TL;DR: First-generation DSPM tools often stop at cloud discovery, leaving gaps in endpoint coverage, lineage, and enforcement as data moves toward unauthorized destinations, according to Cyberhaven. The practical shift is from static visibility to continuous control, especially where sensitive data flows into browsers, SaaS apps, and AI tools.
At a glance
What this is: This is a buyer’s guide for evaluating next-generation DSPM, with the key finding that discovery alone is no longer enough when data moves across endpoints, SaaS, and AI workflows.
Why it matters: It matters because IAM and security teams need to know not only where sensitive data sits, but who can move it, where it goes, and whether controls can intervene before exposure becomes an incident.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
👉 Read Cyberhaven's guide to evaluating next-generation DSPM tools
Context
Data security posture management is supposed to answer where sensitive data lives, who can access it, and how exposed it is. The problem is that many deployments only answer the first two questions in static cloud repositories, while the real risk appears when data is copied, renamed, pasted, uploaded, or moved onto unmanaged endpoints and AI tools.
That gap matters for identity programmes because access is only part of the control picture. If a user, service account, or agent can move sensitive data outside its intended boundary, posture visibility without enforcement becomes a reporting function rather than a security control. This is where data governance starts overlapping with IAM, PAM, and NHI governance.
The article’s starting point is typical of mature buyer evaluations: teams discover that discovery tools are useful but incomplete, then begin asking whether the platform can follow data in motion and intervene at the point of exposure.
Key questions
Q: How should security teams evaluate DSPM tools that claim to go beyond cloud discovery?
A: Teams should test whether the platform covers endpoints, browsers, SaaS apps, and unmanaged devices, not just cloud repositories. The key question is whether sensitivity context survives movement and whether policy can act at the moment data is leaving. If the tool only produces alerts and tickets, it is still a visibility tool, not a protection control.
Q: Why does data lineage matter more than static classification in DSPM?
A: Static classification tells you where sensitive data exists at a point in time. Lineage tells you whether that sensitivity follows the data after copy, rename, paste, or upload events. Without lineage, organisations lose the context needed to stop exposure once data starts moving across applications and devices.
Q: What breaks when DSPM cannot enforce policy in real time?
A: The gap between detection and action becomes the failure mode. Data can leave controlled environments before a ticket is reviewed, which means the platform may document exposure without preventing it. Real-time enforcement is what turns posture findings into risk reduction rather than after-the-fact reporting.
Q: Should organisations treat DSPM as part of IAM or data security?
A: Organisations should treat DSPM as part of both, because sensitive data exposure depends on identity paths as much as data location. If IAM and DSPM stay separate, teams can classify data accurately while leaving excessive access untouched. The operational answer is one control model across access, classification, and review.
Technical breakdown
Why cloud-only DSPM misses the highest-risk data paths
Cloud-only DSPM tools scan repositories such as object storage, warehouses, and SaaS tenants on a schedule. That model works for inventory, but it misses the operational reality that data risk is created on endpoints, moved through browsers, and often copied into places the original scan never sees. Once content leaves the original repository, snapshot-based classification loses context unless lineage is maintained. This is why discovery without endpoint visibility produces blind spots that dashboards cannot close. In practice, the control problem is not just where the data was found, but whether the tool can keep tracking it after the first movement.
Practical implication: validate endpoint and SaaS coverage before treating any DSPM result as complete.
How data lineage preserves sensitivity as content moves
Data lineage is the ability to trace sensitive content through transformations, access events, and application transitions. In DSPM, that means the sensitivity tag should follow a file even if it is downloaded, copied into a new document, renamed, pasted into an AI prompt, or uploaded into a personal account. Without lineage, classification becomes a point-in-time snapshot instead of a durable control signal. That matters because many exfiltration paths are not single events; they are a chain of normal actions that cumulatively move sensitive information outside approved boundaries.
Practical implication: require lineage-based classification if you need usable controls beyond static inventory.
Why native enforcement changes DSPM from posture to protection
Alerting tells you that sensitive data is moving toward a risky destination, but it does not stop the movement. Native enforcement closes that gap by applying controls at the event layer, such as blocking uploads to personal cloud accounts or preventing pasting into unsanctioned AI tools. That is a different operating model from ticket-based remediation, where response arrives after the data has already left. For practitioners, this shifts DSPM from a compliance-oriented visibility layer into a live control point that can support DLP-like interventions using the same classification model.
Practical implication: ask whether the platform can block, not just detect, data movement in real time.
Threat narrative
Attacker objective: The objective is to extract or redirect sensitive business data through ordinary user workflows without triggering effective prevention controls.
- Entry occurs when sensitive data is created or downloaded onto endpoints, then later copied into SaaS, browser, or AI workflows that the original repository scan does not continuously monitor.
- Escalation happens when classification context is lost as files are renamed, pasted, or transformed, allowing sensitive content to blend into normal user activity and evade policy enforcement.
- Impact follows when the organisation can only observe the exposure after the data has already moved to an unauthorised destination or left the controlled environment entirely.
NHI Mgmt Group analysis
Discovery without enforcement is not a control strategy. Static visibility still has value, but it cannot close the gap between seeing sensitive data and stopping its movement. In modern data environments, that gap is where most practical exposure occurs, especially when endpoints, SaaS, and browser-based workflows are in play. Practitioners should treat alerting-only DSPM as an inventory layer, not as a protection layer.
Data lineage is becoming the decisive concept in modern DSPM. The important question is no longer only where sensitive data was found, but whether its classification survives copy, rename, paste, and upload events. That concept matters because lineage turns posture from a snapshot into a durable security signal. For programmes that govern data access, the practitioner conclusion is to prioritise tools that preserve context in motion.
AI data movement risk: data leaving the enterprise through generative and agentic workflows creates a governance problem that traditional cloud scans cannot see. When employees and AI systems can move content across boundaries in seconds, posture management must understand both user intent and runtime destination. This is where DSPM starts intersecting with identity governance, because the same access that lets a person or agent read data can also let them move it. Practitioners should align DSPM with identity controls and endpoint enforcement, not leave it isolated.
Identity governance and data governance are converging at the boundary of movement. IAM tells you who is allowed to touch a resource, but DSPM increasingly has to answer what happens after that access is used. That creates a new governance burden for service accounts, human users, and AI agents alike. The practical conclusion is that data security programmes now need identity-aware enforcement, not just repository scanning.
Buyers should evaluate posture tools by their control depth, not their scan count. A platform that finds more objects but cannot enforce policy, maintain lineage, or cover endpoints may increase reporting volume without reducing risk. The field is moving toward operational control, and practitioners should make procurement decisions accordingly.
What this signals
Data security programmes are moving toward runtime control, not just inventory management. That shift changes procurement and operating models because teams can no longer rely on periodic scans to explain current exposure. For identity and security leaders, the practical signal is to align DSPM with endpoint control, access governance, and policy enforcement so visibility translates into intervention.
AI data handling now needs the same scrutiny as human file movement. Once employees and AI workflows can ingest and redistribute sensitive content, the boundary between data security and identity governance narrows. Practitioners should expect more pressure to prove that access, movement, and enforcement are connected across the stack.
Discipline will matter more than breadth. Buyers should prefer platforms that can prove lineage, control movement, and support audit evidence over tools that simply produce larger discovery reports. That is especially true where service accounts or AI agents can move data faster than review processes can react.
For practitioners
- Validate endpoint and browser coverage Test whether the DSPM platform can see sensitive data on managed and unmanaged endpoints, then track it through browser uploads, local file copies, and SaaS transfers.
- Require lineage-based classification Confirm that sensitivity labels persist after copy-paste, rename, format change, and application transitions so data context does not reset at each hop.
- Test native enforcement before rollout Run scenarios where users attempt to upload sensitive content to personal cloud storage or unsanctioned AI tools and verify that policy can block the event in real time.
- Map DSPM findings to identity controls Tie sensitive-data exposure paths back to the users, service accounts, and AI workflows that can move the data, then review whether access scope matches the business need.
Key takeaways
- DSPM is no longer just a discovery problem, because data that can move is data that can escape.
- Endpoint coverage, lineage, and enforcement are the three capabilities that separate posture reporting from control.
- Identity and data governance now meet at the point of movement, especially where users, service accounts, or AI tools can export sensitive content.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | The article centers on controlling access and movement of sensitive data. |
| NIST SP 800-53 Rev 5 | AC-6 | Least-privilege access is central to limiting who can move sensitive data. |
| CIS Controls v8 | CIS-5 , Account Management | Account governance matters where identities can move data into risky destinations. |
| ISO/IEC 27001:2022 | A.8.12 | Information leakage prevention aligns with the article's enforcement emphasis. |
| MITRE ATT&CK | TA0009 , Collection; TA0010 , Exfiltration | The article describes data movement paths that map to collection and exfiltration behavior. |
Map data-movement scenarios to collection and exfiltration tactics so detections and blocks target real abuse paths.
Key terms
- Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
- Native Enforcement: Native enforcement means access decisions are made by the data platform itself rather than by a separate overlay or proxy. That matters because every caller reaches the same enforced rule set, but it also means governance must focus on visibility, consistency, and evidence across the platform state.
- Sensitivity Context: Sensitivity context is the information that explains why data is sensitive, including origin, provenance, and business meaning. It is what lets a platform distinguish corporate confidential content from harmless text and preserve that judgment when files change format or location.
- Agentic Data Flow: Agentic data flow is the movement of information through AI systems that can process, route, or redistribute content with broad permissions. It creates a governance challenge because access decisions and data movement can occur without a human triggering every step, which requires identity-aware and runtime controls.
What's in the full article
Cyberhaven's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step evaluation criteria for endpoint data visibility and unmanaged device coverage
- Operational distinctions between DSPM, DLP, and lineage-based enforcement across SaaS and AI tools
- Examples of how provenance-aware classification reduces false positives in real environments
- Questions to ask about onboarding time, evidence storage, and long-term program control
👉 Cyberhaven's full post covers the seven evaluation criteria and the enforcement gaps behind them
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management for practitioners building stronger identity controls. It helps security teams connect lifecycle discipline to the broader access governance problems that modern programmes face.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org