Join our Newsletter — 33% off our NHI Course

DSPM for cloud breach reduction: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Cloud-stored data now appears in 82% of breaches and 39% span multiple environments, according to Cyera’s Data Security Architect’s Guide to Adopting DSPM. The implication is that visibility, misconfiguration control, and privilege reduction now matter more than perimeter assumptions, and DSPM only helps when it is tied to IAM and remediation workflows.

Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “The Data Security Architect's Guide to Adopting DSPM”.

By the numbers:

  • 82% of breaches now involve cloud-stored data.
  • 39% of breaches span across multiple environments.

Key questions

Q: What breaks when cloud data discovery is not tied to access cleanup?

A: Discovery alone only tells you where sensitive data exists.

Q: Why do excessive privileges make cloud data breaches more likely?

A: Excessive privileges enlarge the number of identities that can touch sensitive data, which turns a single compromised account or token into broader exposure.

Q: How do organisations know whether DSPM remediation is actually reducing risk?

A: They need evidence that exposure dropped and stayed down over time.

Practitioner guidance

  • Map sensitive data to reachable identities Build a control view that shows which human accounts, service accounts, tokens, and workloads can actually reach sensitive cloud data, then use that map to remove unnecessary access.
  • Prioritise misconfiguration remediation by exposure depth Rank cloud findings by whether they expose regulated or sensitive data, then fix the settings that materially increase breach likelihood before low-impact hygiene issues.
  • Link DSPM findings to access review workflows Send high-risk exposure findings into the same remediation path used for entitlement cleanup, so data risk and identity risk are closed together instead of in separate queues.

Bottom line: Cloud breach reduction now depends on shrinking reachable sensitive data, not only on protecting the perimeter.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

DSPM is becoming the data-layer control plane for cloud breach reduction. The old assumption that perimeter control could contain cloud risk no longer matches how breaches form across storage, identity, and configuration layers. When data exposure and privilege scope drift together, the meaningful control question becomes which data is reachable and by whom. Practitioners should treat DSPM as an operational prioritisation layer, not a reporting dashboard.

A few things that frame the scale:

  • 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How should security teams use DSPM in an IAM programme?

A: Security teams should use DSPM as a source of identity-aware data context, not as a standalone reporting layer. The practical goal is to connect classified data to the identities that can reach it, then use that mapping to drive access reviews, least-privilege decisions, and exception handling. That is where data governance becomes operational.

👉 Read our full editorial: Data security posture management for cloud breaches and privilege gaps


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.