TL;DR: Splitting DLP, DSPM, insider risk, and AI security into separate tools leaves teams with weak context, slower response, and fragmented enforcement across endpoints, SaaS, cloud, and on-prem systems, according to Cyberhaven. The practical lesson is that discovery only reduces risk when it feeds continuous, identity-aware enforcement.
At a glance
What this is: This is an analysis of how fragmented data security tooling leaves visibility and enforcement disconnected, and why discovery-only approaches fail to reduce risk.
Why it matters: It matters to IAM practitioners because data movement, user context, and AI usage now intersect with identity decisions, access control, and enforcement across the full data lifecycle.
👉 Read Cyberhaven's analysis of unified DSPM and DLP enforcement
Context
Data security breaks down when discovery, enforcement, and behavioural context live in separate tools. That split makes it harder to answer basic questions about where sensitive data sits, who is using it, and whether access or movement is expected. For IAM and security teams, the real issue is not just data visibility. It is the governance gap between identity context and enforcement across endpoints, SaaS, cloud, and AI workflows.
In that model, DSPM without enforcement becomes an inventory exercise, while DLP without discovery becomes a control with poor context. The article describes a platform approach, but the underlying governance problem is broader than any one vendor: security teams need a coherent view of data at rest, in motion, and in use, tied to the identities and systems handling it.
Key questions
Q: How should security teams combine DSPM and DLP in modern data environments?
A: Use DSPM to discover and classify sensitive data, map who can access it, and identify exposure that policy may not see. Use DLP to enforce rules at the point of movement. The strongest programmes connect the two so discovery informs control decisions and enforcement feeds back into prioritisation.
Q: Why do identity signals matter in data security policy decisions?
A: Identity signals help distinguish legitimate business use from suspicious movement, especially across SaaS, cloud, endpoints, and AI tools. A policy that ignores user, workload, or service identity will either overreact or miss abuse. The more dynamic the environment, the more policy needs identity context to stay accurate.
Q: What do teams get wrong when they separate AI security from data security?
A: They assume AI is a standalone risk when in practice it is another path for data movement and reuse. If prompts, outputs, and embedded content are not governed under the same policy model as other workflows, sensitive information can leak through ordinary user activity rather than obvious malicious behaviour.
Q: How can organisations tell whether their data security programme is actually improving?
A: Look for fewer unknown data stores, clearer ownership of sensitive datasets, faster access review completion, and measurable reductions in overexposed information. If the same high-risk data keeps appearing in audits or incidents, the programme is producing activity without control.
Technical breakdown
Why discovery-only DSPM leaves an enforcement gap
DSPM is designed to locate sensitive data, classify it, and map where it resides across cloud, SaaS, endpoints, and on-prem systems. That gives teams posture visibility, but not necessarily the power to stop risky movement or misuse. The weak point is operational handoff: if discovery results do not flow into policy enforcement, teams know where the data is but not what to do next. This is where fragmented tooling creates delay, duplicated triage, and inconsistent decisions.
Practical implication: connect discovery findings to enforceable policies, not just dashboards.
How DLP depends on identity and data context
DLP works best when it can evaluate who is accessing data, from where, and in what workflow. Without identity context, DLP tends to over-block legitimate work or under-block high-risk activity. That is especially true in SaaS and AI-assisted workflows, where the same content may move across multiple environments in minutes. The control challenge is to distinguish expected use from anomalous use using signals such as user identity, data sensitivity, location, and process lineage.
Practical implication: tune DLP decisions using identity, lineage, and usage context.
Why AI data workflows need unified data governance
AI tools increase the surface area for sensitive data handling because prompts, outputs, and embedded content can all become new paths for exposure. If AI security sits outside data security, teams lose visibility into how sensitive information is consumed, transformed, and reused. A unified model treats AI usage as part of the same governance chain as cloud, endpoint, and SaaS activity, which is more realistic than managing it as a separate category.
Practical implication: extend data policy coverage into AI-assisted workflows before shadow usage expands.
Threat narrative
Attacker objective: The objective is to move or misuse sensitive data while fragmented controls prevent timely detection and consistent enforcement.
- Entry begins when sensitive data is spread across endpoints, SaaS applications, cloud services, and AI tools without a single control plane for discovery and enforcement.
- Escalation occurs when teams cannot reliably correlate identity, data lineage, and usage context, allowing risky access or exfiltration to go undetected or unresolved.
- Impact is delayed detection, inconsistent policy enforcement, and higher exposure of sensitive data across human and AI workflows.
NHI Mgmt Group analysis
Discovery without enforcement is governance theatre. Security teams do not reduce risk by knowing where sensitive data lives if they cannot act on that knowledge in the same workflow. Fragmentation between DSPM and DLP creates a control gap where posture insights never become policy outcomes. For practitioners, the lesson is that visibility must be operationalised or it will only describe the breach path after the fact.
Data security now has an identity problem. The article rightly points to the need to connect data location, sensitivity, and usage, but the more important governance issue is identity context. In modern environments, access decisions are made by humans, service accounts, and AI-enabled workflows, all of which can move data quickly across systems. That makes identity-aware enforcement a prerequisite, not an optional enhancement.
AI misuse belongs inside the same data security model as SaaS and endpoint risk. Treating AI as a separate security category encourages blind spots around prompts, outputs, and copied sensitive content. The better approach is to govern AI usage as part of the broader data lifecycle, with the same expectations for classification, monitoring, and enforcement. AI data governance gap: when AI tools are handled outside data security workflows, sensitive information can move faster than controls can respond. Practitioners should fold AI usage into the same operational model as the rest of the data estate.
The market is converging on control-plane consolidation, not just feature overlap. Buyers are no longer evaluating discovery and enforcement as separate outcomes. They are looking for a single operating model that reduces manual correlation and shortens investigation time. That signals a broader shift toward integrated governance architecture, where data security, identity context, and workflow enforcement are expected to operate together.
For identity programmes, the real test is whether data policy can follow the user or workload. If enforcement still depends on separate teams stitching together context, the programme will remain slower than the risk it is meant to manage. The practical conclusion is that identity governance, data security, and AI oversight need shared signals and shared escalation paths.
What this signals
Data security programmes are moving toward a single control plane because teams can no longer afford to discover risk in one tool and act in another. That same pressure is visible in identity and NHI governance, where fragmented visibility usually becomes fragmented accountability.
Context-to-control gap: when identity, data lineage, and policy enforcement are separated, the organisation gets reports instead of decisions. Practitioners should expect more demand for shared signals across IAM, DLP, and AI governance, especially where data moves through cloud and SaaS workflows.
The governance signal is clear: if an analyst can see the risk but not trigger the response, the control stack is incomplete. For identity teams, that means access context, entitlement context, and data sensitivity must be reviewed together, not in parallel queues.
For practitioners
- Unify discovery and enforcement workflows Map where DSPM findings currently stop and where DLP or other enforcement actions begin. Eliminate manual handoffs for high-risk data classes so classification results can trigger policy actions in the same workflow.
- Add identity context to data policy decisions Require user identity, workload identity, data lineage, and location to be part of every high-risk data decision. This reduces false positives and makes policy exceptions easier to justify and audit.
- Extend controls into AI-assisted workflows Treat prompts, outputs, and copied source content as governed data paths. Apply the same classification and monitoring logic to AI tools that you already use for SaaS and endpoint activity.
- Reduce operational drift between teams Create a shared escalation model so data security, IAM, and AI governance teams work from the same risk signal set. That prevents tribal knowledge from becoming the only place where context lives.
Key takeaways
- Fragmented DSPM and DLP tooling creates a governance gap because discovery only helps when it triggers enforcement.
- Identity context is becoming central to data security decisions as data moves across endpoints, SaaS, cloud, and AI workflows.
- Practitioners should measure whether risk findings turn into controls quickly enough to matter, not just whether they are visible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Unified enforcement depends on access decisions that reflect identity and data context. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central when data access must follow user and workload context. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Identity-aware data workflows often depend on service accounts and secrets that need lifecycle control. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance is relevant where data handling spans multiple platforms and teams. |
Use AC-6 to constrain who can access sensitive data and review exceptions where workflows span multiple tools.
Key terms
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.
- Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
- Identity-Aware Enforcement: Identity-aware enforcement is policy decisioning that uses who the user is and which account or context they are using. For browser AI, it helps distinguish sanctioned corporate use from unmanaged personal sessions and applies different controls based on that distinction.
What's in the full article
Cyberhaven's full post covers the operational detail this post intentionally leaves for the source:
- How the platform maps data lineage across cloud, SaaS, endpoints, and on-prem environments
- The specific workflow that connects discovery findings to enforcement actions
- How the redesigned UI reduces investigation time by correlating sensitivity, location, and user behavior
- Why the vendor argues that AI classification should sit alongside data governance rather than beside it
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to the broader security programmes they run.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org