Data Security Posture: Research and Thinking from the PostQKey team.
Technical writing on DSPM: data classification accuracy, cloud access governance, warehouse RBAC complexity, SaaS shadow data, and what GDPR and HIPAA actually require from a data inventory standpoint. Written by engineers who work on the problem, not a content team.
A CISO's Working Guide to Data Security Posture Management
What DSPM actually means in practice, how it fits alongside CSPM and DLP, and the three questions every CISO should be able to answer about their data estate.
Five S3 Misconfiguration Patterns That Expose Sensitive Data
Specific ACL and bucket policy patterns that create public or overly permissive access to S3 data, and how to detect them systematically.
DSPM vs DLP: Two Different Problems, Two Different Tools
Data Loss Prevention catches data leaving. Data Security Posture Management finds data that should not be where it is. Why you need both.
Data Governance Is an Engineering Problem. Treat It Like One.
Security and data teams keep talking past each other on governance. A practical framework for embedding data classification into engineering workflows.
Shadow Data: The Sensitive Records in Apps Your Security Team Did Not Audit
Salesforce exports in Google Drive, Slack files with SSNs, Notion databases nobody deactivated. Shadow data in SaaS apps is a bigger exposure than most cloud security programs account for.
Snowflake Shares and the Access That Outlasts the Relationship
How Snowflake data shares work, why they are frequently over-permissioned, and a walkthrough of finding stale shares in your environment.
PHI in the Cloud: Where Healthcare Data Lands When Engineers Are Moving Fast
Protected Health Information ends up in unexpected cloud locations: analytics pipelines, staging tables, SaaS integration logs. A look at the exposure patterns.
GDPR Article 30 in the Cloud: A Data Discovery Checklist for Security Teams
Article 30 requires a record of processing activities. Most organizations maintain this manually. Here is how automated data discovery changes the workflow.
Zero Trust for Data: Why Identity Policies Are Not Enough Without an Access Graph
Zero Trust network policies stop lateral movement at the perimeter. But who can query your Redshift cluster is a data-layer question that network segmentation alone does not answer.
How AI Data Classification Works (And Where It Still Gets It Wrong)
A look at the classification techniques behind modern DSPM tools: regex, ML models, contextual sampling. What each catches, what each misses.
DSPM vs CSPM: Two Acronyms, Two Different Threat Models
Cloud Security Posture Management looks at infrastructure configuration. Data Security Posture Management looks at what data is there and who can reach it. The distinction matters.
Sensitive Data Sprawl: Why Your Data Estate Grows Faster Than Your Visibility
An honest look at why sensitive data ends up in unexpected places: incentive structures in engineering teams, the lifecycle of data pipelines, and what a realistic inventory requires.