
Opinion
A quiet security system can be a warning sign
"Months of reasonable compromises can leave a company with less protection than it thinks it has," writes Ido Livneh, CEO and co-founder at Jazz. "Most security leaders cannot tell you whether their system got quieter because the data is understood or because it stopped being watched."
Every DLP deployment collects exceptions. Someone in finance keeps getting blocked uploading to a vendor portal, so a rule gets narrowed. An engineering group triggers the same match forty times a week and nobody has time to look at number forty-one, so that path comes off the list. Each of those decisions is reasonable on the day it gets made, and most of them are correct. Two years later nobody can tell you what the exceptions cover.
I have spent years building security products and talking to the people responsible for protecting company data, and this pattern shows up almost everywhere. Matches arrive faster than anyone can investigate them, so security teams narrow the scope until the queue is survivable. The result is that staffing levels end up setting security policy. A security team believes it has decided which risks the company accepts, when what it has really decided is which investigations it can afford.
The difficulty is that you cannot tell the two apart from the alert count. A drop might mean people are handling data more carefully, or it might mean the system stopped examining a category of activity eighteen months ago. Both produce the same graph. The only way to separate them is to know what was checked before the system concluded there was nothing to report.
Exceptions also drift. A team approves a particular transfer after verifying the document, the recipient and the purpose, and then somebody writes the exception against the service rather than against the transfer. Every upload to that service passes from then on, including one going to a personal account. Later the adviser's engagement ends and the employee moves to a different group, and the permission stays exactly where it is, because nothing in the transfer itself records that the reason for it disappeared. This is where the exception problem and the AI question turn out to be the same question.
If a system can investigate every data movement rather than sampling whatever a rule happens to catch, exceptions stop being a capacity decision. At Jazz we built Melody, our agentic investigator, to examine what the data is, who moved it, which systems were involved, and whether the movement fits the way that person actually works. In a typical deployment that means something like two million signals reduced to around eighty cases a person needs to see. The activity that did not surface was still examined.
An assistant that summarizes cases already selected for review cannot recover activity that was excluded upstream. Adding AI to the queue makes the queue easier to work through, which is worth something, though it leaves the coverage question sitting where it was.
Understanding the work also gives you better options than blocking. The finance team keeps uploading to the vendor portal while a sensitive file heading to a personal account gets stopped, and where the intent is unclear you can ask the employee, who usually knows something the software does not. Company policy still decides what is acceptable. Business context is what lets you apply that policy to one action instead of interrupting an entire workflow. Automation still needs scrutiny.
The cases an AI system dismisses are part of its judgment. A confident explanation can rest on a wrong assumption about the file, the recipient or the person's purpose, and you should be able to trace any conclusion back to the activity and the policy behind it. Human judgment still matters when the evidence is thin or the consequences are serious. When the reasoning cannot be checked, a bad call gets harder to find, because it never reaches anyone.
Old compromises can survive a better system. Companies inherit years of exclusions written by an overloaded team, and nobody revisits them, because everyday work got easier once they were in place. A real part of the return on a better system is going back through those exclusions and recovering protection the company already gave up.
Most security leaders cannot tell you whether their system got quieter because the data is understood or because it stopped being watched. That is the question I would want answered before renewing anything.
Ido Livneh is the CEO and co-founder at Jazz.














