TL;DR: Cloud-stored data now appears in 82% of breaches and 39% span multiple environments, according to Cyera’s Data Security Architect’s Guide to Adopting DSPM. The implication is that visibility, misconfiguration control, and privilege reduction now matter more than perimeter assumptions, and DSPM only helps when it is tied to IAM and remediation workflows.
At a glance
What this is: This guide argues that cloud breaches now center on exposed data, misconfigurations, and excessive privileges rather than perimeter failure alone.
Why it matters: IAM, PAM, and NHI teams need to align data discovery and privilege reduction so DSPM findings turn into remediation instead of another visibility layer.
By the numbers:
- 82% of breaches now involve cloud-stored data.
- 39% of breaches span across multiple environments.
Context
Cloud data security posture management, or DSPM, is the practice of discovering where sensitive data lives, how it is exposed, and which access paths make it reachable. In this guide, Cyera frames DSPM as a response to cloud breach conditions where misconfigurations and excessive privileges outpace perimeter-centric controls.
The governance gap is not visibility alone. The operational problem is that organisations often see sensitive data after privilege has already been overextended or cloud settings have already drifted, so response arrives too late to prevent exposure.
That makes DSPM relevant to NHI, IAM, and PAM programmes at the same time, because data exposure, identity scope, and remediation workflows are now part of the same control plane.
Key questions
Q: What breaks when cloud data discovery is not tied to access cleanup?
A: Discovery alone only tells you where sensitive data exists. If entitlement cleanup does not follow, the same identities can keep reaching exposed data, so the organisation gains visibility without reducing breach likelihood. The failure is operational, not analytical, because findings never become enforced changes.
Q: Why do excessive privileges make cloud data breaches more likely?
A: Excessive privileges enlarge the number of identities that can touch sensitive data, which turns a single compromised account or token into broader exposure. That increases both insider risk and attacker payoff, especially when cloud storage and automation credentials share the same access surface.
Q: How do organisations know whether DSPM remediation is actually reducing risk?
A: They need evidence that exposure dropped and stayed down over time. Useful signals include reduced access paths, fewer exposed objects, fewer repeat findings, and successful validation after action. Closing a ticket alone is not proof. Effective programmes confirm that remediation changed the data condition, not just the workflow status.
Q: How should security teams use DSPM in an IAM programme?
A: Security teams should use DSPM as a source of identity-aware data context, not as a standalone reporting layer. The practical goal is to connect classified data to the identities that can reach it, then use that mapping to drive access reviews, least-privilege decisions, and exception handling. That is where data governance becomes operational.
Technical breakdown
How DSPM changes the cloud breach control model
DSPM shifts security from perimeter-centric assumptions to data-centric detection and response. Instead of asking only whether a network boundary held, it identifies where sensitive data is stored, who can reach it, and whether the access path is justified. In cloud environments, that matters because exposed storage, mis-scoped roles, and dormant entitlements often combine to create breach conditions faster than manual review can catch them. The practical result is that data classification, entitlement review, and control enforcement need to operate together rather than as separate projects.
Practical implication: tie data discovery outputs directly to entitlement cleanup and misconfiguration remediation.
Why excessive privileges turn data exposure into breach risk
Excessive privilege expands the number of identities that can reach sensitive datasets, which increases both accidental exposure and attacker opportunity. In cloud estates, that includes human users, service accounts, tokens, and workload credentials that may have more access than their business role requires. When those identities are over-scoped, compromise of any one of them can become a data event rather than a contained account issue. DSPM becomes useful here only when it shows which data sets are reachable through which identities, not just where the data sits.
Practical implication: map sensitive datasets to the identities that can access them and remove unused entitlements.
Where DSPM fits among DLP, IAM, and CSPM
DSPM does not replace DLP, IAM, or CSPM. It sits between them as the layer that connects sensitive data location, identity reach, and cloud configuration state. DLP focuses on preventing data movement, IAM governs identity and access decisions, and CSPM looks for misconfigurations in cloud services. DSPM adds the missing link by showing which data assets are exposed, which permissions make that exposure material, and which findings require remediation now rather than later.
Practical implication: use DSPM as the prioritisation layer that turns IAM and CSPM findings into ranked remediation work.
Threat narrative
Attacker objective: The objective is to reach sensitive cloud data through weak exposure controls and over-permissioned access paths.
- Entry begins when cloud storage, identity scope, or configuration drift exposes sensitive data beyond intended boundaries.
- Escalation occurs when excessive privileges let broader sets of users, service accounts, or tokens reach data that should have been tightly constrained.
- Impact follows when exposed cloud data is accessed, copied, or reused across environments, turning posture gaps into breach events.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
- DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
DSPM is becoming the data-layer control plane for cloud breach reduction. The old assumption that perimeter control could contain cloud risk no longer matches how breaches form across storage, identity, and configuration layers. When data exposure and privilege scope drift together, the meaningful control question becomes which data is reachable and by whom. Practitioners should treat DSPM as an operational prioritisation layer, not a reporting dashboard.
Excessive privilege is the governance failure that turns cloud visibility into breach exposure. Discovering data locations is useful, but it does not reduce risk if the identities that can reach that data remain over-scoped. This is where NHI, IAM, and PAM overlap: human accounts, service accounts, and tokens can all widen access in ways that outlive their original need. Practitioners need a single view of data reachability, not separate inventories for each control domain.
Misconfiguration plus over-permissioning creates identity blast radius: Cloud posture and access posture now interact as one problem. A storage setting that is merely noisy in one environment can become breach material when combined with broad entitlement scope in another. That interaction is exactly why DSPM belongs in remediation workflows, not just assessment cycles. Practitioners should connect posture findings to access cleanup and exception handling.
DSPM validates a control shift from perimeter assurance to exposure management. The article reflects a broader market move toward continuous, evidence-based prioritisation over static policy compliance. That shift does not reduce the need for IAM or CSPM, but it does re-rank them around actual data exposure. Practitioners should expect data security programmes to be judged more on reduced reachable exposure than on the volume of findings generated.
Cloud-breach governance now depends on remediation speed, not inventory completeness alone. A complete list of data stores is not enough if misconfigurations and excessive privileges remain open long enough to matter. The implication for identity teams is clear: access reduction and posture correction must be linked to the same workflow. Practitioners should measure how quickly exposure findings become enforced change.
From our research library:
- 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Read next: Cloud PAM and CIEM Guide
What this signals
Identity blast radius is now a data-security problem, not just an IAM problem. When cloud data is reachable through over-permissioned accounts or automation credentials, posture findings and access findings describe the same exposure path. That is why data security programmes have to be wired into entitlement cleanup, not left as a separate discovery layer.
DSPM works best when it changes decisions, not when it produces another inventory. The programme value is in closing the gap between finding sensitive data and removing the access paths that make it dangerous. In practice, that means exposure scoring should trigger remediation queues, exception review, and ownership assignment, not just reporting.
Misconfiguration control and privilege reduction now move together. A cloud setting that exposes data becomes materially worse when excessive privilege makes that data broadly reachable. Practitioners should measure the programme by how quickly reachable exposure falls after a finding is raised.
For practitioners
- Map sensitive data to reachable identities Build a control view that shows which human accounts, service accounts, tokens, and workloads can actually reach sensitive cloud data, then use that map to remove unnecessary access.
- Prioritise misconfiguration remediation by exposure depth Rank cloud findings by whether they expose regulated or sensitive data, then fix the settings that materially increase breach likelihood before low-impact hygiene issues.
- Link DSPM findings to access review workflows Send high-risk exposure findings into the same remediation path used for entitlement cleanup, so data risk and identity risk are closed together instead of in separate queues.
- Reduce standing privilege around cloud data stores Review persistent access to data platforms and storage layers, especially where service accounts or automation credentials have broad read permissions that no longer match their task scope.
Key takeaways
- Cloud breach reduction now depends on shrinking reachable sensitive data, not only on protecting the perimeter.
- The guide ties data exposure to over-permissioned access and cloud misconfiguration, which is why DSPM belongs in remediation workflows.
- IAM, PAM, and cloud posture teams need shared queues and ownership so exposure findings become enforced access change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CSA Cloud Controls Matrix and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | DSP — Data Security & Privacy | DSPM is directly about cloud data security and exposure control. |
| IAM — Identity and Access Management | The article ties data exposure to excessive privileges and access reach. | |
| Recommendation — Use DSP controls to discover sensitive data and prioritise remediation of exposed cloud assets. Apply IAM controls to reduce broad access paths to sensitive cloud data. | ||
| NIST CSF 2.0 | PR.DS-01 — Data-at-rest is protected | The guide centers on cloud-stored data exposure and protection posture. |
| PR.AA-05 — Access Permissions, Entitlements and Authorizations | Excessive privileges are a core risk in the article's breach model. | |
| Recommendation — Protect data at rest and connect exposure findings to remediation workflows. Review entitlements and authorisations for any identity that can reach sensitive cloud data. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Service accounts and automation credentials are part of the exposure path described. |
| Recommendation — Reduce overprivileged non-human identities that can reach sensitive cloud data. | ||
Key terms
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Exposure Reachability: The degree to which a vulnerability, asset, or identity can actually be reached and abused by an attacker. It is more useful than static severity alone because it reflects whether the risky condition is present in a path that could realistically be used during an attack.
- Privilege Reduction: The practice of removing unnecessary elevated access so users and systems hold only the permissions they need. It is a core control for limiting blast radius, especially where legacy systems have long-standing admin accounts or inconsistent approval workflows.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org