Join our Newsletter — 33% off our NHI Course

DSPM adoption and data blind spots: what security teams should know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: 90% of the world’s data was created in the last two years and the total is set to reach 181 zettabytes in 2025, increasing pressure to find and protect sensitive data without expanding blind spots, according to Cyera’s 2024 DSPM Adoption Report based on a survey of 637 IT and cybersecurity professionals. The governance problem is no longer data growth alone, but the gap between discovery, classification, and control.

Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “The 2024 DSPM Adoption Report”.

By the numbers:

  • 90% of the world’s data was created in the last two years.
  • The 2024 State of Data Security Posture Management Report is based on a survey of 637 IT and cybersecurity professionals.

Key questions

Q: What breaks when organisations do not know where sensitive data is stored?

A: Identity controls lose their target.

Q: Why do data visibility gaps create compliance risk even when policies exist?

A: Policies fail when teams cannot see where regulated data lives or how it moves.

Q: How do organisations know whether DSPM is actually improving control?

A: They should look for fewer unmanaged repositories, faster classification of newly created stores, and better linkage between sensitive data and the identities that can access it.

Practitioner guidance

  • Map sensitive data discovery to governance owners Assign clear ownership for each critical data domain so discovery results have a remediation path, not just a dashboard entry.
  • Validate classification against real data locations Compare current classification outputs with where sensitive records actually live across cloud and SaaS stores, then correct drift before policy enforcement.
  • Tie access reviews to current data sensitivity Use the latest discovery and classification results when reviewing who can reach high-value datasets, especially for service accounts and automation paths.

Bottom line: DSPM is rising because organisations cannot protect sensitive data reliably until they can see where it lives and how it is classified.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

DSPM is becoming a visibility discipline before it is a control discipline. The article’s central message is that data growth has outpaced the ability of many teams to maintain a reliable map of sensitive information. When the map is stale, control selection becomes guesswork and exposure persists longer than governance teams assume. Practitioners should treat visibility as the prerequisite control, not a supporting report.

A question worth separating out:

Q: Should organisations prioritise data discovery or access governance first?

A: They should do both together, but discovery usually comes first when the estate is not well understood. Without knowing where sensitive data resides, access governance becomes a partial exercise that misses the highest-risk datasets. Once discovery is in place, teams can align privileges to actual exposure rather than assumptions.

👉 Read our full editorial: DSPM adoption is rising as data visibility gaps widen


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.