The IDC DataSphere 2024-2028 reports a vast explosion in data growth from current figures. By 2028, it predicts the amount of data created, captured, replicated and consumed worldwide will reach almost 395ZB – more than double the 175ZB predicted in 2025 and three times the 129ZB from 2023.

This dramatic increase is fueled by the rapid adoption of AI – particularly generative AI models that both ingest and output huge volumes of data – and continued digital transformation initiatives by organizations looking to maximize efficiency and drive innovation.

These initiatives include digitization of physical records, cloud migration and app deployment. Okta reported in its Businesses at Work 2025 report that companies with 2,000 or more employees deploy an average of 247 apps – meaning the number of places where data resides is magnified. In addition, more than half of enterprise and SMB workloads now run in the cloud with 70% operating hybrid cloud environments, according to the Flexera State of the Cloud Report 2025.

This acceleration in data growth amid a complex cybersecurity landscape, driven by increasingly sophisticated cyber threats and geopolitical tensions, means that effective data security practices are essential to regain control while supporting continued growth and innovation.

Data management realities and the digital supply chain

Organizations now operate in highly fragmented digital environments composed of multiple cloud services, SaaS platforms, AI tools and third-party supply chains, with a hybrid workforce spanning on-premises and remote locations. This distributed architecture significantly expands the attack surface, making traditional perimeter-based security models obsolete.

Meanwhile, AI adoption continues apace with 73% of businesses investing in generative AI tools. Unauthorized use of AI and SaaS services is also growing, as almost two-thirds of employees admit to using publicly available AI tools at work and 55% are utilizing SaaS solutions with no involvement from central security teams.
Against this backdrop, businesses face an uphill battle to identify and protect sensitive data from unauthorized access and cyberattacks. It is imperative they look to a coordinated data security posture management framework capable of providing governance oversight and control across diverse, fragmented and highly distributed environments.

DSPM: A framework for data-centric governance and control

The concept of data security posture management (DSPM), coined by Gartner, has emerged to bridge the gap between traditional, infrastructure-based security and the realities of data sprawl driven by new technologies and working practices.

DSPM provides a framework for discovering previously unknown data across on-premises networks and cloud platforms, categorizing and classifying structured and unstructured data assets based on their sensitivity. Under DSPM, access reviews support evaluation of data security posture and “exposure to privacy, security and AI-usage risks.”

DSPM operates at the data level – the core of business operations, innovation and growth – essentially asking: What sensitive data do we have; where is it; who can access it; how is it being used; how is AI using it; and what is its exposure?

The six principles of DSPM

DSPM can be broken down into six core principles.

1. Discovery and identification

Data discovery enables organizations to locate sensitive, regulated and business-critical information across diverse formats and environments – from structured databases to unstructured files and semi-structured logs. This visibility is critical not only for reducing risk – especially as 1 in 3 breaches now involve shadow data – but also for meeting growing regulatory demands. According to Ground Labs research, 42% of organizations lack confidence in identifying their sensitive data, while 30% have never used a data discovery or identification tool.

2. Categorization and classification

Once identified, data assets should be categorized into data type - e.g., personal information, protected health information, intellectual property, secrets, etc. It should then be classified and labeled based on its sensitivity. Additional contextual information can also be added to support data lifecycle management, including data owner, purpose, master location and retention period.

3. Threat and vulnerability detection

With data now identified and classified, organizations can identify the systems, platforms and services that store, transmit and process it. Threats and vulnerabilities affecting these should be identified and documented, along with any recommended mitigation actions. These could include misconfigurations, software supply chain vulnerabilities, platform vulnerabilities, insecure plugins, API security exposures, etc.

4. Risk assessment

The risk assessment process evaluates the security posture and exposure of data assets to privacy, security and AI-usage risks, based on who has access to it and how it is protected in situ. With the rise of cloud computing and SaaS, access controls are the primary security measure protecting sensitive data. According to the Cloud Security Alliance, 67% have overshared sensitive information via SaaS, and 56% have uploaded this data to unauthorized apps.

5. Mitigation and policy enforcement

In the mitigation phase, any unacceptable exposures should be addressed by implementing security controls such as least-privilege access and multifactor authentication, encryption/tokenization, data localization/deduplication, and addressing platform and service misconfigurations. In addition, enforcement of security policies should be automated through DSPM solutions to prevent similar failures recurring.

6. Continuous monitoring

As new data is ingested and created all the time, this process must be established in a continuous cycle to ensure real-time monitoring and evaluation of data risk across the organization. Organizations must be able to identify new and unknown stores of information, apps and services before they become a liability. Continuous monitoring is essential for effective risk reduction against threats including ransomware, supply chain attacks and insider threats.

Aligning governance, risk and cybersecurity frameworks

DSPM provides a comprehensive framework for identifying and managing data security across complex technology landscapes. However, it does not operate in isolation. DSPM aligns common cybersecurity, risk management and IT governance standards in a unified approach.

DSPM offers cross-domain support for ISACA frameworks including COBIT 2019 and the Risk IT Framework.

  • COBIT 2019 – DSPM informs enterprise data strategy and risk appetite, while enabling performance and compliance monitoring over time. It provides evidence for effective data management and a structure for achieving it, in both development pipelines and business operations.

  • Risk IT – DSPM provides a structure for identifying and evaluating data risk, and mechanisms for treating them according to a consistent, centralized and informed process.

Further, DSPM integrates and consolidates across a much wider range of standards, legislation and best practices including:

  • NIST CSF 2.0 – DSPM addresses the oversight, discovery and management of data throughout the govern-identify-protect-detect-respond framework

  • ISO/IEC 27001 – DSPM supports the data-first approach adopted in the 2022 version of the standard, driving identification and management of information assets and the systems and services that process it

  • US Privacy Legislation - CCPA/CPRA, CPA, CTDPA, MODPA, KCDPA, etc. – DSPM is a core baseline for managing the rapid expansion of the US privacy patchwork, enabling compliance with mandatory audits, strict data minimization, and new sensitive data controls.

  • Industry Standards and International Legislation - PCI DSS, HIPAA, GDPR, etc. – DSPM enables compliance with international legislation and industry-centric standards  such as PCI DSS, HIPAA and global privacy laws by identifying and mitigating data risk, in an approach that can prioritize categories of data depending on organizational goals, business context and strategic objectives.

DSPM: A unifying framework for the modern enterprise

Global data volumes are rising rapidly, driven by AI adoption, SaaS sprawl and hybrid cloud growth. While this growth represents a huge opportunity, it brings with it significant risk and complexity that traditional security models cannot manage.

DSPM provides a data-centric approach to data governance designed for highly diverse, complex and fragmented digital estates. It answers critical questions about where sensitive data resides, how it is used and how exposed it is.

Aligned with ISACA frameworks like COBIT 2019, Risk IT and common security standards, DSPM bridges cybersecurity, governance and compliance – ensuring organizations can innovate while maintaining control of their data. DSPM delivers the foundation of effective data governance and control in an ever-changing, increasingly complicated technology and cyber-threat landscape.