3 min read

Cybersecurity costs companies millions of dollars. It is a challenge that grows increasingly complex in the age of AI and will be even more so with the advent of quantum computing.

Data is often shared and no longer stays within an organization’s own network boundaries.

To address this, Attribute-Based Encryption (ABE) offers data-centric encryption, access control, and post-quantum security readiness.

An innovative example is SaltGrain, the industry’s first sovereign data platform powered by ABE, developed through NTT Research’s incubator Scale Academy.

Addressing Complex Cybersecurity Challenges

Cybersecurity is about keeping control of information.
 
It is a massive challenge that costs companies millions of dollars. The global average data-breach cost was an estimated US$4.44 million per incident in 2024, according to research by IBM and Ponemon Institute[1]. In the U.S., the average was even higher, at US$10.22 million[2].
 
Many organizations rely on a cybersecurity framework called zero trust architecture (ZTA). ZTA is based on the continuous verification of users, devices, applications and workloads, rather than automatically assuming that anyone already inside the organization’s network must be trustworthy.  
 
But the challenge has become more complex. AI interacts with sensitive data. Soon quantum computing will enable powerful decryption capabilities. Even now data moves beyond network boundaries and existing security tools can fail. What’s needed are data-centric controls that protect sensitive information even after it leaves the environment where access was granted.
 
Attribute-Based Encryption (ABE) offers a solution that includes data-centric encryption, access control and post-quantum security readiness.

How Attribute-Based Encryption (ABE) Works

In most organizations, data moves around and is accessed by different applications and individuals. That leaves it open to risk of attack.

With ABE, security travels with the data. It embeds access controls directly into the data layer, and it doesn’t rely on perimeter defenses like conventional security models. So, no matter where the data is located, even if it’s outside organizational boundaries, it is protected and remains sovereign to the original owner.

ABE also controls access to sensitive portions of data. Users only get access to the part of the document they are authorized to see, and not the whole file. That way, an attacker can’t view, alter or use the data, even if they are able to access it. Data is decrypted only when user attributes match defined security policies.

The benefits of this fine‑grained, role‑ and context‑based access control include a reduced risk of unauthorized access or data leakage, as well as encryption and protection throughout the data lifecycle. It also readies businesses for the additional security risks that come with an increasing use of AI and the post-quantum era.

How ABE Prepares Organizations for the Future of Cybersecurity

All systems are vulnerable to attack, including from within. The risk is even greater in the age of AI when sensitive data is accessed by systems and autonomous agents.

Agentic AI expands rapidly and will be widespread in the near future. ABE gives AI agents access to documents they need but closes off access to any portions they aren’t allowed to use or view. This is done at the data layer to ensure access policies are enforced throughout the process. Encryption follows the data wherever it goes, protecting it from hackers inside or outside the network.

But AI isn’t the only concern. Quantum computing is in development and is expected to be available for widespread use starting as soon as 2030. Hackers today hold encrypted sensitive data with the goal of decrypting it once quantum computing becomes available, believing it can break through today’s levels of encryption. ABE addresses this with post-quantum resistance.

The level of protection provided by ABE is especially critical for organizations managing high-value or regulated data, such as financial services, healthcare and technology. They need to collaborate on and share data but cannot risk a breach that could cost them millions of dollars.

ABE in Action: SaltGrain from NTT Research

An example of ABE implementation is SaltGrain, the industry’s first sovereign data platform using ABE to bind access policies directly to encrypted data. SaltGrain is also the first commercial business from NTT Research’s incubator Scale Academy.

Bennett Indart, NTT Research SVP Business Incubation, who leads Scale Academy, explains “Business start-ups have their own rhythms and incentives that quarterly metrics miss. Scale Academy accommodates those realities, with SaltGrain providing a timely entrance amidst AI risk acceleration, gaps in network and identity controls and the growing need to protect data wherever it moves.”

New Controls for Next-Generation Data Security Threats

AI and quantum computing are changing how cyber attackers are operating and changing the risks for organizations. Using ABE, security now moves with the data and offers a layer of protection against these new threats, fine-tuning access for AI agents, and supporting post-quantum cryptographic deployment. In an era when cybersecurity costs companies millions of dollars, ABE has the potential to reduce those costs and keep information safe.

[1] https://webobjects2.cdw.com/is/content/CDW/cdw/on-domain-cdw/brands/ibm/cost-of-a-data-breach-2025-full-report.pdf?enkwrd=samsung
[2] https://webobjects2.cdw.com/is/content/CDW/cdw/on-domain-cdw/brands/ibm/cost-of-a-data-breach-2025-full-report.pdf?enkwrd=samsung