Thales has introduced CipherTrust Data Security Posture Management (DSPM), a platform that combines sensitive-data discovery and risk analysis with encryption, tokenisation and masking. It is designed to help security teams move from identifying exposed data to prioritising risks and applying protection within the same platform. Thales describes CipherTrust DSPM as the first purpose-built DSPM offering designed to move beyond discovering exposed sensitive data and access-based remediation, aiming to help organisations prioritise risks and protect sensitive information directly.
According to the company, sensitive data is increasingly distributed across cloud infrastructure, SaaS applications, on-premises systems, analytics environments and third parties. AI applications, copilots and agents add to that challenge as they gain access to enterprise information and data moves into additional repositories and workflows.
Connecting data risk to protection
CipherTrust DSPM combines sensitive-data discovery and classification with information about security posture, access, activity and behaviour. This approach is intended to help security teams determine which exposures carry the greatest risk and connect those findings directly with remediation.
Through integrated policy enforcement and workflows, the platform can encrypt, tokenise or mask exposed sensitive data from within the platform. Organisations can also address supported access-control risks and receive remediation guidance, extending the response beyond changes to permissions and access controls.
“Organisations don’t need another security tool that simply gives them a longer list of problems to investigate,” Todd Moore, Vice President of Data Security Products at Thales, said. “They need to understand which sensitive data is truly at risk and take direct action to reduce it. While traditional DSPM remediation often focuses on restricting who can access data, CipherTrust DSPM goes further by connecting risks to protections such as encryption and tokenisation, helping protect the data itself, rather than relying on permissions alone.”
Security teams can also use the platform to assess where sensitive information resides, who or what can access it, how it is being used and which exposures should receive attention first.
Using AI analytics to assess access and activity
Using AI-driven behavioural analytics, CipherTrust DSPM detects unusual access and activity. The platform correlates those signals into attack chains intended to help security teams investigate and respond faster to threats such as insider risk.
Thales says the system combines sensitive-data discovery with access, entitlement and activity context to identify inappropriate exposure and govern data before AI deployments scale. According to the company, this approach builds on more than 30 years of its work in data discovery, data protection, key management, access control and activity analysis.
Covering cloud, on-premises and hybrid data
Across cloud, on-premises and hybrid sources, CipherTrust DSPM provides discovery and risk visibility for structured and unstructured data. Integration with Thales data-protection capabilities allows organisations to move from identifying risks to applying encryption, tokenisation and masking across those environments.
Tokyo Electron Device cited the platform’s ease of deployment and data-classification accuracy as useful when working with enterprises that are connecting AI tools and agents to more business data. Hiroji Sugito, Principal Data Security Engineer at Tokyo Electron Device, said: “Tokyo Electron Device works with enterprises to address increasingly complex cybersecurity challenges as these organisations connect AI tools and agents to more of their business data. CipherTrust DSPM’s ease of deployment and the accuracy of its data classification enables us to help customers quickly gain understanding of where their sensitive data is, who or what can access it, how to protect it, and without slowing AI adoption. These capabilities provide significant value to customers looking to embrace AI while maintaining control of their most sensitive information.”




