By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: CyberhavenPublished March 11, 2026

TL;DR: At Axos Bank, the security team frames risk management around full visibility into where data sits, how it moves, and which protections are actually applied, according to Cyberhaven's Q&A with CISO Raghu Valipireddy. The implication is that broad controls without data context create false confidence, and DSPM becomes most useful when it ties policy to real usage rather than assumption.


At a glance

What this is: This Q&A argues that effective risk management in a financial services environment depends on understanding data location, movement, and protection coverage.

Why it matters: It matters because identity and access decisions only work when security teams can see which users, systems, and workloads are touching sensitive data and whether those access paths are justified.

👉 Read Cyberhaven's Q&A on data visibility and risk management at Axos Bank


Context

Data security posture management, or DSPM, only becomes useful when it answers a practical question: where is sensitive data, who can reach it, and what controls actually apply. In regulated environments, teams often widen controls because they lack that visibility, which can reduce confidence without reducing risk. The primary issue here is not tool coverage, but governance clarity around data movement and access.

This discussion also intersects with identity governance. Access control decisions, service account permissions, and workload entitlements all become more defensible when they are anchored to real data usage rather than assumed exposure. For IAM, PAM, and data security teams, that makes visibility a prerequisite for least privilege, not a reporting luxury.


Key questions

Q: How should security teams use DSPM in an IAM programme?

A: Security teams should use DSPM as a source of identity-aware data context, not as a standalone reporting layer. The practical goal is to connect classified data to the identities that can reach it, then use that mapping to drive access reviews, least-privilege decisions, and exception handling. That is where data governance becomes operational.

Q: Why does data visibility matter for least privilege?

A: Least privilege depends on knowing what access is actually needed for specific data, systems, and workflows. When teams lack visibility, they usually compensate with broad controls that are easier to apply but harder to justify. Visibility makes it possible to scope permissions to real usage instead of assumed exposure.

Q: What breaks when organisations apply controls everywhere without data context?

A: They often create a false sense of security, because the control exists but may not cover the data path that matters. Universal policies can also add friction for low-risk use cases while leaving high-risk data flows insufficiently explained. The result is weaker governance, not stronger assurance.

Q: How do identity teams and data security teams share accountability for on-prem exposure?

A: Identity teams need to supply the effective permission model, while data security teams need to identify which files and datasets are truly sensitive. The shared accountability point is the overlap between the two. When both teams work from the same exposure view, they can explain access, prioritise remediation, and defend decisions during audit or incident response.


Technical breakdown

Why data visibility changes risk decisions

Data visibility gives security teams a current map of what sensitive information exists, where it lives, and which systems move it. Without that map, organisations tend to apply controls broadly because they cannot confidently scope exposure. DSPM closes that gap by correlating data discovery, classification, and movement so teams can distinguish real risk from theoretical risk. In practice, this shifts security from blanket restriction to evidence-based control selection.

Practical implication: use visibility data to narrow controls to the assets that actually contain or move sensitive information.

How DSPM supports access governance

DSPM is strongest when it informs access governance rather than sitting beside it. Once teams know where data resides, they can evaluate whether human users, service accounts, and workloads have access that matches business need. That matters because over-permissioned identities often become invisible risk multipliers when data flows across cloud, SaaS, and internal systems. Visibility therefore becomes the input to entitlement review, not a replacement for it.

Practical implication: feed DSPM findings into IAM and PAM reviews so entitlements reflect data sensitivity and usage.

Why broad controls often create false confidence

Applying the same control everywhere is a common response when organisations cannot trace data confidently. It feels safer, but it often hides the difference between high-value datasets and low-risk information. The result is control fatigue, where teams accumulate policy but cannot prove whether it protects the right data at the right time. That is a governance failure as much as a technical one.

Practical implication: test whether existing controls are tied to specific data locations and flows, not just policy defaults.


NHI Mgmt Group analysis

Data visibility is the missing control plane in many security programmes. The Axos Bank discussion shows that teams often treat visibility as an observability issue, when it is actually a governance issue. If you cannot see where data lives and moves, you cannot credibly assert that access controls are proportionate or effective. For practitioners, that means data visibility should sit upstream of policy design, entitlement review, and monitoring.

DSPM becomes most valuable when it informs identity decisions, not only data discovery. The article points to a basic truth that IAM and data security teams still struggle with: identity controls are only as accurate as the data context behind them. Human and non-human identities alike can accumulate access that looks acceptable on paper but is excessive relative to the data they can reach. For practitioners, DSPM should feed identity governance workflows, not operate in isolation.

Broad controls without data context create governance debt. When organisations apply controls universally because they cannot locate or classify data confidently, they often expand friction without improving assurance. That pattern produces policy sprawl, confused ownership, and weak evidence for audit. The discipline-level lesson is that security programmes need data-aware governance if they want least privilege to be measurable rather than aspirational.

Data visibility also sharpens the boundary between technical protection and business risk. Valipireddy's framing links security success to business continuity, which is the right lens for financial services and any regulated sector handling sensitive information. A programme that cannot explain which data is protected, by whom, and at what level of assurance will struggle to defend its risk decisions. For practitioners, the question is not whether to deploy more controls, but whether those controls map cleanly to the data that matters.

What this signals

Data visibility is increasingly a prerequisite for identity governance. As data environments expand across cloud and SaaS, security teams cannot rely on broad policy alone to prove control effectiveness. The practical signal for programmes is that entitlement reviews, classification, and monitoring must be joined up if least privilege is to mean anything operationally.

Non-human identities are the pressure test for data-aware governance. Where machine accounts, API keys, and service accounts can reach sensitive datasets, the question is not whether the control exists but whether it is scoped to the right data path. That aligns closely with the governance problems discussed in the NHI Lifecycle Management Guide and the NIST Cybersecurity Framework 2.0.

Visible data movement will become a board-level assurance requirement. Financial services, in particular, will need stronger evidence that protective controls follow the data rather than the organisation chart. Programmes that cannot map access to sensitive data will struggle to support audit, incident response, and regulatory reporting when pressure rises.


For practitioners

  • Map sensitive data to identity and workload access Build a current inventory that connects data stores to the human users, service accounts, and workloads that can reach them. Use that map to identify where access is broader than business need and where review cycles are blind to real data movement.
  • Feed DSPM findings into entitlement reviews Use data discovery and classification results as the starting point for IAM and PAM review queues. Prioritise identities with access to regulated, customer, or transaction data, then verify whether those privileges still match operational need.
  • Replace blanket controls with data-scoped policies Adjust control design so the highest-friction protections apply only where sensitive data is actually present or moving. This reduces unnecessary friction elsewhere and gives auditors clearer evidence that protection is proportional to risk.
  • Validate protection against actual data movement Check whether encryption, access restrictions, and monitoring are aligned to how data travels across cloud, SaaS, and internal environments. If the security model cannot explain the path, it cannot confidently prove coverage.

Key takeaways

  • Axos Bank's framing shows that risk management depends on seeing where data lives, how it moves, and which identities can touch it.
  • Without that visibility, organisations tend to apply broad controls that increase friction but do not necessarily increase assurance.
  • DSPM is most useful when it informs IAM and PAM decisions, because data context makes least privilege measurable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS-1Data protection outcomes depend on knowing where sensitive data resides and moves.
NIST SP 800-53 Rev 5AC-6Least privilege is central when data visibility feeds entitlement decisions.
CIS Controls v8CIS-6 , Access Control ManagementAccess control management supports data-scoped permissions and review discipline.
ISO/IEC 27001:2022A.5.12Information classification underpins the visibility-first approach described in the article.
GDPRArt.32Where personal data is involved, visibility supports appropriate technical and organisational measures.

Apply AC-6 to limit access to sensitive data paths and remove permissions that are not operationally justified.


Key terms

  • Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
  • Least Privilege: A security principle requiring that every identity — human or non-human — is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Sensitive Data Discovery: Sensitive data discovery is the process of locating where protected or regulated information exists across systems, storage, and workflows. In cloud environments, it must be continuous because assets appear, move, and replicate quickly, making one-off inventories unreliable for governance or incident response.

What's in the full article

Cyberhaven's full case study covers the operational detail this post intentionally leaves for the source:

  • How Axos Bank uses DSPM to connect data visibility with security decision making
  • The specific way the security team evaluates where data sits and how it moves across the environment
  • The practical role Cyberhaven says DSPM plays in the bank's security operations
  • Why the CISO describes visibility as the foundation for confidence in controls

👉 The full Cyberhaven case study adds the bank's security perspective on visibility, control coverage, and decision making.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management. It helps practitioners connect identity controls to the broader security and governance decisions their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org