// Inside the mIssion

The Urgent Need for Confidential Computing

As cloud environments grow and AI systems take charge, protecting data in use becomes critical to any organization’s security.

By: Dave Dimlich
President of SD3IT

For years, people talking about data security tended to focus on two things: data at rest and data in transit. By first encrypting the data sitting in a database, file system or storage device, and then encrypting the connections used to send that data across a network, you were in pretty good shape.

Those two practices are still essential, but security leaders can no longer ignore the third leg of the secure-data stool: data in use.

With ever more workloads moving into cloud and edge environments, and artificial intelligence increasing the amount of data being processed at any given time, securing data that’s being processed is becoming a huge security concern.

Consider, for example, an agentic AI system analyzing a sensitive dataset. The information it’s working with must be available to the application or model and must be loaded into memory, processed and potentially combined with other information before the AI system can answer a query or perform a function. Traditional encryption doesn’t necessarily protect the data during that computation, so for the time it’s being processed, that data is exposed.

That’s why organizations are increasingly emphasizing the importance of confidential computing, which is beginning to catch on as a way to protect data while it’s actively being used, providing it with the protections that have traditionally been applied to data at rest and data in transit. The National Institute of Standards and Technology (NIST) describes confidential computing as a means of extending encryption protection to data while it is being processed, including data used by AI workloads in cloud environments.

It doesn’t replace the encryption of data at rest or in transit, but provides the missing piece in the security chain, supplying security at a stage that is becoming increasingly risky.

AI Increases the Urgency

Exploiting data being processed isn’t entirely new, as high-profile breaches over the past decade have made clear. First American Financial Corporation, for example, leaked 885 million financial records in 2019 because a web application let users make changes in active URL strings and view active processing files. In 2017, Equifax exposed sensitive data on nearly 150 million people when malicious actors exploited an unpatched vulnerability in a framework for active web-form data processing.

Those attacks might seem ancient in a world of constant cloud and AI enhancements, but the explosion of processing that has accompanied the use of AI, particularly agentic AI, has expanded the attack surface and raised the stakes. The Confidential Computing Consortium notes that as much as 87% of organizations have inadequate protections against outside threats, 44% are merging sensitive datasets for AI without the in-use encryption and 83% are exposed to inside threats, whether malicious or inadvertent, for example when proprietary models and training data are held in unprotected memory.

The risks become more significant as AI takes on larger and more complicated workloads. Even when you’re not looking, an AI system could be accessing and working with a smorgasbord of sensitive data, including proprietary information, personally identifiable information (PII), financial records, operational data, intellectual property or sensitive government information. An agentic AI system can retrieve information, call other applications, access databases, use tools and carry information from one step of a process into another.

The upshot is that more sensitive information is being processed, often with minimal or no direct human oversight, giving attackers ample opportunities to exploit vulnerabilities in applications, APIs, credentials, memory, configurations or other components involved in active processing. Organizations need more than encrypted databases and strong data transport protocols. They need to protect data in use, which is where confidential computing comes into the picture.

Processing Data Inside a Trusted Environment

The basic idea behind confidential computing is pretty straightforward. Sensitive workloads run inside a hardware-based trusted execution environment (TEE), which creates an isolated area where the workload and its data can be protected.

The important distinction is that the protection is rooted in hardware rather than the operating system, hypervisor or surrounding software stack. The processor separates routine and sensitive tasks, and the RAM is encrypted from within the CPU. Another important capability is remote attestation, which provides cryptographic evidence that the proper hardware and software environment is being used. The process is particularly useful when sensitive workloads are running in environments that an organization does not completely control.

Confidential computing gives organizations the means to secure sensitive workloads and establish proof that everything has gone according to plan, helping to establish trust in the computing environment itself.

A sensitive AI workload moving to the cloud, for instance, can raise questions about who has access to the underlying infrastructure. And it is much more than an AI issue. With or without AI, organizations perform sensitive analytics and work with financial information, healthcare data and intellectual property, all of which require secure processing.

Another significant use case, common within many enterprises, would be collaborative workloads involving multiple organizations. Imagine two organizations working together on a project that involves sensitive information. In many settings, they can’t simply hand each other their underlying datasets, but a properly designed confidential computing environment can allow them to perform approved computations without requiring either party to expose all of its raw information. In that example, confidential computing not only protects the data they’re working with, but can create opportunities for further collaboration that otherwise may be considered too risky.

The same principle becomes relevant at the edge, where sensitive information can be processed in remote, distributed or operationally constrained environments.

Handling Confidential Computing’s Complexity

In the face of growing threats, the advantages of confidential computing have gotten the attention of business and IT leaders. A November 2025 study by IDC found that 75% of organizations were already using or piloting confidential computing, with 18% reporting production use and 57% actively piloting the technology.

But confidential computing is not a turnkey solution. A TEE-capable environment requires upgraded hardware and firmware, along with software modifications and other steps that, together, make it a complex implementation to manage. The NIST report, Confidential Computing of Data in Cloud Workloads, which focuses on hardware-enabled security, is one source outlining the steps organizations should take.

A key to implementing confidential computing is ensuring that all the components—including hardware, cloud infrastructure, identity, encryption, key management, workload security, data classification and access policies—work together, which is the focus of our work at SD3IT.

Our work with zero-trust and data-centric security, for example, focuses on protecting information based on its sensitivity and the circumstances under which it is being accessed. That becomes particularly important in distributed environments. Working with an array of partners, SD3IT helps federal and defense organizations, as well as commercial interests, to process information across cloud, edge and disconnected or contested environments.

Secure Processing Should Be the New Normal

As organizations expand use of cloud environments, the amount of data in use will grow exponentially, especially with the help of AI. For organizations to safely operate in this high-risk environment, confidential computing must become as prevalent a practice as protecting data at rest and in transit. Going forward, as NIST’s report states, “confidential computing will play a pivotal role in improving security and privacy in cloud environments.”

It addresses a question that we may not have always had to think about but which has become extremely urgent: How do we protect data that a computer is actually using? Confidential computing provides the answer, giving organizations a way to ensure that all data stays safe, even while it’s actively being processed.

About SD3IT

SD3IT (Solution Driven, Designed and Delivered Technology) helps government and commercial organizations modernize mission-critical IT through integrated infrastructure, cybersecurity, cloud and edge solutions. We work closely with leading technology partners to design, deploy and support secure, resilient environments that align with operational requirements, compliance mandates and long-term business objectives.

Skip to content