TL;DR: A global travel platform secured petabytes of sensitive data across 600-plus cloud accounts in 30 days by replacing manual tagging and reactive DLP with agentless discovery, AI classification, and compliance mapping, according to Sentra. The bigger lesson is that visibility, access governance, and data classification have to move together when cloud estates outgrow manual operations.
NHIMG editorial — based on content published by Sentra: how a global travel platform secured petabytes of sensitive data across 600+ cloud accounts
By the numbers:
- Sentra says the travel platform secured sensitive data across 600+ cloud accounts in just 30 days.
- The environment included over 150K data stores, underscoring the scale of the discovery problem.
Questions worth separating out
Q: How should security teams govern cloud accounts when estates keep growing?
A: They should treat account growth as a control-design problem, not a provisioning problem.
Q: Why do manual tagging and reactive DLP fail at cloud scale?
A: Manual tagging cannot keep up with rapid storage growth, and reactive DLP only detects issues after data has moved or been exposed.
Q: What do IAM teams need to do differently when data visibility improves?
A: They should use new visibility to trigger access decisions, not just reporting.
Practitioner guidance
- Implement continuous cloud data discovery Replace periodic scans and manual tagging with continuous discovery across cloud accounts, storage services, and regions so sensitive data is visible as the estate changes.
- Link classification findings to access review Feed sensitive data inventories into IAM and entitlement review workflows so owners can assess who has access to high-risk stores and revoke excess access faster.
- Measure classification quality, not just coverage Track false positives, missed labels, and time-to-detect for sensitive data so the team can judge whether classification is reliable enough for governance decisions.
What's in the full article
Sentra's full case study covers the implementation details this post intentionally leaves for the source:
- How the agentless deployment was tuned across 600-plus cloud accounts and 150K-plus data stores
- What the team changed in scanning cycles for high-memory formats and near real-time discovery
- How the organisation reduced false positives while aligning findings to PCI DSS and GDPR
- What the customer success and engineering collaboration looked like during rollout
👉 Read Sentra's case study on securing petabytes of cloud data across 600+ accounts →
Petabyte-scale cloud data security: what IAM and DSPM teams should note?
Explore further
Petabyte-scale data security fails when visibility is treated as a project instead of a control. Once cloud estates reach hundreds of accounts, manual tagging and periodic reviews cannot keep pace with change. The operational consequence is that teams only discover exposure after it has already widened. For identity and data governance leaders, the lesson is that inventory freshness is a control property, not an administrative task.
A question worth separating out:
Q: How do compliance teams turn DSPM findings into audit value?
A: They should map sensitive data locations to the specific controls and evidence auditors ask for, then document who can access what and why. This is especially useful for PCI DSS and GDPR, where inventory, access limitation, and accountability matter. The key is to make classification output usable for control testing.
👉 Read our full editorial: Cloud data security at petabyte scale exposes the limits of manual DLP