Microsoft has brought Data Security Posture Management — DSPM — into Purview, and it borrows a concept from the cloud-security world that data governance has badly needed: posture. The idea is simple and powerful. Instead of asking "are we compliant" as a yes/no box-tick, posture asks "where does our risk actually live right now, and how bad is it?" — and it answers with a map. For anyone who owns data risk and has been flying half-blind, that map is worth a great deal. I just want to be precise about what a map is and isn't, because the word "posture" invites a dangerous misreading.

What DSPM actually gives you

Let me translate the concept, because "Data Security Posture Management" is a mouthful that hides something genuinely useful. DSPM continuously answers the questions a data-risk owner should be able to answer at any moment and usually can't:

  • Where is our sensitive data? Not "where do we think it is" — where it actually is, including the copies that sprawled into places nobody catalogued. Sensitive data has a way of migrating into shared workspaces and exports, and DSPM goes looking for it.
  • Who can get to it? The gap between who should have access and who does is where most data incidents live. DSPM surfaces over-exposure — the sensitive dataset shared far more widely than anyone intended, the permissions that accreted over years.
  • What's our biggest risk right now? Rather than a flat list of a thousand findings, it prioritises — with Copilot assistance — so you can see the handful of things that actually matter instead of drowning in an undifferentiated report.

Put together, that's a genuine shift from point-in-time compliance to continuous risk visibility. Compliance tells you that you passed an audit on a Tuesday. Posture tells you, today, that a folder of sensitive customer data is shared with a group of two hundred people who shouldn't have it. The second is far more useful for actually not having a bad day, and I'm glad the data world is finally getting the posture concept that cloud security has had for years.

The misreading the word invites

And now the caution, which is the whole reason I'm writing rather than just cheering. "Posture management" sounds active. It sounds like defence. It is not. DSPM shows you the risk. It does not remove the risk. It is a map of where the danger is, and a map has never stopped anything from happening.

This matters because of a specific psychological trap. When you deploy a tool that continuously surfaces your data risk, it's easy to feel safer — the dashboard is green-ish, the tool is watching, someone must be handling it. But visibility is not protection. If DSPM shows you that a sensitive dataset is dangerously over-shared and nobody acts on that finding, you are not safer than you were before you had DSPM. You are arguably in a worse position, because now there's a record that you knew. Seen-and-ignored is a worse place to be, legally and ethically, than never-looked.

That's the thing to hold onto. The value of DSPM is entirely realised in the acting, not the seeing. The seeing is the easy, automatable part. The acting — going to the data owner, reducing the access, cleaning up the sprawl, making the call about what's acceptable — is human work that the tool surfaces but cannot do.

A posture tool is a smoke detector, not a sprinkler. It's one of the most useful things you can install — and it has never, once, put out a fire. That part is still on you.

How to use it so it's worth having

So the way to get real value from DSPM is to treat every finding as the start of a workflow, not the end of a worry. Concretely:

Wire it to action, not just to a dashboard. Decide, before you turn it on, who owns responding to a high-priority finding and how fast. Use the prioritisation to protect your team's attention — chase the handful of genuine exposures, not every theoretical one — but make sure the handful actually get chased and closed. And be disciplined about the psychology: resist the quiet comfort of the tool being installed. The dashboard being watched is worth nothing; the over-shared folder being un-shared is worth everything.

Used that way, DSPM is one of the more valuable additions Purview has had, because it finally gives data-risk owners the continuous, prioritised visibility that security teams have long taken for granted. It turns "I hope our sensitive data is okay" into "here are the three things about our sensitive data that need action this week" — and that's a genuine upgrade to how you manage risk.

The verdict

I'm enthusiastic about DSPM, with one asterisk I'd staple to the deployment plan. Bringing posture thinking to data is exactly right, and the visibility it provides is something most organisations sorely lack and badly need. Deploy it.

But deploy it understanding what you've bought: the best map of your data risk you've ever had, and not one inch of actual protection. The map is enormously valuable if it drives action and worthless — possibly worse than worthless — if it just makes everyone feel watched-over while the exposures it reveals sit untouched. DSPM reinvented how you see data risk. Whether it reduces your data risk is a decision that gets made after the dashboard loads, by a human who does something about what it shows. Make sure that human exists before you admire the map.