Sleeping data, living risks: Protecting what your organisation stores in the dark

The 2nd Data Privacy and Protection Summit 2026, organised by CICRA and the Daily FT, concluded recently at the Oak Room, Cinnamon Grand Colombo, drawing over 380 senior professionals from data protection, governance, compliance, and cybersecurity sectors. The landmark event, supported by Mastercard as Title Partner, Concentric AI as Strategic Partner (in partnership with Orin Corporation), People›s Bank as Exclusive Banking Partner, and LankaPay as Silver Partner, provided a critical platform for understanding how AI enablement is transforming both the threat landscape and defensive capabilities.

In a powerful keynote address titled «Sleeping Data, Living Risks: Protecting What Your Organisation Stores in the Dark,» Mastercard Sri Lanka Country Manager Mahesha Amarasuriya, delivered a stark warning to organisations, urging them to confront hidden risks lurking within their own data archives.

Drawing a parallel to homeowners focusing on front doors while neglecting broken back entrances, Mahesha illustrated how organisations are failing to secure «dark data» information stored but no longer actively managed, understood, or used. She cited that nearly 60% of data breaches involve information stored in systems that organisations have forgotten or deprioritised.

«The rules of the game have changed with the rapid adoption of AI,» Mahesha stated. «While AI drives productivity, it is also being used by attackers to identify weaknesses faster. We are not just talking about protecting systems, but discovering risks before attackers discover them.»

To underscore the threat, Mahesha referenced the infamous Marriott International breach, where the acquisition of Starwood Hotels led to the compromise of 383 million guest records, costing over $50 million. «Data does not age like fine wine; it ages like dynamite,» she cautioned.

Mastercard Sri Lanka Director of Account Management Shashi Madanayaka, built on this theme, unveiling alarming findings from Mastercard›s Asia Pacific research. The estimated card-not-present fraud losses have surged to $ 49 billion a staggering 149% jump from 2025.

«The numbers are not just statistics, they represent a clear and present danger to every organisation that holds data,» Shashi told the packed audience. «The final impact of a data breach is threefold: financial impact, reputation impact, and operational impact. No organisation can afford to ignore any of these dimensions.»

Shashi emphasised that 75% of consumers say they will not deal with an organisation that has suffered a data breach, noting that the global average cost of a data breach in 2024 stood at USD 4.8 million.

Drawing on Mastercard›s insights specific to Sri Lanka, Shashi outlined the most common attack methods targeting organisations: Malware, Email phishing, Ransomware, and Reconnaissance. He identified primary asset targets as customer financial data, intellectual property, business systems, and customer personally identifiable information (PII).

Perhaps most striking was Madanayake›s revelation that seven out of ten cyberattacks are targeting the technology, financial, and government sectors. ‘These are the pillars of our digital economy,’ he said. ‘When they are under siege, the entire ecosystem is at risk.’

A dynamic panel discussion brought together leaders from across the financial and technology sectors. Moderated by Daily FT Editor/CEO Nisthar Cassim, the panel featured Mahesha Amarasuriya, Shashi Madanayaka, LankaPay CEO Channa De Silva, and People›s Bank

Chief Manager of Data Protection Unit/Data Protection Officer Saranga Sri Wimukthi.

The discussion explored practical challenges of identifying and securing sleeping data, particularly in the context of Sri Lanka›s imminent PDPA enforcement set for 1 January 2027.

Channa De Silva highlighted the scale of the challenge as digital payments expand across the country: «Our national payment infrastructure is enabling real-time, secure, and inclusive transactions. But with that comes an enormous responsibility to protect the data that flows through these systems. The sleeping data problem is amplified in a connected ecosystem where data traverses multiple entities.»

Saranga Sri Wimukthi shared People’s Bank’s proactive approach to data governance: ‘At People’s Bank, we process vast amounts of sensitive personal and financial information across our extensive network. Data protection is not merely a regulatory requirement, it is the bedrock of customer confidence and operational integrity.’

She highlighted the practical challenges: «Do we know what data we hold? Do we know where it is stored? Who has access to it? How is it being used? What risks does it create? With AI, we can now understand context, meaning, and relationships. That changes everything.»

The panel emphasised that public trust will ultimately determine the success of digital transformation. «If customers do not trust that their data is being protected, they will not embrace digital services,» the panel stressed. «Organisations must treat data protection as a strategic priority, not just an IT function. The tone must be set from the top.»

Shashi Madanayaka added that AI-driven solutions can help organisations achieve this balance: «AI-powered security can autonomously discover and classify sensitive business data across cloud and on-premises environments. It can reduce data security threat surfaces and provide actionable strategies to build a resilient, PDPA-ready compliance framework.»

Channa De Silva concurred, noting that collaboration across the financial ecosystem is essential: «Data protection is a shared responsibility. Both Government institutions and private sector organisations have a role to play in protecting citizen and customer data.»

The session concluded with a powerful consensus: sleeping data represents one of the greatest risks facing organisations today, but it is a risk that can be managed. By leveraging AI driven solutions to discover, classify, and protect unstructured and forgotten data, organisations can transform this vulnerability into a strength.

With the PDPA enforcement date approaching, the summit served as a critical call to action for Sri Lankan organisations to prioritise data protection, embrace AI powered security solutions, and build the governance structures necessary to thrive in an increasingly digital economy.

Cinnamon Grand was the Hospitality Partner and MullenLowe was the Brand Communications Partner of the 2026 Data Protection and Privacy Summit.

Leave a Reply

Your email address will not be published. Required fields are marked *