ChannelLife Australia - Industry insider news for technology resellers
Secure cloud with digital shields interconnected data streams hybrid ai

CrowdStrike unveils Falcon Data Protection for GenAI security

Fri, 19th Sep 2025

CrowdStrike has announced new developments in its Falcon Data Protection product, focusing on addressing data protection challenges associated with generative AI and hybrid cloud environments.

GenAI challenges

Generative AI (GenAI) tools have transformed business processes by accessing and transferring data across local endpoints, cloud systems, and SaaS applications. The rapid adoption of these tools has exposed limitations in existing security solutions, particularly those designed to protect data at rest or in easily monitored conditions.

Many organisations have found that conventional data loss prevention (DLP) and data security posture management (DSPM) tools struggle to secure data in environments where information is constantly moving and evolving. These tools often stop at browser boundaries, rely on network overlays, or can be circumvented by encryption, leaving potential vulnerabilities in both local applications and cloud-based services.

Unified coverage

"AI has reshaped how data is created and shared, but legacy data loss prevention and posture management tools weren't built to secure data in the modern era," said Elia Zaitsev, Chief Technology Officer at CrowdStrike. "Falcon Data Protection follows sensitive data everywhere it moves, across devices, cloud services, SaaS applications, and GenAI workflows. By delivering the real-time visibility and enforcement customers need, we're making it easier to consolidate cybersecurity at scale and securely innovate with AI."

CrowdStrike's Falcon Data Protection is designed to provide coverage across both managed and unmanaged GenAI tools, extending protections beyond the browser and into local and runtime cloud environments. It offers real-time prevention against inadvertent data exposure and can block data leakage as it occurs, regardless of where the data is being transferred or accessed.

Consolidating legacy tools

According to CrowdStrike, legacy DLP and DSPM offerings remain fragmented. DLP was built with static endpoints in mind, while DSPM generally provides insights based on cloud environment snapshots. These approaches may not keep pace with how GenAI interacts with data or with the continuous movement of information across hybrid systems.

Falcon Data Protection seeks to address this by enabling unified visibility and enforcement. Key features of the latest release include real-time protection for sensitive data exceeded beyond browsers, the ability to block data leakage in both managed and unmanaged GenAI tools, and the prevention of data exposure in local application usage as well as runtime cloud activity.

Detection and visibility

The new Falcon Exposure Management AI Discovery function detects large language models (LLMs), AI applications, and agents operating on managed endpoints. This capability aims to eliminate blind spots created by shadow AI tools, which could otherwise expose confidential information.

Combined with enhanced cloud AI discovery and Falcon Data Protection controls, the platform offers centralised visibility and security oversight across increasingly complex hybrid environments.

Classification and insider threats

CrowdStrike has also introduced AI-powered data classification tools within Falcon Data Protection. These employ large language models to identify sensitive data types such as credentials, secrets, and passwords. The aim is to reduce false positives and improve enforcement of data protection policies.

A unified insider threat dashboard brings together signals such as identity, HR data, and data movement to help organisations detect and respond to insider activity - whether it is malicious, negligent, or results from compromised accounts. The platform's unified detections and cross-domain visibility are said to increase the detection coverage for issues like data loss, GenAI misuse, and insider threats by a factor of ten compared to previous offerings.

Movement towards consolidation

With growing use of AI and increasingly mobile data, many organisations are looking to consolidate cybersecurity tools to reduce complexity and improve response times. Falcon Data Protection's real-time enforcement and broad coverage are aimed at supporting this transition from fragmented point solutions to unified security architectures.