Data Management
Written by: Nick Ritter | Founder, Global Leadership & Trust Advisors | Former CISO
Updated 8:00 AM EDT, September 25, 2026

Data security today requires organizations to move beyond traditional perimeter defenses. For Chief Data Officers (CDOs), Chief Information Security Officers (CISOs), and data leaders, that means adopting modern data governance, AI governance, and security frameworks that provide stronger visibility, risk management, and control across increasingly complex cloud, SaaS, hybrid, and AI-enabled environments.
Modern data protection shifts the focus from securing infrastructure to securing the data itself, wherever it resides. Two of the most critical and complementary frameworks supporting this shift are Data Security Posture Management (DSPM) and Data Loss Prevention (DLP). When used in conjunction with robust access authentication, authorization, and logging practices, these frameworks create a strong foundation for modern data protection and governance.
DSPM is a proactive, data-centric approach focused on data-at-rest and its associated risks. At its core, DSPM helps organizations answer three foundational questions:
By continuously identifying, classifying, and assessing sensitive data assets, DSPM provides organizations with the visibility needed to understand and reduce their overall data risk surface. The following capabilities form the foundation of an effective DSPM strategy.
Table 1: Core DSPM Functions

Borrowing from the 2022 blockbuster, the desire is often for enterprises to protect “everything, everywhere, all at once.” In practice, however, DSPM is essential for helping organizations define what is truly critical to protect in their environment.
Just as importantly, DSPM also helps organizations answer another difficult question: “How much friction can business processes realistically absorb?”
Successful governance programs must balance security controls with operational usability and business needs. If an organization is too heavy-handed, organizational resistance may doom the program; however, if an organization is too light, then the controls may not deliver meaningful value.
DLP is an enforcement mechanism focused on data-in-motion and unauthorized egress. It helps organizations answer a critical question:
This is where DLP becomes a critical enforcement layer within a broader data governance strategy. DLP relies heavily on the classification and visibility provided by governance and DSPM tools to enforce policies in real time. By itself, however, DLP has some significant limitations that can be mitigated through the robust data classification and tagging capabilities provided by DSPM.
DLP platforms support several core enforcement and monitoring functions.
Table 2: DLP — Core Capabilities

DSPM and DLP are not mutually exclusive; they are two sides of the same data security coin. Their synergy forms the foundation of a robust modern governance program. As mentioned previously, DLP has some significant limitations unless paired with robust data classification and tagging capabilities.
Overall, the key takeaways are:
Table 3 below highlights how DSPM and DLP work together within a unified governance framework.
Table 3: DSPM vs. DLP — Roles in a Unified Data Security Framework

A successful program uses DSPM to provide actionable insights for tuning and strengthening DLP policies, helping organizations close security gaps that traditional DLP alone might miss in dynamic cloud environments.
While advanced data protection and governance frameworks are essential for modern enterprises, implementing them at scale presents several challenges for program leaders.
The proliferation of cloud services (e.g., SaaS, IaaS, PaaS) and AI tools continues to drive massive data sprawl across organizations. Sensitive data often exists in unmanaged or untracked locations, creating “shadow data” that legacy DLP and traditional cloud security tools cannot effectively manage. This is a core challenge DSPM is designed to help solve.
Legacy DLP solutions are notorious for generating high volumes of false positives, leading to alert fatigue for security teams and operational friction for business users. Modern governance programs require contextual classification from DSPM to prioritize genuine, high-risk alerts and automate lower-risk remediation.
Traditional security tools often struggle to integrate with the speed and agility of DevOps and modern cloud-native architectures. Governance solutions must integrate seamlessly through APIs and agentless architectures to monitor dynamic cloud-native environments without slowing development or operational workflows. This requires ongoing collaboration between security, engineering, and data teams to operationalize governance controls in cloud-native environments.
Security investments must translate into demonstrable improvements in compliance (e.g., GDPR, HIPAA, CCPA) and risk reduction. Proving the value of modern security and governance tools requires continuous reporting, automated compliance mapping, and clear metrics tied to security posture improvement. Establishing these metrics early helps organizations determine whether security and governance controls are actually reducing risk over time.
Program leaders can strengthen organizational vigilance by adopting strategic, data-centric governance practices.
Strategy:
Before enforcing any rule, organizations must first understand what they are protecting. Using high-level business categorizations of data (e.g., PCI, HIPAA, intellectual property, PII, non-public financial information, business strategy, etc.), organizations should co-document these assets with the data and process owners who are critical to the business. These then become the organization’s most business-critical and sensitive data assets — its “Crown Jewels.”
Actionable Step:
Co-develop risk tolerance and risk appetite for the organization’s most critical data assets. Depending on the organization, different risk levels may be associated with different important data sets.
Strategy:
Prioritize the deployment of a DSPM solution to establish a comprehensive, accurate, and continuous inventory of critical and sensitive data assets, including their locations and risk profiles. Refine the organization’s Crown Jewel inventory based on the data discovery process.
Actionable Step:
Use DSPM to identify the top five most over-permissioned repositories containing sensitive or business-critical data, and prioritize initial DLP policy enforcement on those assets.
Strategy:
Move beyond manually-tuned policies and towards the integration of DSPM and DLP technologies. Use the risk-based insights provided by DSPM to automate the creation and refinement of DLP rules. This helps ensure policies are based not only on keywords but also on actual risk context — including sensitive data in vulnerable locations with overly permissive access.
Strategy:
A core principle of modern governance is the enforcement of Zero Trust principles for data access. Leverage DSPM to audit and enforce least-privilege access by continuously identifying and flagging over-permissioned accounts and roles, particularly within cloud-native data stores like S3 buckets or Snowflake databases.
Strategy:
Implement tools to automate remediation and scale governance capabilities.
Actionable Steps:
2. Measure Posture Improvement, Not Just Incidents
Strategy:
Shift reporting metrics from a reactive focus on data leak incidents to a more proactive focus on security posture improvement.
Actionable Steps:
Implement key program metrics, including: