prepared testimony dated May 22, 2024, Michael Sikorski, CTO and vice president of engineering at Unit 42, Palo Alto Networks’ threat-intelligence and incident-response division, said, “AI models are only as good as the inputs they are trained on.” The hearing record also includes testimony about cyber-defense AI and the importance of auditable, interrogatable inputs.
Free tools Windows power users keep installed
One-click scans. No signup required.
Sikorski reported that his company’s AI-powered SOC ingested 59 billion events daily and reduced them to 26,000 raw alerts, then 75 requiring further analysis. He also described customer outcomes reported by his company: response times reduced from 2–3 days to under 2 hours, a fivefold increase in incident closeout rates, and a fourfold increase in daily security data ingested and analyzed. These are company-reported figures in testimony, not independently evaluated benchmarks. The testimony supports the relevance of data quality and triage to cyber-defense discussions; it should not be read as independent proof of product performance.
The distinction matters: a public hearing can document what experts and companies told lawmakers, while its claims still require attribution and independent evaluation before being treated as established performance evidence.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How should an organization assess a data architecture?
Au’s article does not compare products or prescribe a deployment model. For an architecture review, the issues it raises translate into practical questions rather than a universal scoring formula:
- Coverage and fidelity: Which sources are available, and what event details are lost through filtering, normalization, or retention limits?
- Cross-system context: Can analysts connect identity, endpoint, network, cloud, SaaS, and relevant business events without assuming that isolated alerts tell the whole story?
- Lineage and investigation: Can the team trace data from its origin through transformations and query historical activity when an investigation needs it?
- Control: Where do data and models run, who can access inputs and outputs, and how are permissions enforced?
- Privacy and legal governance: Is each source needed for a defined purpose, and have applicable obligations been assessed for the organization’s circumstances?
- Operational burden: What integration, storage, maintenance, and analyst workload would broader collection add?
The goal is not maximal collection by default. It is enough trustworthy, connected evidence to answer security questions, with controls proportionate to the sensitivity and risk of that evidence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

