Learn more
Case study

How BioIVT Builds AI Readiness Into Its Data Security Program

In the field

BioIVT

BioIVT needed full visibility into sensitive data across a complex environment, especially as AI adoption accelerated inside the business. Cyberhaven delivered the lineage, classification, and context to make that possible.

BioIVT Overview

BioIVT is a global provider of high-quality biological specimens and value-added research services that support life science and diagnostic companies around the world. The company specializes in sourcing and preparing human and animal tissues, cell products, blood, and other biofluids to help researchers better understand disease processes and advance therapeutic development.

With an unmatched portfolio of clinical specimens and a focus on precision medicine research, BioIVT collaborates with scientists and pharmaceutical partners to enable smarter science and accelerate medical breakthroughs. This commitment to supporting critical research extends into how BioIVT approaches internal priorities such as protecting its sensitive scientific and operational data, particularly as the organization brings more AI models into production.

Challenges

01

The security team lacked a unified view of sensitive data across the organization, making it difficult to quickly assess risk, investigate incidents, and demonstrate compliance with confidence.

02

Without a clear way to see how data was classified, where it originated, and how it flowed between systems, understanding the true sensitivity of the environment was not possible.

03

With multiple AI models already in production and others in development, the organization needed a clear understanding of its data before those models were trained or deployed, before it became too late to act.

04

New frameworks including NIST 2.0, HIPAA 2.0, and the EU AI Act are all focused on governance and transparency in how data moves, especially before an organization turns on AI models.

Ready before AI

Overview

Cyberhaven gave BioIVT a unified way to understand its data by bringing lineage, context, and visibility together in a single platform. Rather than relying on fragmented views across systems, the security team gained the ability to see how sensitive data originated, moved, and changed over time, and to get ahead of that data before it ever reached an AI model.

“BioIVT's AI future is really already here. We already have multiple models in place for user assistance, and a couple in place for sales functions or activities that are automated. We have multiple models on the radar for different internal initiatives and feasibility functions. Some are already in production.”

Chad Pallett
Acting CISO, BioIVT
The challenge at hand

Challenge and Impact

As a global life sciences company, BioIVT operates in a highly regulated environment where large volumes of sensitive data are central to daily operations. The organization manages personal patient data, proprietary business information, and other sensitive assets while meeting strict regulatory and audit requirements across regions.

For Acting Chief Information Security Officer Chad Pallett, managing that responsibility starts with visibility, and with cutting through the noise of too many disconnected tools.

"My job really is to help bring awareness of what's happening in the real world on a day to day basis. That means understanding what data we have, where it's moving, and the risks associated with it."

— Chad Pallett, Acting CISO, BioIVT

"As a CISO, the main focus is awareness of solutions and the sprawl of the different solutions in our tool belt. The more we can consolidate to fewer solutions working in a fluid, integrated method, the more powerful we can be, without digging through the millions of signals we get from these different systems."

— Chad Pallett, Acting CISO, BioIVT

While BioIVT had insight into individual systems, the security team lacked a unified view of sensitive data across the organization. Without a clear way to see how data was classified, where it originated, and how it flowed between systems, it became more difficult to quickly assess risk, investigate incidents, and demonstrate compliance with confidence.

That challenge grew more urgent as BioIVT expanded its use of AI, and as pressure to move fast came from the top of the organization.

"At the board and executive level, AI is all the conversation is about. I've heard my CIO bring back the response that when we told the board we have two models in motion in production, they were giddy. That is really the energy in so many environments. The pressure from the board and executive teams is to move forward, to jump in, dive in, make us some money with these models."

— Chad Pallett, Acting CISO, BioIVT

That pressure to move fast made it more important, not less, to understand the data behind each model before it launched.

"My desire and drive to get ahead of any and all data modeling and identifying classification elements and opportunities is so critical, because it's almost too late in some cases once the models are already turned on."

— Chad Pallett, Acting CISO, BioIVT

For Pallett, that urgency reflects a broader shift in what the role of a CISO has become.

"That's so much of what, as security leaders, we're realizing. Two parts of the 'new CISO': one, that we're driving with governance and risk now, not just checking boxes, saying here's the solution we need to buy to say we're checking this type of box."

— Chad Pallett, Acting CISO, BioIVT

Method

Solution

Security Made Seamless, Even as AI Scales

Seamless deployment

Implementing DSPM required minimal new effort. As an existing Cyberhaven customer, BioIVT expanded visibility largely by refreshing what was already in place.

"In the past we were connected to Microsoft 365, watching SharePoint. So this was really a matter of refreshing some permissions, re-updating a couple connector logins to let it reconnect to those SaaS solutions. And then sitting back and watching Cyberhaven do its magic, taking the data that was already there and adding the ability to contextualize and classify at a very impressive rate."

— Chad Pallett, Acting CISO, BioIVT

One pane of glass across every SaaS surface

That same visibility now extends well beyond email and file storage. With Cyberhaven, Pallett can trace a piece of data back to the system it lives in and bring the right people in before it becomes a problem.

"What I love is being able to quickly look now and see, okay, if it's this type of data, where is it coming from? Oh, it's in Salesforce. It's in 365 email, it's in SharePoint. It gives me a very easy opportunity to go work with the appropriate verticals and business leaders to protect and verify how that data is being used, or, if it doesn't have a policy around it, to implement one before we find ourselves in a position where that data becomes exposed."

— Chad Pallett, Acting CISO, BioIVT

"With the additional options now of being able to see third-party and other SaaS solutions like Salesforce and GitHub in that same pane of glass, it really gives me comfort when I'm relaying to executives and business units where our data really is and where our risks really are."

— Chad Pallett, Acting CISO, BioIVT

Full data lineage history

That lineage and context proved critical during investigations.

"One of the many things I love about Cyberhaven is the ability to track the lineage and bring that whole history. It's been life saving on many occasions, unfortunately more this year than I'd like to have seen, but that's the beauty of having transparency and the ability to see what people are doing."

— Chad Pallett, Acting CISO, BioIVT

Rationalize the noise with DSPM

Cyberhaven's DSPM capabilities help BioIVT make sense of data across systems in a single view, rather than piecing together signals from separate tools.

"DSPM is key in the ability to rationalize all the different elements of what's happening with your day to day information behind the scenes. A lot of people have visibility into maybe some portions of it, but not all the signals, or better yet, a single pane, a way to really track the lineage of where the true sensitivity of their day-to-day business is."

— Chad Pallett, Acting CISO, BioIVT

Uncover classifications you didn't know to look for

That visibility is now feeding directly into a broader overhaul of how BioIVT classifies data.

"We're actually in the process of overhauling our data classification policies, building some very clean roles, responsibilities, and use allowances. This really helped bring information to the table that I didn't have at my hands, and was able to quickly show me a lot more ways we could classify data that I didn't even consider."

— Chad Pallett, Acting CISO, BioIVT

Get ahead of AI models before they launch

For Pallett, the real value of DSPM is proactive, not reactive: understanding data before it feeds an AI model, not after.

"Prepping and preparing that data before you turn on these AI models, I think that's one of the largest things I appreciate: the ability to proactively get ahead of these as we release models and encourage AI use. We've had a great opportunity to use the system to help expose and identify multiple elements we can protect along the way."

— Chad Pallett, Acting CISO, BioIVT

Tie remediation to lineage, not just alerts

That understanding translates directly into action.

"One of the many advantages the DSPM options bring is the ability to now join the remediation efforts and actions along with the lineage and elements you're exposing."

— Chad Pallett, Acting CISO, BioIVT

A depth of visibility Pallett hasn't found elsewhere

For Pallett, the differentiator comes down to lineage, and how far back it reaches.

"I still have yet to ever see anybody that can perform and bring that level of visibility, especially from a historic perspective. If you're in any level of regulatory environment, having that contextual, even down to screenshots, for however many years you have it captured, is just unheard of, and a power that is critical to all cybersecurity programs."

— Chad Pallett, Acting CISO, BioIVT

"There are so many systems that may have tremendous abilities, again, none that I've seen that can do lineage yet, but even those other systems, you're still playing whack-a-mole. You're reactive. You don't have the whole solution playing together."

— Chad Pallett, Acting CISO, BioIVT

The Vision

Looking Ahead

As BioIVT continues to expand its use of AI, having strong data governance and preparedness remains a critical focus. With multiple AI initiatives in motion, the organization needs confidence that sensitive data is identified, understood, and protected before it is introduced into AI systems.

"The provenance that Cyberhaven provides is critical to building your data program for AI, or for any cybersecurity measures."

— Chad Pallett, Acting CISO, BioIVT

That same foundation extends to compliance work well beyond AI readiness.

"This is a powerful tool that lets them check a lot of boxes and achieve a lot more than they may have considered with one security solution, especially companies under CMMC compliance or new environments that require that need but don't have the resources or expertise."

— Chad Pallett, Acting CISO, BioIVT

As AI adoption accelerates across the business, Pallett sees the security team's role shifting from a gatekeeper to a partner in how the company builds with AI.

"It's kind of that same thing now with the AI engines. You know, consider what you're putting in there, because once it's out there, it's out there. We need to make sure we're building models, solutions, and opportunities for our companies to use AI, but with that mindset, at the top of focus: what data do we want where, how do we want to protect it?"

— Chad Pallett, Acting CISO, BioIVT

Preparing for evolving data risks

Conclusion

For BioIVT, protecting sensitive data and supporting the organization's mission depend on having clear visibility into how data is created, used, and moved across the environment, including the data behind every AI model in production. Cyberhaven has become a foundational part of building that understanding and advancing a more mature data security program.

"Cyberhaven has been critical in our ability to build a mature cybersecurity program and to bring the visibility to the other team members that is needed."

— Chad Pallett, Acting CISO, BioIVT

"We live and breathe with the visibility Cyberhaven brings to the security team on a day-to-day basis. I couldn't give it a higher platinum rating if there was one."

— Chad Pallett, Acting CISO, BioIVT

For organizations looking to gain a clearer picture of their data and associated risk, Pallett's advice is straightforward.

"Try it out and take off the blindfold for a couple days. See what's really happening in your environment. You won't be disappointed."

— Chad Pallett, Acting CISO, BioIVT