Megatrend · Cybersecurity & Digital Trust

You can't protect what you can't see — so where is your company's secret data right now?

Almost every company knows it has "secret data" — customer lists, card numbers, secret recipes, source code. But ask where exactly it lives and who can get to it, and the answer is usually silence. That's because the data is scattered everywhere: a cloud bucket everyone forgot about, copies in someone's personal Google Drive, a test database full of real data, and lately — in the ChatGPT prompt box employees paste into every day. This node is the two-layer technology that fixes this: DSPM goes out and finds and classifies the secret data in every nook and cranny, and shows who can touch it; DLP then keeps it from leaking out.

Category Cybersecurity Level Specific topic Layer platform Read time ~12 min
A huge map dotted with glowing points of secret data scattered everywhere — on clouds, in drawers, and in the shadows — while a beam from a scanner slowly sweeps across, finding and marking each one.
ภาพประกอบ (hero.webp)
Before you can protect it, you have to find it. A company's secret data is scattered across the cloud, apps, and personal devices — DSPM's first job is to "shine a light" and find all of it.

01What it is — protecting the data itself, not just the wall

Most of the IT security we're used to is about building a wall — firewalls, passwords, checking a device before it joins the network. All of it protects the path and the door. But there's one question a wall can't answer: if an attacker, or a careless employee, has already walked in — then where are the "valuables," and are they locked up well enough? This node is security that turns to face the data itself, directly, instead of just the wall around it.

It's made of two pieces that work together as a loop. The first is DSPM (Data Security Posture Management) — a tool that goes out and finds the data everywhere a company keeps it (AWS/Azure clouds, SaaS apps like Salesforce, databases, file shares), then classifies which of it is secret (credit-card numbers, health data, trade secrets), and tells you who can access it and where it's "wide open" more than it needs to be. The second is DLP (Data Loss Prevention) — the checkpoint that stops secret data from flowing out of the company, whether by email, USB, upload, or a paste into an AI chat box.

An easy way to remember it: DSPM = the treasure map (you know where the valuables are and who holds the keys) · DLP = the guard at the gate (nothing valuable leaves without permission). On the megatrend map, this node is a sub-theme under Data Security & Cyber Resilience within the big trend Cybersecurity & Digital Trust, with a sibling right next to it: Cyber Resilience & Ransomware Recovery — if this node is the "keep the data from leaking" side, that sibling is the "get it back after you've been hit" side.

Key terms
DSPM · DLP · Shadow Data

DSPM = managing your data's "security posture" — finding, classifying, and assessing the risk of data across the cloud · DLP = preventing data leaks — detecting and blocking data as it's about to leave the organization · Shadow Data = secret data "nobody knows exists" — forgotten copies, test databases loaded with real data, files uploaded to apps IT doesn't even know about. The number-one cause of data leaks.

02Why it matters — the expensive stuff you can't find

Start with the fact that keeps security people up at night: of the data companies keep in the cloud, about 54% is considered sensitive — yet fewer than 10% of companies encrypt more than 80% of the secret data they hold. In plain terms, valuables are everywhere, but most of them aren't locked up well — and worse, companies often don't even know where they are. This is the source of the line at the heart of the whole node: "you can't protect what you can't see."

The reason data "disappears" into the dark is data sprawl — data multiplying faster than anyone can keep up. Every time a team spins up a new SaaS app, copies a database to test on, or an employee saves a file to a personal drive, another "shadow copy" is born somewhere new. Surveys find that 56% of organizations have employees uploading secret data to apps IT never approved, and about 65% of the SaaS apps in use across organizations went through no approval at all. Every copy nobody knows about = a door left open.

Lots of valuables, but hardly any locked up
The share of cloud data that's secret, versus companies that encrypt more than 80% of their secret data
Source: Thales/Skyhigh cloud security data (2025); estimates
A single secret document slowly splitting into a flood of copies that drift everywhere — onto clouds, into drawers, and into the unwatched shadows.
ภาพประกอบ (sprawl.webp)
One becomes a thousand. Data sprawl is when a single piece of secret data multiplies into countless shadow copies — and every copy nobody knows about is a door left open.

And if it really is lost, what does it cost? In 2025, the average cost of a data breach was $4.44 million per incident worldwide, and in the U.S. it hit an all-time record of $10.22 million per incident. That number isn't just fines — it includes investigation costs, business downtime, lost customers, and vanished trust. So for executives, DSPM/DLP isn't "an IT luxury" — it's a tangible reduction in financial risk.

$10.22M the average cost of a single data breach in the U.S. in 2025 — an all-time record, while the global average sits at $4.44 million. This is the "price" of not being able to see where your secret data is.

Economically, this is big because it touches every company that holds customer data — not just banks and hospitals. Privacy laws (GDPR in Europe, various state laws in the U.S., PDPA in Thailand) require companies to know whose personal data they're storing and where, or face fines. DSPM has become the tool that makes "complying with the law" actually possible, instead of just filling out paperwork.

03How it works (find → classify → check access → stop)

The whole node runs as a conveyor belt of four continuous steps. The first three are DSPM (knowing your own data); the last is DLP (keeping it from leaving). Let's look at the whole belt.

The four-step conveyor belt of DSPM and DLP From left to right: step one, search for data across the cloud. Step two, classify what's secret. Step three, see who can access it and where the risks are. Step four is the DLP checkpoint that stops data as it's about to leak out via email, USB, upload, or an AI chat box. 1 Find Cloud · SaaS · databases 2 Classify Secret Cards · health · secret recipes 3 Check access Who can touch it · wide-open spots 4 Stop (DLP) Email · USB · upload · AI Outside the org
Four steps that link into a loop. The first three (DSPM) let a company "see" its secret data and the risk around it; the last step (DLP) is the checkpoint that only lets the safe stuff out — every leak path, email, USB, and AI chat box, has to pass through it first.

The reason this order matters is that DLP without DSPM in front of it is usually "blind" — it can only block what it's been told about. If nobody finds the test database hiding real data, DLP can't protect it. This is why the whole industry brought the two together: find it first (DSPM), then post a guard (DLP) on what you found — and because data is always changing, this belt isn't a one-and-done; it loops continuously.

04How it connects in the ecosystem

This node doesn't work alone. It's a "data layer" that ties several areas of security together.

  • Inseparable from Identity Governance (IGA): DSPM answers "where is the secret data," while IGA answers "who should be able to access what" — only by overlaying the two do you see the real danger spots, like "an employee who left but can still reach the customer database." Cutting excess privileges (least privilege) needs both
  • The flip side of its sibling Cyber Resilience & Ransomware Recovery: this node is the "keep the data from leaking out" side, while that sibling is the "get the data back after it's been encrypted for ransom" side — prevention vs. recovery, two faces of the same coin that an organization needs both of
  • Accelerated and challenged by AI at the same time: AI lets employees paste secret data into ChatGPT in one click (a new leak path), but AI also classifies data far more accurately and quickly — it's both the problem and the tool to fix it, in one
  • A foundation for Cloud Infrastructure: organizations will only dare move important data onto multiple clouds when they have a way to "see" and control data across them — DSPM is what keeps multi-cloud from becoming a blind spot
Perspective If Endpoint & Network Security guards the "path and the door" — this node guards the "treasure itself" directly. The two layers complement each other: even if an attacker breaks through the wall, if the secret data has been found, classified, and locked up well, the damage stays contained. This is the "assume breach" mindset that makes data security the last, indispensable checkpoint.

05Where it stands now

The hottest thing about this node right now is the GenAI leak path. Employees today use an average of more than 66 AI apps per organization, and every time they paste customer data, source code, or a financial model into a prompt box, the data leaves the company — in a way old-school DLP (built to catch "files") can't see. The famous case is the Samsung employee who pasted secret source code into ChatGPT, prompting the company to ban it instantly. So newer DLP has moved to catch things at the browser layer — catching it the moment an employee hits "paste," before the text even reaches the AI.

+$670K the added breach cost when a data breach involves "shadow AI" (employees secretly using AI without approval) — a factor in 20% of all breaches, and 97% of organizations breached through AI admit they didn't have good enough access controls on AI.

On the player side, the field splits clearly into three camps. The first is the data specialists (pure-plays), led by Varonis, which has worked on "who can access which data" for over a decade and just finished reinventing itself as a full cloud service — subscription revenue (SaaS ARR) reached ~86% of all recurring revenue by the end of 2025. The second is the platform giants — Microsoft bundles DSPM/DLP into its Purview suite, thrown in with Microsoft 365 (its weapon is a massive customer base), while Zscaler and Palo Alto Networks fold data protection into the security checkpoints they already run.

The third is the wave of DSPM startups, so hot they're being snapped up by the giants across the board: Google poured $32 billion into Wiz (which has its own data-security layer), Rubrik bought Laminar, and Veeam spent $1.725 billion on Securiti. The standout still going it alone is Cyera, whose valuation jumped from $3 billion to ~$12 billion in under two years — a sign that investment money believes this is one of the fastest-growing fields in security.

DSPM is small but rocketing — DLP is big and growing steadily
Market size (in billions of dollars) — 2030/2031 are estimates, the median across several firms
Source: MarketsandMarkets/Grand View (DSPM, CAGR ~38%); Mordor Intelligence (DLP, CAGR ~21%); wide-range estimates

The big picture: DSPM is still a "small but very fast-growing" market (from a base of about $2 billion in 2025, expected to grow at high-double-digit rates a year), while DLP is a bigger, steadier-growing market (from ~$43 billion in 2026 to about $112 billion by early next decade) — and the clear trend is that the two markets are merging into a single platform.

Key players in this field
Varonis SystemsVRNS · US
United States · data specialist
A data-security pure-play that's worked on "who can access which data" for over a decade — and just finished reinventing itself as a full cloud service. Subscription revenue (SaaS ARR) reached ~86% of all recurring revenue by the end of 2025, and it's expanding into controlling the data fed to AI.
core · data-security pure-play
Microsoft (Purview)MSFT · US
United States · platform giant
Bundles DSPM and DLP into its Purview suite, thrown in with Microsoft 365 — its weapon is a massive enterprise customer base and the fact that most data already lives in its own systems (email, files, Teams), letting it "see" data more broadly than anyone.
core · platform giant
ZscalerZS · US
United States · zero-trust + DLP
Folds data protection (DLP) into the cloud security checkpoint it already runs — since everyone's traffic already passes through it, it's a spot that can catch leaks comprehensively, including the GenAI leak path at the network layer.
core · SSE + data protection
Palo Alto NetworksPANW · US
United States · unified platform
Folds DSPM/DLP into its own large security platform (partly through acquiring data-focused companies) — playing the "everything in one place" game so customers don't have to bolt together several brands.
core · platformization
RubrikRBRK · US
United States · data + recovery
Started with data backup and recovery, then expanded into DSPM by acquiring Laminar — its edge is tying "preventing data leaks" to "recovering after ransomware" in one platform, covering both sides of the coin.
secondary · DSPM + recovery
NetskopeNTSK · US
United States · cloud-first DLP
An SSE leader strong in data protection (DLP) and controlling cloud-app usage — a top choice for organizations that put the most weight on stopping leaks through SaaS apps and the GenAI path.
core · cloud DLP
Cyeraprivate
United States/Israel · private standout
The hottest DSPM startup — the first to combine DSPM + DLP + identity into one platform. Its valuation jumped from $3 billion to ~$12 billion in under two years, reflecting investors' belief that this is the fastest-growing field (still a private company).
core · DSPM pure-play

06The road ahead

The first direction is merging into a single "data security platform." Customers are tired of bolting one brand's DSPM onto another brand's DLP. The winner will be whoever combines find–classify–check-access–stop into one platform. That's why Cyera advertises that it unites DSPM + DLP + identity, and why the giants are buying startups to fill in the missing pieces.

A shield made of data blueprints protects a learning machine brain, while a small hand tries to slip in a secret document but is filtered out.
ภาพประกอบ (ai-shield.webp)
Protecting the data you feed to AI. When a company takes its internal data to train its own AI models, a new question arises: "can the secret data leak out through the AI's answers?" — a new field that data security has to answer.

The second direction is data security built specifically for the AI era. When a company takes internal data to train or feed a model (RAG, fine-tuning), a new risk appears: secret data could "leak" out through the chatbot's own answers. DSPM is expanding its role to control which data the AI is allowed to see and to check that the model doesn't accidentally reveal secrets — this is set to become a pillar of AI security across the whole industry.

The third direction is AI making classification more accurate and cheaper. DSPM's biggest obstacle so far has been "misclassification" — flagging non-secret things as secret (false positives) until the team stops paying attention. Newer AI models understand the context of text far better, so they can tell a "real card number" from a "random number in a test document" more accurately — cutting the noise that used to be the biggest weakness.

07Challenges & risks

The first risk is data multiplying faster than the tools can keep up. Every new SaaS app, every AI project, every database copy creates a new "shadow" all the time. DSPM is a chase that never reaches the finish line — if an organization opens new data faster than the tool finds it, the gap stays open. This is why it has to be a continuous process, not a one-time project.

The second risk is false positives and team fatigue. If DLP blocks the wrong thing often enough that employees can't work, the organization will "turn it off" or set it so loose it's meaningless. A tool that gets in the way too much is a tool nobody ends up using — the balance between "actually preventing leaks" and "not blocking work" is the hardest problem in this field.

The third risk is consolidation and the giants' competition. When Microsoft throws Purview in with Microsoft 365 and Google buys Wiz, small specialist players get squeezed — they have to be far better to fight something customers already get "for free." For investors, this means a field with high acquisition prices and constant consolidation. The winner may not be whoever has the best technology, but whoever sits closest to the customer's data.

The bottom line for investors Data Security Posture & DLP is the "last checkpoint" that protects the treasure itself in an era where walls get breached as a matter of course — a fast-growing market driven by privacy laws, record-setting breach costs, and the GenAI wave. Three keys: (1) who can most completely combine find–classify–check-access–stop into one platform · (2) who can lock down the GenAI leak path first (browser + data security for AI) · (3) who can classify accurately enough that false positives are low enough for customers to actually use it — the real value lies in "a platform that sees all the data and that customers are locked into," more than in one standout feature.

In short: this node is about turning back to protect the data itself directly, after the industry spent decades building walls around it — finding where the valuables are, seeing who holds the keys, then posting a guard so it can't leak out. In a world where data is a company's most valuable asset, this is a security layer you can no longer do without.

Explore this theme — live data, stocks & news →