Major New Features
Refreshed data-at-rest dashboard report
We’ve refreshed the Risk tab within the DSPM Dashboard, providing a unified reporting hub that consolidates fragmented risk scores and scan results into a single, cohesive narrative. This update eliminates the need to manually piece together data protection stories by providing an end-to-end view of your security posture—from high-level infrastructure down to specific user identities and actions.
With these insights, security teams can:
- Monitor risk posture from a high-level infrastructure view down to granular data classification and access details
- Demonstrate security value to executive leadership with “at-a-glance” visibility into program effectiveness
- Address SaaS data security risks using new widgets, such as Top Sensitive Data Exposed and Sensitive Files Exposed, to identify high-risk exposure points
- Optimize organizational policies by centralizing insights across both SaaS and non-SaaS environments in one place
This enhancement reinforces Netskope’s leadership in data security by making complex data-at-rest insights accessible and actionable. The dashboard is automatically available to all DSPM users with reporting permissions across all management planes, no additional configuration required.
Improvements and Updates
Object-level policy updates
Netskope One DSPM now features object-level policy evaluations, moving beyond aggregate data store summaries to provide granular, per-file analysis for unstructured data. This enhancement allows the policy engine to return individual file matches and precise sensitive record counts, supported by new discovery signals such as service, region, and platform. Security teams can now monitor high-risk events with pinpoint precision across their entire data environment. To streamline automated response, these detailed object-level insights are consolidated within workflow payloads such as AWS SNS JSON, ensuring downstream security workflows receive the exact metadata needed for rapid remediation.
New option to use existing VPC when onboarding AWS EBS
AWS EBS volumes can now be onboarded and scanned using existing VPCs, subnets and security groups. This update eliminates the need for granting Netskope high-privileges to manage your VPCs & internet gateways, allowing organizations to maintain a policy of least privilege while scanning cloud block storage. To use this feature, simply specify your pre-configured AWS network information during the data store connection process.
Changes
Deprecation of emailed scheduled reporting
As part of our ongoing integration with Netskope Advanced Analytics (NAA), the standalone Scheduled Report functionality within DSPM is being deprecated to centralize reporting across the Netskope platform. Moving forward, users can leverage NAA for automated reporting needs, ensuring a consistent experience across all services. While automated scheduling within the DSPM module will be retired, administrators can still manually generate, download, and email reports directly to stakeholders as needed.

