Key Takeaways
- Legacy DLP was built to watch a defined perimeter, but most sensitive data no longer lives behind one. Now, it moves across SaaS platforms, cloud data stores, and AI pipelines, which those tools were never built to see.
- Nearly 60% of leaders say they have less visibility into where their data resides today, as multicloud and SaaS environments grow.
- Data Security Posture Management (DSPM) is a continuous, automated way to find sensitive data wherever it lives, map who can access it, and flag how exposed it is, across cloud, SaaS, and AI pipelines.
- Poor visibility directly limits recovery. Among organizations hit by ransomware, only 10% recovered more than 90% of their data.
- AI raises the stakes. AI-generated attacks are now seen as the top threat to data, ahead of ransomware (66% to 50%), and every model is a new place for sensitive data to end up unmonitored.
Executives don’t lose sleep over antivirus updates. Instead, they’re kept awake over the next headline: A breach that erases a quarter’s earnings, a regulator’s inquiry, or a board asking why nobody saw it coming.
Veeam’s own research shows that even if a leader feels confident in their organization’s recovery… that confidence does not always equal proven resilience. In Veeam’s Data Trust and Resilience Report 2026, 90% of security leaders said they were confident they could recover within defined RTOs, but only 69% said those targets fully align with business continuity needs. Nearly 3 in 10 organizations experienced a cyber incident in the past year that caused data loss, downtime, or business disruption — and among those, 41% reported financial loss or revenue impact. Ransomware exposes the gap even more sharply: only 28% of affected organizations fully recovered all impacted data.
If your data protection strategy still assumes a tidy, single-location data center, it’s already behind where the risk actually lives. Legacy data loss prevention (DLP) was built for that tidy world. It watches endpoints and networks for data leaving a defined perimeter, which is a model that made sense when most sensitive data sat on company-owned servers. It makes far less sense now.
In Veeam’s survey of senior IT and business decision-makers, nearly 60% said they have less visibility into where their data resides today, which is a direct consequence of the growth of multicloud and SaaS environments. Today, data moves constantly between SaaS platforms, cloud data lakes, and warehouses that legacy DLP was never built to see.
The gap shows up in two ways. First, visibility: Endpoint and network tools can’t inspect what’s sitting inside a cloud data store, who can access it, or whether it’s misconfigured. Second, accuracy: Older classification methods rely heavily on pattern matching that wasn’t built for how enterprises use data today. That shows up as noise, too many false alarms, and, worse, real exposure that never gets flagged. The cost of that gap is revealed in the numbers, too. Veeam’s 2025 Ransomware Trends report found that, among organizations hit by an attack last year, only 10% recovered more than 90% of their data, and 57% recovered less than half. Poor visibility into where sensitive data lives doesn’t just raise risk. It directly limits how much of it you get back.
AI is raising the stakes further. For the first time, Veeam’s IT leadership survey found AI-generated attacks are seen as the greatest threat to data security, ahead of ransomware, 66% to 50%. Compliance pressure is following close behind: Data sovereignty is now rated extremely or moderately important by 76% of leaders, reshaping cloud strategy at the same time AI is reshaping the threat landscape. Feeding a model doesn’t just create a new workflow. It creates a new place for sensitive data to end up unmonitored.
None of this means your security team failed. It means the map changed faster than the tools built to read it. That gap is what Data Security Posture Management, or DSPM, was built to close. DSPM is a continuous, automated way to find sensitive data wherever it lives, map who can access it, and flag how exposed it is, across every cloud, SaaS platform, and AI pipeline your business runs on. Where legacy DLP watches a perimeter, DSPM follows the data. Securiti, now part of Veeam, helped pioneer the category, and the shift it represents, from reacting to data loss to understanding data risk before it becomes a headline, is one every leadership team will need to make.
The question worth bringing to your next security review isn’t whether your DLP tools are working. It’s whether they can even see the risk you’re actually carrying.
Sources:
Whitepaper: Think Beyond Data Classification: Unlock Contextual Data + AI Intelligence
Guide: The DSPM Architect’s Handbook
Analyst Whitepaper: Enterprise AI Readiness: Data Controls and Recovery for AI Agents
FAQs
DSPM is a continuous, automated approach to finding sensitive data wherever it lives, mapping who can access it, and flagging how exposed it is, across every cloud, SaaS platform, and AI pipeline an organization runs on. It shifts data security from reacting to data loss toward understanding data risk before it becomes an incident.
DLP watches a defined perimeter for data leaving endpoints and networks. DSPM discovers where sensitive data lives across your environment and assesses its posture: who and what can access it, whether it’s misconfigured, and how exposed it is to risks. DLP asks whether data is leaving; DSPM asks where sensitive data lives and whether it is at risk in the first place.
Legacy DLP was built for a world where most sensitive data sat on company-owned servers behind a clear perimeter. That perimeter has dissolved. With nearly 60% of leaders reporting reduced visibility into where their data resides, endpoint and network tools can no longer see what sits inside a cloud data store, who can access it, or whether it is misconfigured.
Feeding data to an AI model creates a new place for sensitive information to end up unmonitored. DSPM extends visibility into AI systems , showing what data feeds a model, who and what can reach it, and where it is exposed, so AI adoption does not outpace the controls meant to govern it.
You cannot fully protect or recover data you cannot see. Among organizations hit by ransomware, only 10% recovered more than 90% of their data and 57% recovered less than half. Knowing where sensitive data lives is a direct input to how much of it you get back.