The Blog | Prescriptive Data Solutions

You Can't Protect Data You Can't See

Written by John Parker | Sep 13, 2026, 1:00:00 PM

 

Organizations have more tools for protecting data than ever before. Firewalls inspect traffic. Endpoint platforms protect laptops and servers. Multifactor authentication adds another layer around access. Data loss prevention tools can stop sensitive information from leaving the organization.

And yet, one basic question is becoming harder to answer: Where is the data?

Not long ago, the answer was relatively straightforward. Important information lived on a file server, inside a known application, or somewhere else within an environment the organization controlled. Today, that same data might be stored in a cloud platform, copied into a SaaS application, downloaded to an employee's laptop, shared through a collaboration tool, or entered into an AI service.

The controls still matter, but controls alone are not enough. Before an organization can decide how to protect its data, it needs to understand what it has, where it lives, and who—or what—can access it.

That is the work of data security posture management.

 

DSPM Starts with Three Questions

Data security posture management, usually shortened to DSPM, can sound like one more acronym in an industry already overflowing with them. The concept itself is much simpler. DSPM helps an organization answer three foundational questions:

1. What data do we have?

2. Where does that data live?

3. Who or what can access it?

Those questions have to come before enforcement. If we do not know that a file contains sensitive customer information, intellectual property, financial records, or regulated data, we cannot reliably apply the right protection to it. If we do not know that a copy has moved into a cloud service or onto a remote endpoint, a policy written for the original location may no longer help us.

This is why I think of DSPM as the missing first step in many data-protection conversations. Organizations often begin by saying they need data loss prevention, stronger access controls, or another security product. Those may all be appropriate. But we cannot regulate data until we know what the data is.

 

DSPM, CSPM, and DLP Are Related—but Not Interchangeable

Some of the confusion around DSPM comes from its overlap with other security disciplines.

Cloud security posture management, or CSPM, focuses primarily on the configuration and security of cloud infrastructure. It asks whether cloud resources are configured correctly, whether permissions are appropriate, and whether the environment introduces avoidable risk.

DSPM follows the data itself. The data may be in the cloud, but it may also be on-premises, in a SaaS platform, on an endpoint, or moving between those locations. The focus is not only whether the surrounding infrastructure is configured correctly, but whether the information is known, classified, and appropriately accessible wherever it travels.

Data loss prevention, or DLP, is the enforcement side of the equation. DLP can help prevent a sensitive file from being uploaded, emailed, copied, or otherwise sent somewhere it should not go. But a DLP rule needs something to act upon. It needs to know which data is sensitive and what should happen when that data moves.

In simple terms, DSPM establishes visibility and context. DLP applies rules based on that knowledge. CSPM helps secure the cloud environment in which some of the data may reside.

 

The Data Perimeter Has Disappeared

The need for that visibility has grown because data no longer stays within a predictable boundary.

Remote work is an easy example. An employee may be working from home on a company laptop that contains or can reach sensitive information. The organization may need to ensure that opening a particular file requires multifactor authentication, or that the file cannot be uploaded to an unapproved service.

Cloud and SaaS applications create the same challenge. Every new service depends on data, and each one creates another place where information may be stored, processed, or shared. Even when a service is approved by IT, the organization still needs to understand what information is flowing into it and what protections apply there.

AI makes the issue more urgent, but it does not create an entirely new problem. It just accelerates a problem we already had.

Organizations are encouraging employees to use AI to work faster and become more efficient. At the same time, employees are often expected to decide for themselves which information is safe to provide to those tools. That is not a realistic security model. Individual users cannot be solely responsible for recognizing every sensitive element in every document, especially when the business is actively encouraging adoption.

Leadership must establish the policy. Security and IT teams must provide enforceable guardrails. DSPM provides the visibility those guardrails require.

 

You May Already Own Part of the Answer

The good news is that many organizations may already own tools capable of contributing to this strategy.

Modern endpoint, firewall, secure access, and cloud security platforms increasingly include data discovery, classification, inspection, or enforcement capabilities. Sometimes those capabilities are included; sometimes they are available as an additional module. Either way, the first question does not always have to be, “What new product should we buy?”

A better question may be, “What can our existing environment already see and enforce?”

Having a capability and implementing it successfully, however, are two different things. For example, inspecting encrypted traffic can allow an organization to identify sensitive data while it is moving and stop an inappropriate transaction. Turning on that inspection can also introduce privacy, compliance, application, and operational considerations. What looks like a checkbox in a product interface may require planning and coordination across several business units.

That is another reason to begin with visibility. DSPM should not mean turning on every possible control at once. It should help the organization understand its exposure, identify its most important data, and make deliberate decisions about which protections are justified.

 

Start with What You Need to Know

No organization can eliminate every risk or protect every piece of information in exactly the same way. The objective is not perfection. It is clarity.

Start by identifying the data that would create the greatest business, legal, financial, or reputational consequence if it were exposed. Determine where that information lives today—not where the policy

says it should live. Understand which people, systems, and services can reach it. Then evaluate whether the controls already in place match the value and sensitivity of the data.

That sequence matters. Discover first. Classify second. Enforce based on what you learn.

Without that foundation, organizations are left applying security controls to an incomplete picture. With it, they can make better decisions about access, data loss prevention, cloud configuration, AI use, and the technologies they may already own. For now, the most important place to begin is also the simplest:

You cannot protect data you cannot see.

 

Ready to Understand Your Data Exposure?

Prescriptive can help you evaluate where sensitive data lives, how it moves, and which practical controls fit your organization. If you are ready to make data risk visible and take a more deliberate approach to protecting it, contact us. We'd welcome the opportunity to help.