Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Data visibility and DSPM in banking: what IAM teams should notice


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: At Axos Bank, the security team frames risk management around full visibility into where data sits, how it moves, and which protections are actually applied, according to Cyberhaven's Q&A with CISO Raghu Valipireddy. The implication is that broad controls without data context create false confidence, and DSPM becomes most useful when it ties policy to real usage rather than assumption.

NHIMG editorial — based on content published by Cyberhaven: Q&A: Managing Risk Through Data Visibility at Axos Bank

Questions worth separating out

Q: How should security teams use DSPM in an IAM programme?

A: Security teams should use DSPM as a source of identity-aware data context, not as a standalone reporting layer.

Q: Why does data visibility matter for least privilege?

A: Least privilege depends on knowing what access is actually needed for specific data, systems, and workflows.

Q: What breaks when organisations apply controls everywhere without data context?

A: They often create a false sense of security, because the control exists but may not cover the data path that matters.

Practitioner guidance

What's in the full article

Cyberhaven's full case study covers the operational detail this post intentionally leaves for the source:

  • How Axos Bank uses DSPM to connect data visibility with security decision making
  • The specific way the security team evaluates where data sits and how it moves across the environment
  • The practical role Cyberhaven says DSPM plays in the bank's security operations
  • Why the CISO describes visibility as the foundation for confidence in controls

👉 Read Cyberhaven's Q&A on data visibility and risk management at Axos Bank →

Data visibility and DSPM in banking: what IAM teams should notice?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Data visibility is the missing control plane in many security programmes. The Axos Bank discussion shows that teams often treat visibility as an observability issue, when it is actually a governance issue. If you cannot see where data lives and moves, you cannot credibly assert that access controls are proportionate or effective. For practitioners, that means data visibility should sit upstream of policy design, entitlement review, and monitoring.

A question worth separating out:

Q: How do identity teams and data security teams share accountability for on-prem exposure?

A: Identity teams need to supply the effective permission model, while data security teams need to identify which files and datasets are truly sensitive. The shared accountability point is the overlap between the two. When both teams work from the same exposure view, they can explain access, prioritise remediation, and defend decisions during audit or incident response.

👉 Read our full editorial: Data visibility is the control plane for risk management at Axos Bank



   
ReplyQuote
Share: