TL;DR: The gap is cohesion: most organisations already have DSPM and DLP capabilities, but risk insights stay in dashboards while enforcement lives elsewhere, creating delays when data moves across cloud, endpoint, SaaS, and AI environments, according to Cyberhaven. That fragmentation now matters more because data is increasingly mobile and GenAI usage is expanding.
NHIMG editorial — based on content published by Cyberhaven: Redefining Data Security: From Insight to Action
By the numbers:
- 62% of organizations are experimenting with AI agents, and 82% of the top 100 most-used GenAI SaaS applications are medium, high, or critical risk.
- 40% of data breaches involve data spread across multiple environments, including public clouds, private clouds, and on-premises infrastructure.
- By 2026, over 20% of businesses will prioritize DSPM technologies to discover and secure their known and unknown data repositories.
Questions worth separating out
Q: How should security teams combine DSPM and DLP in modern data environments?
A: Use DSPM to discover and classify sensitive data, map who can access it, and identify exposure that policy may not see.
Q: Why do data security controls fail when data moves from cloud to endpoint?
A: Because many programmes still assume the repository is the control boundary.
Q: What do security teams get wrong about unified cloud security platforms?
A: Teams often assume consolidation alone solves cloud risk.
Practitioner guidance
- Define one data policy model Map classification, access conditions, and enforcement actions to a single policy schema so teams do not translate rules manually between DSPM and DLP.
- Prioritise endpoint and collaboration controls Focus on the places where data is copied, emailed, downloaded, or shared into unmanaged environments, because that is where context is most often lost.
- Track data lineage for sensitive content Record where sensitive files originated, how they moved, who touched them, and where they currently reside so analysts can distinguish expected work from suspicious relocation.
What's in the full article
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- How its combined DSPM and DLP workflow is intended to reduce translation gaps between discovery and enforcement
- Examples of endpoint-first data tracking across cloud, SaaS, email, and personal devices
- The specific way lineage is used to decide whether a file move is risky or routine
- Why the vendor frames unified data security as a platform operating model rather than a stitched integration layer
👉 Read Cyberhaven's analysis of unified DSPM and DLP for data security →
DSPM and DLP cohesion: what data security teams are missing?
Explore further
The real problem is not the absence of data security tools, but the absence of a shared control plane. Discovery tools without enforcement produce alerts that teams cannot act on fast enough, while enforcement tools without discovery miss what should be protected in the first place. That split weakens both governance and response. For practitioners, the takeaway is that cohesion matters more than inventory.
A question worth separating out:
Q: How do teams know if identity security controls are actually working?
A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads. A useful sign is reduced time between entitlement change and policy review. Another is fewer unresolved conflicts between approved access and actual production permissions.
👉 Read our full editorial: Unified data security is exposing the DSPM and DLP gap