Cloud transformation has reached a new stage of maturity in most organizations. Critical applications now span multiple cloud providers, while employees rely on hundreds of SaaS services, and valuable information continues to reside in data centers, branch offices and edge environments.
Yet, artificial intelligence (AI) is accelerating the creation, movement and consumption of data across these environments.
This has created a paradox. Organizations have more visibility into infrastructure than ever before, yet many struggle to answer a seemingly simple question: Where does our most important data live?
For security leaders, the challenge is no longer limited to securing cloud platforms. Rather, it is understanding, governing and protecting data as it moves across increasingly complex digital ecosystems. In this context, data discovery, classification and Data Security Posture Management (DSPM) are emerging as foundational capabilities for cyber resilience.
The shifting data landscape
The traditional security model assumed critical data resided in a limited number of controlled environments, but that no longer holds true.
Today, sensitive information may exist simultaneously across public cloud platforms, SaaS applications, collaboration tools, development environments, backup repositories, AI services and on-premises infrastructure. Business units often adopt new services independently, while mergers, acquisitions and digital transformation programs introduce additional complexity.
Industry research reflects this reality. Cloud Security Alliance’s State of AI and Cloud Security Survey Report 2025 reports that most organizations now operate across multiple cloud providers while maintaining hybrid environments. As a result, data is increasingly distributed across different platforms, ownership models and operational teams. The challenge is not simply the volume of data. It is the loss of visibility that accompanies its distribution.
Organizations cannot effectively protect information they cannot see, classify or understand. Yet many security programs still focus primarily on infrastructure, networks, and endpoints rather than the data itself.
Visibility: The new security perimeter
For years, identity has been described as the new perimeter. While identity remains critical, data visibility is rapidly becoming an equally important control point. Security teams frequently discover that they lack a complete inventory of sensitive information.
Now data may be duplicated across cloud storage repositories, embedded within SaaS platforms, exposed through development pipelines, or retained long after business requirements have expired. This creates several risks, such as those illustrated below:
- Security teams struggle to assess exposure accurately. A misconfigured storage bucket containing public marketing material represents a very different risk than one containing customer records or intellectual property.
- Compliance obligations become more difficult to manage. Regulatory frameworks increasingly require organizations to demonstrate where sensitive information resides, who has access to it, and how it is protected.
- Incident response becomes slower and less effective. When an event occurs, leaders need immediate answers about which data has been affected and what business impact may follow. Without data visibility, these questions become difficult to answer.
This is where data discovery and classification become essential.
Turn data into actionable insights
Data discovery helps organizations to locate information across cloud, SaaS and on-premises environments. Classification adds context by identifying the sensitivity, business value and regulatory relevance of that information.
Together, these capabilities transform data from an unknown asset into a manageable one.
Leading organizations increasingly view discovery and classification as continuous processes rather than periodic exercises. While new data is created every day, existing data moves between platforms, and business priorities evolve constantly. This renders static inventories quickly outdated.
Modern approaches therefore focus on continuous monitoring and automated classification, enabling organizations to maintain an up-to-date understanding of their data landscape. The objective is not merely to create a catalog but to establish a reliable foundation for risk-based decision making.
Data Security Posture Management (DSPM): Highlighting data risk
As cloud adoption expanded, security teams developed capabilities such as Cloud Security Posture Management (CSPM) to identify infrastructure misconfigurations. More recently, Cloud-Native Application Protection Platforms (CNAPP) have emerged to provide broader visibility across cloud workloads, identities and runtime environments.
Yet a critical question still remained unanswered: Which risks matter most to the organization’s data?
Data Security Posture Management addresses this gap.
According to Gartner’s, Market Guide for Data Security Posture Management (2025), DSPM helps organizations discover, classify, catalog and assess exposure of data across distributed environments. Rather than focusing solely on infrastructure vulnerabilities, DSPM focuses on the information itself.
This shift is significant.
A security team may identify thousands of cloud alerts in any given week. However, only a small subset may involve systems containing highly sensitive or business-critical information. DSPM helps organizations prioritize risks by connecting security findings directly to the data they could impact.
The result is a more effective allocation of resources and a stronger alignment between cybersecurity activities and business priorities.
Beyond the cloud: A unified data protection approach
One of the most important lessons emerging from recent years is that data protection cannot be approached through isolated technology domains.
Organizations often manage cloud security, SaaS security, data governance, compliance, identity management and backup operations as separate disciplines. While each remains important, effective protection depends on how these functions work together.
Typically, a unified approach combines several core capabilities, as follows:
- Continuous data discovery and classification across all environments
- Identity and access governance to ensure appropriate access to sensitive information
- Encryption and key management aligned with business and regulatory requirements
- Data loss prevention and monitoring capabilities to provide ongoing visibility into data movement
- Resilient backup and recovery strategies designed to support cyber recovery and operational continuity
- Consistent governance policies applied across cloud, SaaS and on-premises platforms
The goal is not technological uniformity; different environments will continue to require different tools and operational models. Rather, the objective is consistent visibility and control regardless of where data resides.
How a data-first security approach impacts organizations
The most successful organizations are those that treat data protection as a governance challenge rather than a purely technical one. Decisions about data ownership, classification standards, retention policies, third-party relationships and AI usage all influence cybersecurity outcomes. This requires closer collaboration between security teams, data governance functions, legal and compliance stakeholders, cloud platform teams and business leaders.
It also changes the questions leaders should ask.
Instead of focusing exclusively on how many vulnerabilities have been remediated or how many alerts have been investigated, organizations should look to answer questions such as:
- Do we know where our most critical data resides?
- Can we identify who has access to it?
- Can we detect when it becomes exposed?
- Can we demonstrate compliance requirements consistently across environments?
- Can we recover critical information quickly following a cyber incident?
These questions provide a more meaningful measure of resilience than infrastructure metrics alone.
Become a game-changer in digital transformation
The next phase of digital transformation will be shaped by artificial intelligence, increasing regulatory expectations and continued expansion of multi-cloud ecosystems. Each of these trends will amplify the importance of understanding and governing data.
The organizations that succeed will not necessarily be those with the largest security budgets or the most extensive technology portfolios. They will be the organizations that develop a clear understanding of their information assets and establish consistent controls around them.
In a world where data exists everywhere, visibility becomes the foundation of trust.
The question for security leaders is therefore not whether they have invested in cloud security, governance or resilience. The key question is far simpler:
Do you know where your most important data lives?
Adam Rusin
Product Director Hybrid Cloud, Data and Application Security, Atos
View detailsof Adam Rusin >Raul Salagean
Global Deputy Product Director for Cloud & Application Security, Atos
View detailsof Raul Salagean >


