Overview
Data Security Posture Management (DSPM) is an advanced approach to identifying, monitoring, and securing sensitive data across cloud and on-premises environments. Netskope DSPM (formerly known as Netskope One DSPM) automates data security and governance controls for structured, semi-structured, and unstructured data.
It provides granular visibility and control over your data infrastructure, attributes, users, and usage. You can locate sensitive data regardless of its location and flag critical issues that pose security or privacy risks. Use Netskope DSPM to remediate these risks seamlessly, automatically, and continuously.
To learn more see What is DSPM?.
On-Premises Classification
For on-premises and private-network data stores, Netskope DSPM provides local data classification to ensure that only the classification results, never the sensitive data itself, leave your network. Two deployment models are available:
- Single Appliance (Standard): Bundles both the DLP and sidecar services into one virtual machine. This is the recommended path for most customers. To learn more: Deploy the DSPM Single Appliance.
- Distributed Deployment (Advanced): Deploys sidecars and a DLP appliance separately for large-scale scanning scenarios that require independent scaling.
To learn more about how these models work: DSPM Architecture.
Data Infrastructure
Once onboarded, Netskope DSPM enables you to discover your inventory of data stores, including unknown (shadow) data stores and misconfigurations. For a complete list of compatible data stores, see DSPM Supported Data Stores. It offers visibility across cloud, self-managed, and hybrid environments to automatically discover:
- files throughout your organization’s data hierarchy
- data stores
- schemas
- tables
- fields
Data Attributes
Automatic classification and tagging streamline compliance efforts and allow you to focus on business-critical objectives. Netskope DSPM continuously classifies sensitive data to enable broad reporting and dashboarding capabilities. Key functions include:
- programmatic assignment of sensitivity levels
- application of business purpose tags
- mapping of data to specified regulations
Data Users
Netskope DSPM profiles data users across the organization to detect over-privileged access and risky data usage. This visibility exposes potential breaches and privacy violations, which enables your security and data teams to:
- identify areas that require stronger access controls
- mitigate security threats related to user privileges
- enforce the principle of least privilege
Data Usage
Netskope DSPM offers holistic data-in-use monitoring to continuously analyze user activity for risky behavior. It detects which users access specific data stores and identifies excessive privileges. This ensures that permissions remain secure and align with organizational policies.
Security and Governance Policies
A simple no-code policy engine enables your security and compliance teams to configure rules and workflows. These workflows cover shadow data discovery, misconfigurations, data classification, access violations, and monitoring.
When a violation occurs against data policies, the system immediately notifies the responsible security or governance teams. User behavior insights also reveal intentional or accidental data usage violations.
Integrations
Automated workflows streamline remediation processes to improve efficiency and collaboration across the organization. You can maintain your existing ecosystem by connecting to more than 50 out-of-the-box integrations supported by Netskope DSPM. Continuous auditing and reporting enhance security controls and help build trust with C-level leadership and the board.

