DSPM Beyond Discovery: Protect Data After It Moves

DSPM Beyond Discovery: Protect Data After It Moves

September 25, 2026 / in Blog / by Zafar Khan, RPost CEO

DSPM Finds the Data, But What Happens When the Document Travels?

Rocky the Raptor here, RPost’s cybersecurity product evangelist. I noticed something interesting in conversations with CISOs at the recent Gartner Security & Risk Management Summit in London this week: everyone has plenty of security tools, but the questions are increasingly about the data itself. Where is it? Who can actually access it? What can AI read? Where has it been copied? And perhaps most importantly, what control remains once that data begins moving?

The Gartner summit brought together more than 2,500 CISOs and cybersecurity leaders, and the agenda reflected how quickly AI, identity, infrastructure, and data security are colliding. Data Security Posture Management, or DSPM, was part of that conversation because enterprises are discovering that knowing their systems are secure is not the same thing as knowing their data is secure.

That distinction may sound small, but it isn't. Your infrastructure can be secure while your data is still overexposed.

For years, enterprise security teams became very good at securing infrastructure. They hardened networks, configured cloud environments, deployed identity controls, installed DLP mechanisms, monitored endpoints, and built policies around who should have access to what.

Then the data went everywhere. A confidential board presentation lands in Microsoft 365, a contract gets copied into a shared drive, someone creates an external sharing link and forgets about it, an employee downloads a customer document to work remotely, while another uploads part of it into a personal AI tool for a quick summary.

Each action may be reasonable on its own. Collectively, they create a difficult question for CISOs: Who can actually get to the sensitive information now? That is the problem DSPM is attempting to solve. DSPM discovers and classifies data, examines who can access it, and helps organizations understand where sensitive information may be overexposed. The cloud bucket may be configured correctly, but the confidential document inside it might still be accessible to hundreds of people.

AI Just Made the Data Problem Much Bigger

This is where the London conversations got especially interesting. AI security is often discussed as though the main issue is securing the AI model. But from the CISO's perch — err... chair, excuse my Raptor pun 😊 — one of the more immediate questions is what the AI can see.

An employee can upload sensitive contracts, presentations, customer records, financial information, and other enterprise data to enhance efficiencies that can be used by the LLM models to turn into something useful in seconds. An AI agent connected to enterprise repositories can do the same thing at machine speed. Yesterday's messy file permissions can quickly become tomorrow's AI permissions. So, the conversation increasingly becomes one of data visibility and control.

A document might contain customer PII, intellectual property, pricing, acquisition plans, legal strategy, medical information, or credentials. The filename may tell you almost nothing. The content tells you everything.

Modern DSPM therefore focuses not just on locating information, but on understanding its context: what it contains, how sensitive it is, where it resides, who or what can reach it, and how exposed it is. That matters particularly with unstructured data because documents get duplicated, renamed, downloaded, emailed, forwarded, uploaded, and forgotten. But attackers and AI agents don't forget.

The Permission You Assigned Isn't Always the Access You Actually Have

Enterprise permissions rarely stay simple. Suppose Sarah isn't directly permitted to access a confidential acquisition folder. But she belongs to a regional group, that group belongs to another group, and that group inherited permissions from a collaboration workspace. Someone may also have created a broad sharing rule six months ago.

Can Sarah read the document? The policy may say no. The effective access path may say yes. This is why discovery, classification, and access analysis belong together. DLP remains valuable for detecting or stopping information as it crosses particular boundaries, but DSPM asks a different set of questions:

  • Where is the sensitive information?
  • Who or what can access it?
  • Where is it overexposed?
  • Which exposure matters most?

And this leads to the part of the DSPM discussion that deserves more attention: discovery is only half of the document security problem.

Imagine DSPM identifies a highly sensitive financial presentation inside an enterprise repository. It is correctly classified, permissions have been cleaned up, and excessive access has been removed. Problem solved? Only until somebody legitimately needs to send that presentation to the board, an auditor, outside counsel, or an investment adviser. Now the information starts moving again.

DSPM is tremendously useful for understanding the security posture of data where it resides. But CISOs should also be asking: What happens to that security posture after the document is distributed? Document security becomes much more interesting here.

The Next Step Is Data Security That Travels with the Document

Document security shouldn't end at discovering, classifying, and remediating information.

For highly sensitive documents, the model needs to extend to discover, classify, control, observe, and respond. That means thinking about reader restrictions, time-based access, geographic or domain controls, identity markings, usage visibility, and the ability to change or revoke future viewing after distribution.

And then comes the cybersecurity question: is someone reconnoitring the document? Document security here intersects with another trend we've been talking about at RPost: preemptive cybersecurity. 

An attacker doesn't always steal information and immediately commit fraud. Sometimes the information is reconnaissance. Access to contracts, invoices, names, relationships, transaction details, and communication patterns creates context. And context makes the next impersonation lure more believable. It can tell an attacker who pays whom, which deal is closing, and which executive is travelling. So, protecting documents isn't only about protecting what is inside them; it’s also about denying an attacker the intelligence needed for the next attack.

Where RPost Fits into This Conversation

This is where I'll finally bring Rocky's talons back to home turf. We're not trying to replace the enterprise's entire DSPM stack. The interesting opportunity is what happens after sensitive information has been identified and needs to move.

With RDocs™, organizations can convert sensitive documents into RPD™ Rights Protected Documents designed to maintain selected access controls after distribution. Depending on the policies applied, organizations can restrict readers, limit access by time, domain, network, or geography, apply visible and covert reader-identification markings, monitor activity, and change supported access settings or revoke future viewing after distribution.

And when document access begins to look suspicious, RDocs AI Auto-Lock™ adds response to the mix. It can react to activity identified as suspicious by locking further access, notifying the document owner, and allowing the owner to decide whether access should be restored or remain restricted.

That changes the security question from: “Where is my sensitive data?” to “Who is interacting with it now, does that activity make sense, and can I still do something about it?”

That may be where the DSPM conversation goes next. Because discovering risk is enormously valuable. But when the sensitive document has already left the building, discovery isn't the end of the security problem.

For me — Rocky the Raptor — that's where things get interesting...