Megatrend · Cybersecurity & Digital Trust
You can't protect what you can't see — so where is your company's secret data right now?
Almost every company knows it has "secret data" — customer lists, card numbers, secret recipes, source code. But ask where exactly it lives and who can get to it, and the answer is usually silence. That's because the data is scattered everywhere: a cloud bucket everyone forgot about, copies in someone's personal Google Drive, a test database full of real data, and lately — in the ChatGPT prompt box employees paste into every day. This node is the two-layer technology that fixes this: DSPM goes out and finds and classifies the secret data in every nook and cranny, and shows who can touch it; DLP then keeps it from leaking out.
01What it is — protecting the data itself, not just the wall
Most of the IT security we're used to is about building a wall — firewalls, passwords, checking a device before it joins the network. All of it protects the path and the door. But there's one question a wall can't answer: if an attacker, or a careless employee, has already walked in — then where are the "valuables," and are they locked up well enough? This node is security that turns to face the data itself, directly, instead of just the wall around it.
It's made of two pieces that work together as a loop. The first is DSPM (Data Security Posture Management) — a tool that goes out and finds the data everywhere a company keeps it (AWS/Azure clouds, SaaS apps like Salesforce, databases, file shares), then classifies which of it is secret (credit-card numbers, health data, trade secrets), and tells you who can access it and where it's "wide open" more than it needs to be. The second is DLP (Data Loss Prevention) — the checkpoint that stops secret data from flowing out of the company, whether by email, USB, upload, or a paste into an AI chat box.
An easy way to remember it: DSPM = the treasure map (you know where the valuables are and who holds the keys) · DLP = the guard at the gate (nothing valuable leaves without permission). On the megatrend map, this node is a sub-theme under Data Security & Cyber Resilience within the big trend Cybersecurity & Digital Trust, with a sibling right next to it: Cyber Resilience & Ransomware Recovery — if this node is the "keep the data from leaking" side, that sibling is the "get it back after you've been hit" side.
DSPM = managing your data's "security posture" — finding, classifying, and assessing the risk of data across the cloud · DLP = preventing data leaks — detecting and blocking data as it's about to leave the organization · Shadow Data = secret data "nobody knows exists" — forgotten copies, test databases loaded with real data, files uploaded to apps IT doesn't even know about. The number-one cause of data leaks.
02Why it matters — the expensive stuff you can't find
Start with the fact that keeps security people up at night: of the data companies keep in the cloud, about 54% is considered sensitive — yet fewer than 10% of companies encrypt more than 80% of the secret data they hold. In plain terms, valuables are everywhere, but most of them aren't locked up well — and worse, companies often don't even know where they are. This is the source of the line at the heart of the whole node: "you can't protect what you can't see."
The reason data "disappears" into the dark is data sprawl — data multiplying faster than anyone can keep up. Every time a team spins up a new SaaS app, copies a database to test on, or an employee saves a file to a personal drive, another "shadow copy" is born somewhere new. Surveys find that 56% of organizations have employees uploading secret data to apps IT never approved, and about 65% of the SaaS apps in use across organizations went through no approval at all. Every copy nobody knows about = a door left open.
And if it really is lost, what does it cost? In 2025, the average cost of a data breach was $4.44 million per incident worldwide, and in the U.S. it hit an all-time record of $10.22 million per incident. That number isn't just fines — it includes investigation costs, business downtime, lost customers, and vanished trust. So for executives, DSPM/DLP isn't "an IT luxury" — it's a tangible reduction in financial risk.
Economically, this is big because it touches every company that holds customer data — not just banks and hospitals. Privacy laws (GDPR in Europe, various state laws in the U.S., PDPA in Thailand) require companies to know whose personal data they're storing and where, or face fines. DSPM has become the tool that makes "complying with the law" actually possible, instead of just filling out paperwork.
03How it works (find → classify → check access → stop)
The whole node runs as a conveyor belt of four continuous steps. The first three are DSPM (knowing your own data); the last is DLP (keeping it from leaving). Let's look at the whole belt.
The reason this order matters is that DLP without DSPM in front of it is usually "blind" — it can only block what it's been told about. If nobody finds the test database hiding real data, DLP can't protect it. This is why the whole industry brought the two together: find it first (DSPM), then post a guard (DLP) on what you found — and because data is always changing, this belt isn't a one-and-done; it loops continuously.
04How it connects in the ecosystem
This node doesn't work alone. It's a "data layer" that ties several areas of security together.
- Inseparable from Identity Governance (IGA): DSPM answers "where is the secret data," while IGA answers "who should be able to access what" — only by overlaying the two do you see the real danger spots, like "an employee who left but can still reach the customer database." Cutting excess privileges (least privilege) needs both
- The flip side of its sibling Cyber Resilience & Ransomware Recovery: this node is the "keep the data from leaking out" side, while that sibling is the "get the data back after it's been encrypted for ransom" side — prevention vs. recovery, two faces of the same coin that an organization needs both of
- Accelerated and challenged by AI at the same time: AI lets employees paste secret data into ChatGPT in one click (a new leak path), but AI also classifies data far more accurately and quickly — it's both the problem and the tool to fix it, in one
- A foundation for Cloud Infrastructure: organizations will only dare move important data onto multiple clouds when they have a way to "see" and control data across them — DSPM is what keeps multi-cloud from becoming a blind spot
05Where it stands now
The hottest thing about this node right now is the GenAI leak path. Employees today use an average of more than 66 AI apps per organization, and every time they paste customer data, source code, or a financial model into a prompt box, the data leaves the company — in a way old-school DLP (built to catch "files") can't see. The famous case is the Samsung employee who pasted secret source code into ChatGPT, prompting the company to ban it instantly. So newer DLP has moved to catch things at the browser layer — catching it the moment an employee hits "paste," before the text even reaches the AI.
On the player side, the field splits clearly into three camps. The first is the data specialists (pure-plays), led by Varonis, which has worked on "who can access which data" for over a decade and just finished reinventing itself as a full cloud service — subscription revenue (SaaS ARR) reached ~86% of all recurring revenue by the end of 2025. The second is the platform giants — Microsoft bundles DSPM/DLP into its Purview suite, thrown in with Microsoft 365 (its weapon is a massive customer base), while Zscaler and Palo Alto Networks fold data protection into the security checkpoints they already run.
The third is the wave of DSPM startups, so hot they're being snapped up by the giants across the board: Google poured $32 billion into Wiz (which has its own data-security layer), Rubrik bought Laminar, and Veeam spent $1.725 billion on Securiti. The standout still going it alone is Cyera, whose valuation jumped from $3 billion to ~$12 billion in under two years — a sign that investment money believes this is one of the fastest-growing fields in security.
The big picture: DSPM is still a "small but very fast-growing" market (from a base of about $2 billion in 2025, expected to grow at high-double-digit rates a year), while DLP is a bigger, steadier-growing market (from ~$43 billion in 2026 to about $112 billion by early next decade) — and the clear trend is that the two markets are merging into a single platform.
06The road ahead
The first direction is merging into a single "data security platform." Customers are tired of bolting one brand's DSPM onto another brand's DLP. The winner will be whoever combines find–classify–check-access–stop into one platform. That's why Cyera advertises that it unites DSPM + DLP + identity, and why the giants are buying startups to fill in the missing pieces.
The second direction is data security built specifically for the AI era. When a company takes internal data to train or feed a model (RAG, fine-tuning), a new risk appears: secret data could "leak" out through the chatbot's own answers. DSPM is expanding its role to control which data the AI is allowed to see and to check that the model doesn't accidentally reveal secrets — this is set to become a pillar of AI security across the whole industry.
The third direction is AI making classification more accurate and cheaper. DSPM's biggest obstacle so far has been "misclassification" — flagging non-secret things as secret (false positives) until the team stops paying attention. Newer AI models understand the context of text far better, so they can tell a "real card number" from a "random number in a test document" more accurately — cutting the noise that used to be the biggest weakness.
07Challenges & risks
The first risk is data multiplying faster than the tools can keep up. Every new SaaS app, every AI project, every database copy creates a new "shadow" all the time. DSPM is a chase that never reaches the finish line — if an organization opens new data faster than the tool finds it, the gap stays open. This is why it has to be a continuous process, not a one-time project.
The second risk is false positives and team fatigue. If DLP blocks the wrong thing often enough that employees can't work, the organization will "turn it off" or set it so loose it's meaningless. A tool that gets in the way too much is a tool nobody ends up using — the balance between "actually preventing leaks" and "not blocking work" is the hardest problem in this field.
The third risk is consolidation and the giants' competition. When Microsoft throws Purview in with Microsoft 365 and Google buys Wiz, small specialist players get squeezed — they have to be far better to fight something customers already get "for free." For investors, this means a field with high acquisition prices and constant consolidation. The winner may not be whoever has the best technology, but whoever sits closest to the customer's data.
In short: this node is about turning back to protect the data itself directly, after the industry spent decades building walls around it — finding where the valuables are, seeing who holds the keys, then posting a guard so it can't leak out. In a world where data is a company's most valuable asset, this is a security layer you can no longer do without.