Decoding the world of cybersecurity

Thales ties DSPM to data protection

Thales has launched CipherTrust DSPM, combining sensitive-data discovery and risk analysis with encryption, tokenisation, and masking as AI systems gain wider data access.

Thales ties DSPM to data protection
Summary
  • CipherTrust DSPM combines data discovery, classification, and contextual risk analysis.
  • Thales links identified risks directly to encryption, masking, and tokenisation workflows.
  • The platform is designed for cloud, on-premises, hybrid, and AI-connected data environments.

Thales has launched a data security posture management platform that connects discovery of sensitive information with encryption, masking, and tokenisation controls as organisations give AI applications and autonomous agents broader access to enterprise data.

Thales said CipherTrust Data Security Posture Management combines sensitive-data discovery and classification with information about access, entitlements, activity, and behaviour in order to prioritise exposures.

The platform then connects identified risks to data-protection mechanisms on the same system, including encryption, tokenisation, and masking. Thales is positioning that integration as a step beyond DSPM products that primarily identify sensitive data and recommend changes to permissions.

The company describes CipherTrust as the first purpose-built DSPM offering to provide that combination. The claim depends on how competing products and integrations are defined, but the product direction reflects a wider move in the DSPM market from visibility towards active remediation.

Sensitive enterprise data now moves through public cloud services, SaaS applications, analytics platforms, on-premises systems, and third parties. AI introduces another layer because copilots and autonomous agents can retrieve information from several repositories while generating new outputs and moving data into additional workflows.

That creates a governance problem even where individual data stores are reasonably controlled. An organisation may know which systems contain regulated or confidential information without having the same visibility into which AI workloads can retrieve it, how often access occurs, or where generated outputs subsequently move.

Thales says CipherTrust DSPM combines discovery with access, entitlement, activity, and behavioural context to identify inappropriate exposure before AI deployments scale. Behavioural analytics are also used to identify unusual activity and correlate signals for investigation.

The more distinctive part of the proposition is the connection between visibility and protection. Encrypting, tokenising, or masking sensitive information can reduce the consequence of unauthorised access, but those controls have traditionally been operated separately from tools used to discover and classify data.

Bringing them into the same platform could reduce the interval between finding an exposed data set and applying protection. It also creates a larger governance surface inside the DSPM platform itself because automated remediation can alter how production applications and users interact with information.

That trade-off becomes particularly relevant in AI environments. Restricting data too aggressively can break model and agent workflows, while leaving information broadly readable increases the risk that sensitive content enters prompts, retrieval systems, autonomous tasks, or generated output.

Todd Moore, vice-president of data security products at Thales, said organisations need to understand which sensitive information is genuinely at risk and connect those findings with controls that protect the data itself rather than relying only on permissions.

The platform covers structured and unstructured information across cloud, on-premises, and hybrid sources. Its eventual value will depend on the accuracy of classification and risk prioritisation, as well as whether integrated remediation can be applied safely across heterogeneous environments.

The launch nevertheless reflects a clear pressure in enterprise data security. AI is increasing both the number of identities that can touch sensitive information and the speed at which data moves between repositories, leaving discovery-only controls with less time to translate findings into protection.

×