Why Data Security Posture Management Paves the Way Forward for Effective Data Security

Why Data Security Posture Management Paves the Way Forward for Effective Data Security

Enterprises are struggling with three key data challenges. First, there is massive growth in data, often it increases exponentially from year to year. Equally, there is massive migration of data to the cloud. And finally, the data that is worth protecting has become a very complex environment – from Intellectual Property to financial data to business confidential information to regulated PII/PCI/PHI data.

All of these factors present unique challenges to data security. Traditional ways of protecting data like rule writing to discover what data users have that is worth protecting or relying on end users to ensure that data is shared with the right employees at all times simply doesn’t work in an environment such as the cloud where it is now very easy for employees to create, modify and shared sensitive content with anyone.

 

Data Security Posture Management (DSPM) is emerging as a key technology area to solve these challenges. DSPM identifies and remediate risks to structured and unstructured data. It’s an emerging security practice enabled by automated tools that make it possible to secure content at an atomic level without unnecessary overhead or new IT skills. And it’s an enabling technology for a new, more dynamic approach to access management called purpose-based access control (PBAC).

To understand DSPM, consider the similarly named Cloud Security Posture Management (CSPM) category. These solutions improve security by targeting cloud configuration errors, and they were a response to a spate of security breaches related to misconfigured Amazon S3 data storage buckets. Some of the most consequential misconfiguration incidents granted public access to sensitive data or the complete loss of administrative control for production cloud solutions.

Like CSPM, DSPM also focuses on misconfigured access privileges that can lead to data loss. DSPM solutions, however, confront a more extensive and complex threat surface. A moderately complex cloud estate may house a few dozen storage instances and accounts for a handful of administrators. Contrast that threat surface with the complexity of an organization’s entire collection of unstructured data, which can run to tens of millions of files, and that is what DSPM protects. Confronted with the volume and diversity of content needing to be managed and secured, most organizations simply leave data security up to their end users.

Few organizations are comfortable with that risk, but the rise of automated DSPM solutions offers some hope. They offer four capabilities essential to robust data protection:

  1. Content discovery and categorization that provides the proper context for evaluating security best practices
  2. Detection of access misconfigurations, inappropriate sharing, and risky use of email or messaging services
  3. Evaluation of risks associated with data access and use
  4. Risk remediation with the flexibility to tailor actions to suit business requirements

Unlike CSPM, where protected assets – storage buckets, administrative interfaces, online applications, and the like – are well-defined and understood, user-created data is far more complex. Content categories range from valuable source code and intellectual property to regulated customer information and sensitive strategic documents. Accordingly, content discovery and accurate, granular categorization are essential precursors to effective DSPM. But categorization can require a significant initial investment and substantial ongoing maintenance. The two most common approaches – user-applied document tags and automation based on rules – lack the scalability and accuracy necessary for workable categorization.

Detecting misconfigured access settings, overshared files, or the use of risky channels (like personal emails) is even more challenging. Why? Because, even with highly accurate data categorization, hard and fast rules surrounding who can and can’t view a specific data category usually don’t exist. It’s a high-stakes problem because over-constrained data can quickly impact business operations and agility, while overshared data is a potential security risk. Striking the right balance between access and security is critical.

Of course, simply finding at-risk data isn’t enough to protect it. Assessing risk, remediating misconfigured access permissions, and fixing sharing errors complete the DSPM cycle. There’s no magic bullet: Different organizations have different definitions of what’s critical, what’s trivial, and what’s at risk. Evaluating and quantifying risk gives focus to the process of fixing it. Work on the big stuff. Ignore the trivial. Know the difference.

All these tasks – categorizing content, detecting misconfigurations, and analyzing risk – can be accurately completed in DSPM solutions using deep learning technologies. With deep learning, the data (and related information about storage and usage) tells a rich and valuable security story. Advanced deep learning solutions autonomously categorize data; then compare access configurations, storage locations, and data handling practices across similar files to spot and assess risk. It’s the future of DSPM.

It is also critical to do this with an easy deployment model that:

  1. Is API based, agentless, and can be easy to deploy in 5-10 minutes and provides results in days vs months
  2. Can work across unstructured and structured data
  3. Can handle petabytes of data without requiring large security teams
  4. Operates as a SaaS solution

Data Security Posture Management protects your organization from data loss and breaches. Understanding your data, assessing risk, and remediating overly permissive access to sensitive information is at the heart of DSPM. Accurate, autonomous DSPM forms the foundation for more effective access control and overall data security.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.