DSPM

DSPM stages and why copied data creates exposure

Your production database is well protected. DSPM is about the eleven copies of it that are not.

  • Glossary
  • Data

The short answer

DSPM stands for data security posture management. It finds sensitive data wherever it actually lives across cloud accounts and stores, classifies what it finds, maps who can reach it, and ranks the resulting exposure. Where other tools secure the infrastructure holding data, DSPM starts from the data itself and works outwards.

That reversal is the whole idea. Most security controls are applied to systems somebody deliberately built. Sensitive data ends up in places nobody deliberately built.

The four questions DSPM answers

Where is it? Scan stores, buckets, snapshots, warehouses What is it? Personal, payment, health, credentials Who can reach it? Roles, keys, links, public exposure What first? Sensitivity crossed with exposure The third question is the one that produces action. A sensitive store nobody can reach is a low priority. A moderately sensitive one open to every employee is not.

Copies are the problem

Nobody loses control of the production database. They lose control of what was made from it.

Where the copy livesHow it got there
Analytics warehouseA pipeline replicates production so the data team can query without touching live systems
Development seed dataA production dump loaded into a test environment because synthetic data was too slow to build
Backups and snapshotsRetained for recovery, often for longer than the retention policy on the original
Exports and reportsA CSV pulled for a board deck and left in shared storage
Model training setsReal records used to train or evaluate a model, then kept in case the experiment is repeated
Abandoned migrationsThe old store from a platform change nobody decommissioned

The controls stayed with the original

Each of those copies is the same data, but the encryption standard, the access policy, the retention rule and the audit logging were configured on the source. A snapshot inherits storage-level protection at best. The copy in the test environment is frequently readable by every engineer, which is how a company with a genuinely well-secured production database still suffers a personal data breach.

DSPM, CSPM and DLP

DSPMCSPMDLP
Starts fromThe dataThe infrastructureThe exit point
Core questionWhere is sensitive data and who can reach it?Is this cloud resource configured safely?Should this leave right now?
State of the dataAt restNot its concernIn motion
Finds unknown storesYes, that is the purposeOnly misconfiguration in known accountsNo
Typical outputAn inventory of sensitive data with access pathsA list of misconfigurationsA blocked or allowed transfer

They answer different questions and most teams need more than one. CSPM tells you a bucket is public. DSPM tells you that bucket contains customer records, which is what turns a configuration finding into a priority.

Why regulators care

Data protection law is built on an assumption that is quietly demanding: that you know what personal data you hold and where.

ObligationWhat it assumes you can do
GDPR records of processingDescribe categories of data, purposes and recipients, which requires knowing where the data sits
Data subject requestsFind every copy of one person’s data, including in the analytics warehouse and the backup
Retention and erasureDelete data when its purpose ends, which is impossible for stores you have not identified
DPDP Act safeguardsReasonable security over personal data, applied wherever that data actually is
PCI DSS scopingDefine the cardholder data environment accurately. An unknown store holding card data expands scope without anyone knowing
Breach notificationState what data was affected, within a deadline, which needs an inventory prepared in advance

Where Osto fits

Osto does not sell a standalone DSPM product, and this section is not going to pretend otherwise. What Osto covers is the layer of controls a DSPM finding would tell you to apply, and several of the paths by which data escapes in the first place.

Cloud security posture management surfaces the misconfigured storage and over-permissive policy that expose a store. Data loss prevention and device controls govern data leaving through endpoints. Encryption at rest, access management and role-based access control determine who can reach what. Access and storage events correlate in the same SIEM, so unusual reads against a sensitive store are visible alongside the identity that made them. If your requirement is a dedicated sensitive-data inventory across every warehouse and lake, that is a different category of product. If your requirement is to control and evidence access to the data you know you hold, that is what this stack does.

Platform walkthrough

Control the paths, not just the store

Cloud posture, access control, encryption and data loss prevention in one stack, with reads against sensitive stores correlated to the identity behind them. One owner, one dashboard.

Book a demo

Evidence from live controls · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is DSPM?

Data security posture management. It discovers sensitive data across cloud stores, classifies it, maps who can access it and prioritises the exposure. It starts from the data rather than from the infrastructure holding it.

What is the difference between DSPM and CSPM?

CSPM checks whether cloud resources are configured safely. DSPM asks where sensitive data sits and who can reach it. CSPM tells you a bucket is public. DSPM tells you it contains customer records, which is what makes the finding urgent.

What is shadow data?

Copies of sensitive data in places nobody is tracking: analytics replicas, development seed dumps, old snapshots, exported reports, model training sets and abandoned migrations. The controls were configured on the original, not on the copy.

Do small companies need DSPM?

Usually not as a dedicated product at an early stage, when the data estate is small enough to reason about. The underlying discipline matters immediately though, because a single production dump in a test environment creates the same exposure at any company size.

Does DSPM replace DLP?

No. DLP governs data in motion at the point it might leave. DSPM governs data at rest and the access paths to it. They cover different halves of the same concern.