The Data You Don't Know You Have Is the Data That Will Burn You
DSPM tools are selling fast and consolidating faster — here's why security teams are scrambling to find the data they forgot existed.

The alert didn't come at 4 a.m. this time. It came quietly, during a routine cloud audit, when a threat hunter at a mid-sized financial services firm scrolled past a storage bucket nobody had touched in two years. Inside: customer records, unencrypted, quietly aging. Nobody had put them there on purpose. Nobody had remembered them at all.
That scenario is the reason data security posture management (DSPM) has become one of the fastest-growing categories in enterprise security. Gartner found DSPM adoption sat at less than 1% of its client base as recently as 2022; within two years, the research firm reported, DSPM's growth had outpaced every other cybersecurity category on the board. The acquisition wave that followed tells its own story: Palo Alto Networks took Dig Security, Rubrik absorbed Laminar Security, IBM folded Polar Security into Guardium, Proofpoint acquired Normalyze, and Google closed its $32 billion deal for Wiz. Tenable, Veeam, Varonis, and Thales each made their own moves, buying niche players and stitching the capabilities into existing platforms.
So what does a DSPM tool actually do that a traditional data loss prevention product doesn't?
The short answer is: it finds the things DLP doesn't know to look for. Classic DLP works from a known threat surface. DSPM starts from a different premise — that your threat surface includes data stores you have actively forgotten. Shadow data is the term of art: old repositories left on a cloud container nobody decommissioned, AI training datasets assembled outside IT's visibility, a rogue analytics warehouse a business unit spun up without a ticket. Gartner describes DSPM as bridging "the gap between data discovery/classification and the eventual implementation of automated remediation controls," said the firm in its most recent market analysis.
The mechanics matter. Most DSPM products operate agentlessly, pulling metadata rather than the raw data itself through read-only API access. That means a scanner can move across AWS S3 buckets, Redshift clusters, Azure Blob Storage, and on-premises SQL servers without copying a single sensitive record out of the customer's environment. Varonis has built what it calls a "universal data connector" designed to reach structured data destinations that less flexible platforms miss. Veeam, meanwhile, is unusually explicit about publishing which cloud services each of its scan profiles actually covers (a transparency other vendors don't always match).
But scanning is only the opening move. Once data is cataloged, the real work is continuous: watching for changes in access rights, detecting when data migrates into a forgotten corner of an estate, flagging when an AI agent starts training on a dataset nobody authorized. That last use case is growing quickly. Shadow AI (internal tools built on unvetted data pipelines) is generating new categories of untracked, mission-critical data stores at a pace traditional IT governance was never built to handle.
And here is where the DSPM category gets genuinely complicated. CVE identifiers don't apply here the way they do in software patching; the risk is architectural, not a discrete flaw. DSPM tools can locate the exposure, but remediation typically belongs to a separate stack: SOAR platforms, SIEM ingestion, or CNAPP enforcement layers. Some vendors bundle these fix-it capabilities; many don't. Gartner noted that the combined capabilities of today's DSPM products "bear only a slight resemblance" to what the category's pioneers originally shipped, leaving buyers uncertain about what they're actually purchasing.
So a security team evaluating platforms right now is making a bet not just on current feature sets but on roadmap velocity. Which cloud services are covered today? Which are promised by Q3? And when that forgotten storage bucket surfaces again at 2 a.m., whose dashboard lights up first?
Nobody at the financial firm could answer that last question about the bucket they found. They're still trying.



