Your DSPM Scan Finished Six Months Ago. Nothing Has Changed.
The scan completed. The findings landed. Six months on, the finance repository it flagged still has no owner's name against it, and the inventory describes a tenant that has moved on without it.
The tool turned on, the program did not start
A DSPM deployment reaches a moment that feels like the finish line. The first scan has walked the tenant, and there is an inventory of data stores with sensitivity findings attached. Where the plan said deploy and configure, deploy and configure is what happened, and the effort stops at the line the plan ends on.
Months later, someone in legal asks who owns the finance repository flagged as holding regulated records. The answer takes a week to assemble, and the finding has been sitting open since the quarter before. The tenant has added storage accounts, sites and workspaces since the scan, and noticing that is somebody's job only if it was written into somebody's week.
Discovery happens once. Posture is a state somebody has to hold. Deciding which person in your company owns a given finding is a judgment about your organization, and the list stays a list until somebody makes that call and comes back in ninety days to see what happened. That work belongs to a program, and a program exists once it is scoped and staffed. Visibility with an operating model attached is what turns the inventory into work.
What three Purview and Securiti engagements had in common
Three delivered engagements, two platforms, Microsoft Purview and Securiti, and the same shape each time: quick wins, then a roadmap, then operationalize. The work arrived at that sequence on its own, once somebody had to decide what to do with more findings than one person could work through.
The roadmap phase is mostly decision effort, and decisions move at the speed of your governance. Schedule it against how long your organization takes to agree on something, because that is the constraint that binds.
Both platforms found what they were pointed at and reported it accurately. An owner, a ratified taxonomy and a cadence are decisions about how your organization wants to work, and they get made by people inside it. Where momentum was lost, it was lost on one of those three.
- Quick wins are the findings that close without an organizational decision. Anonymous sharing links, a storage account with no recorded owner, site collections that should have been retired two reorganizations ago.
- The roadmap holds the findings that meet decisions nobody in the room is able to make. Retention reconciled against a records schedule, a label taxonomy legal has to ratify, enforcement that interrupts a business process the day it moves from audit to block.
- Operationalize is where owners get names, the review takes a permanent place in a calendar and the exception register comes into existence. It carries the value and it loses attention first.
Two things went missing in all three, and both were organizational: a name against a data store, and a taxonomy somebody senior would sign.
The operating model: owners, labels, exceptions, cadence
The operating model has four moving parts, and each one can be written down, staffed and checked against.
Owners come first because everything downstream depends on them. Write one individual's name in the register. Send the finding to a team alias and everyone assumes somebody else has it. An owner is someone whose manager knows they hold it, and who can either fix the finding or formally decline to. The difficulty is political, which is why it gets deferred.
Labels are the classification scheme the platform applies, and they carry enough failure modes to deserve the section below.
The exception register costs the least of the four to build. A finding the business decided to accept is a legitimate outcome, as long as it carries an approver, a reason and an expiry date. Where the register is missing, the same finding gets rediscovered and argued from scratch every cycle.
Cadence is the review where the numbers move, monthly while the backlog is drawn down and quarterly after that. Give it a standing slot and a named chair, because a busy month cancels whatever has no one's name on it.
Four artifacts should exist when the phase closes.
- An owner register that maps every class of data store to a named individual
- A label taxonomy document with a version number and a date for its next review
- An exception register where every entry has an approver, a rationale and an expiry
- A recurring review with a fixed agenda and one number the sponsor reports upward
Classification that survives the labeling committee
Classification is the part where the work turns from configuration into judgment, which is where a program can sit for a year. A working group is convened to define the label taxonomy. It meets over a run of sessions and produces a tier structure, a set of sub-labels and a regulatory mapping. The result is complete, internally consistent, and applied to almost nothing, because using it requires a judgment call no document author is willing to make on a Tuesday afternoon.
The scheme is yours to define, and both platforms will hold whatever taxonomy they are given and apply it consistently. A committee optimizes for completeness whenever completeness is the one thing everyone in the room can agree to. Usability needs somebody with the standing to say no.
Four things make a taxonomy survive contact with the business.
- Define labels by the consequence they carry. If two labels produce the same encryption behavior, the same sharing rule and the same visual marking, they are one label wearing two names.
- Let automatic classification carry the load and keep manual application for the exceptions. A scheme that depends on users choosing correctly at save time loses accuracy as soon as the people applying it get busy.
- Date the taxonomy. Version one is good for twelve months and gets revisited on a known date, which turns an argument about an edge case into an item for the next review.
- Run it as a facilitated decision with a written decision log. Holding legal, records management and a business unit lead in one room and leaving with a ratified scheme is a different job from configuring the policy.
The quarterly cycle that moves the number
The value of this work builds up over quarters. Go-live is where the counting starts. A scan is a photograph of an estate that does not stop moving. New workspaces get created, a business unit adopts an application without telling anyone, and the inventory delivered in March describes a smaller company than the one that exists in September.
A one-off remediation push moves the number once and then lets it drift, because the conditions that produced the findings are still in place. Run the cycle on a schedule and posture turns into a trend line, which is what an auditor or a board can work with.
A deployment is finished when the configuration is complete. A quarter is finished when the four artifacts exist and the report shows movement between two measurement points. That second one is what the next round of attention and budget gets argued from.
Program structure, operating model design and classification governance are CWS practice views, formed across three engagements and stated here as views.
The cycle is the same every quarter, which is what keeps it staffable.
- Reassess, and establish what has changed since the last look
- Bring newly discovered stores into the owner register
- Work the exception register, renewing entries at expiry or sending them back to the backlog
- Close an agreed number of the highest-severity findings
- Report one number to whoever the sponsor answers to
A trend line is the only version of this work that survives a board meeting or an audit.