Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By John Grancarich, Chief Strategy Officer, Fortra
The Growing Complexity of Data Security
In 2026, organizations will face a new level of complexity in managing data security. The volume of data is not only growing; it’s spreading across clouds, SaaS platforms and AI pipelines. This has created blind spots traditional tools weren’t originally built to see, and why Data Security Posture Management (DSPM) is poised to become a foundational capability for modern cybersecurity programs.
What DSPM Brings to the Table
DSPM is about continuously finding, classifying, and monitoring sensitive data across an organization’s environment in its entirety. More importantly, it’s about understanding how this data is being accessed and protected. It offers organizations the visibility and control they need to manage risk in this new, fragmented reality.
While tools like DLP (Data Loss Prevention) and IAM (Identity and Access Management) will remain important, they’re inherently reactive, and enforce policies after the data is understood. DSPM works further upstream. It helps answer a number of key questions:
- Where is all my sensitive data?
- Who has access?
- What is most valuable in that data?
- Is it stored securely?
It uncovers hidden stores, misconfigurations, overexposure and shadow IT that other tools miss. This insight allows organizations to address risks proactively rather than respond after the fact.
Integration Without Complexity
Some security leaders worry that DSPM will add complexity or contribute to tool sprawl. But in 2026, the most effective organizations will treat DSPM as a layer of visibility that strengthens the tools already in place rather than competing with them. Most platforms integrate via APIs and feed data context into SIEM, SOAR, DLP and IAM workflows. The key will be to start with a clear objective , such as mapping sensitive data in cloud storage, and grow from there. When implemented correctly, DSPM reduces complexity by giving other tools the context they need to perform more effectively.
Who Will Lead the Way
Highly regulated, data-heavy sectors like financial services, healthcare, government, and defense will likely lead the way in DSPM adoption. Organizations building AI models will prioritize DSPM because their data exposure risk is growing quickly. DSPM will also accelerate secure cloud migration and zero trust initiatives by delivering continuous visibility into where sensitive data lives and how it’s used.
Visibility as a Strategic Imperative
In the year ahead, visibility will become the most important priority in cybersecurity. You cannot protect what you cannot see. Most organizations still lack full visibility into where their sensitive data lives or if it is exposed. Establishing that visibility is the first step. Everything else -from policy enforcement to automation – depends on it.
Governance and Cultural Shifts
To fully realize the benefits of DSPM, organizations will need to evolve both their governance models and their culture. DSPM is most effective when data security is shared across security, IT, compliance, and business teams. That means clear ownership, consistent classification, and well-defined lifecycle policies. Culturally, organizations will need to shift from “collect everything” to “collect what’s necessary.” Executive sponsorship and accountability ensure DSPM insights lead to real change, not simply improved reporting and dashboards.
A Defining Moment
As cyber threats grow more sophisticated and data environments become more decentralized, DSPM will become a strategic imperative. It is not just another tool-it represents a shift in how organizations think about data risk. Those that embrace it early will be better equipped to navigate regulatory demands, operational complexity, and emerging threats. Those that wait may find themselves reacting to risks they could have prevented.
##
ABOUT THE AUTHOR
As Chief Strategy Officer at Fortra, John Grancarich leads the company’s evolution into a platform-based global cybersecurity provider. With deep expertise in technology markets and operations, he drives innovation that advances how organizations approach security. John advocates for a pragmatic, scalable model where security, IT, and business align to empower cybersecurity professionals through smarter use of AI and automation. Before joining Fortra in 2018, he founded Product Fuse and held leadership roles at KLDiscovery, Kroll Ontrack, and Paul Hastings. He began his career as a developer and computer forensics engineer and holds a bachelor’s degree in finance from Saint John’s University in New York. He is also co-author of Internet Fraud Casebook: The Worldwide Web of Deceit. https://www.linkedin.com/in/johngrancarich/






