Data security management in Swiss SMEs rarely begins with a procurement process. More often, it starts with an uncomfortable realisation after a near miss: no one knows exactly where sensitive personal data, contracts and trade secrets reside across cloud storage, SaaS applications and local file shares. Senior management wants clarity quickly. Meanwhile, data protection teams ask for the record of processing activities and evidence of purpose limitation, while IT faces a complex environment that has evolved over time. This article presents DSPM as a governance and classification discipline. It also examines the limits of manual data discovery and explains what an SME should do before selecting a tool.
What data security management should deliver
Data-Security-Posture-Management, or DSPM, shifts attention from systems to data. The first question is not whether a cloud resource has been configured correctly. Rather, it is what data the resource contains, how sensitive that data is, who can access it and whether this exposure aligns with business purposes and legal requirements. This perspective is particularly valuable for SMEs. Their cloud and SaaS landscapes have often evolved without consistent, centrally managed architectural decisions.
Gartner’s market definition describes DSPM as the ability to discover, categorise and classify previously unknown data across on-premises and cloud environments. It also covers the assessment of access rights in relation to security, privacy and AI risks. This framing is useful because it treats data security management not as another dashboard, but as a data-centric control layer. The definition is publicly available in Gartner’s market overview of Data Security Posture Management.
Distinguishing DSPM from adjacent categories is essential when making procurement decisions. CSPM primarily examines cloud configurations, permissions and policy gaps at the infrastructure level. DLP typically addresses data exfiltration, policy violations and control points such as endpoints, email and web channels. Data Access Governance focuses more closely on access rights and ownership surrounding data assets. DSPM cuts across these areas: it begins with data discovery, adds sensitivity and context, and then prioritises the resulting risks. A German-language comparison of CSPM and DSPM is available from ComputerWeekly.
This distinction also reveals the central argument: DSPM begins with governance and classification, while tool selection comes later. Without defined data classes, responsibilities, risk criteria and a clear legal framework, even technically sophisticated discovery produces little more than a list of findings. It does not provide a reliable basis for decisions.
The groundwork without software: scope, classification and the legal framework
Before introducing DSPM, an SME must decide which parts of its data landscape to examine. A sensible scope typically includes central cloud storage, collaboration platforms, business applications, file shares, databases and selected SaaS services. However, not every storage location requires the same depth of analysis at the outset. What matters is that the organisation defines the scope deliberately, prioritises it according to risk and documents its reasoning. Technical happenstance should not determine the boundaries.

DSPM first requires a classification scheme, data owners and clear decision criteria. Technical data discovery comes afterwards
Data classification in SMEs: deliberately lean rather than academic
An SME does not need an over-engineered classification model. It needs one that supports consistent decisions. A few levels usually suffice, such as public, internal, confidential and strictly confidential. Concrete examples should supplement them: personnel files, customer data, health data, financial information, quotations, development documents and credentials. Moreover, operational confidentiality levels must remain distinct from statutory categories such as sensitive personal data. Each class also needs handling rules. These should cover permitted storage locations, sharing, retention, encryption, logging and reporting procedures for findings outside authorised zones.
At the same time, the organisation must appoint data owners. In an SME, this responsibility rarely sits within a dedicated data governance function. Instead, business owners, data protection specialists and IT security staff often share the duties. This arrangement is workable, provided that tasks and decision-making powers are explicitly defined. Without data owners, a DSPM finding is difficult to assess reliably. IT can identify the storage location, but may not know the business significance, processing purpose or applicable retention period.
FADP: the record of processing activities and DPIA as points of reference
For Swiss SMEs, the data protection framework is not a secondary concern. The revised Federal Act on Data Protection requires data security appropriate to the risk. The record of processing activities under Art. 12 FADP and the data protection impact assessment under Art. 22 FADP provide a methodological bridge to DSPM. Both require a structured view of processing purposes, data categories, recipients, retention and risks. Regarding the SME exemption from maintaining a record of processing activities, Steiger Legal explains that company size alone is not decisive. The assessment must also consider whether the processing presents only a low risk to the personality or fundamental rights of the individuals concerned.
Discovery scans need a clear purpose
Technical data discovery analyses content, metadata and permissions. Therefore, when personal data is involved, the scan itself constitutes data processing. Before a scan begins, the organisation must clarify its purpose and determine which data sources it will include. It must also decide who may view the results and how long it will retain findings. The Data Protection Ordinance defines the risk-based exemption from maintaining a record of processing activities for certain companies. This exemption does not apply if processing presents a high risk to the personality or fundamental rights of the individuals concerned. The commentary on Art. 24 DPO illustrates why organisations should document this risk assessment.
The limits of manual work in distributed cloud and SaaS landscapes
A legitimate question follows: if an SME does not know exactly where its data resides, how can it complete reliable groundwork before selecting a tool? The answer requires a clear distinction. Conceptual preparation remains both possible and necessary without a tool. People must define the scope, classification scheme, responsibilities, legal framework and risk criteria. However, in modern distributed environments, an SME can rarely achieve comprehensive technical data discovery through manual work alone.
Why manual data discovery reaches its limits
First: Shadow Data. Data does not exist only in core systems. It also appears in exported spreadsheets, temporary project folders, chat repositories, email archives, log files, downloaded reports and copies held in SaaS applications. These assets often arise from legitimate business needs. However, they may subsequently disappear from organisational oversight. Interviews and manual inventories therefore tend to capture them only partially.
Second: unstructured repositories. An SME may be able to identify its most important databases. Nested folder structures, attachments, shared links, local synchronisations and archives are more difficult to map. Yet these locations often contain personal data and trade secrets without reliable classification. Simple keyword searches generate many results, but provide little context. They also miss content that cannot be identified through unambiguous terms.
Third: dynamic access rights. Permissions change faster than the documentation that records them. Project groups expand, external partners receive temporary access and employees change roles. Without technical analysis of effective access rights, the data security posture remains a snapshot based largely on assumptions.
This tension cannot be resolved through a simple either-or choice. An SME should not procure a DSPM tool blindly and hope that governance will emerge from it. Nor should it assume that spreadsheets, workshops and samples can keep an inventory permanently complete across cloud, SaaS and on-premises environments. A two-stage approach is more robust. First, the organisation defines its decision criteria. Technical data discovery then applies those criteria to real data assets, tests assumptions and exposes gaps.
Data security management before tool selection: a sequenced SME agenda
The introduction of data security management should not begin with product presentations. An SME gains more by sequencing the initial work packages methodically. Consequently, it creates a robust basis for product selection, piloting and subsequent controls.
1) Record data sources: Create a prioritised list of relevant storage locations: cloud repositories, collaboration platforms, file shares, business applications, databases, exports in repositories associated with backups and selected SaaS services. Completeness remains the objective. Initially, however, transparency across the most significant risk areas matters most.
2) Define risk priorities: Specify which data requires attention first. Priorities may include sensitive personal data, large volumes of other personal data, trade secrets, credentials and financial data. Information subject to contractual protection obligations also merits particular attention. This prioritisation prevents DSPM from becoming a broad inventory exercise with no discernible effect.
3) Document the classification logic: Define which characteristics determine a data class. These may include content, origin, business context, file type, metadata, storage location and the permission model. The rules need not be perfect at the outset. However, they must be explainable, verifiable and version-controlled.
4) Define governance roles: Appoint data owners, approval authorities, the data protection contact and technical operators. Define who reviews and prioritises DSPM findings, who may accept risks and at what level senior management must become involved.
The organisation should then define success criteria for the pilot. These include more than the number of sensitive documents found. More important measures are classification quality, the reduction of excessive access rights and the traceability of decisions. Integration with existing controls and operability despite limited resources also matter. For SMEs seeking a more systematic approach to information security, linking data security management with an ISMS is a logical step. Our article ISO 27001 for SMEs in Switzerland provides further context.
The TECHWAY position on data security management
As a vendor-neutral cybersecurity adviser, we do not regard DSPM as a purely technical procurement exercise. Data security management is a method for placing data assets, sensitivity, access rights and risks within a manageable framework. Tool support may be necessary for technical discovery. However, it cannot determine which data is critical to the company, which access rights are permissible and which risks the organisation can accept.
For CISOs and Information Security Managers, the principal benefit lies in risk-based prioritisation. DSPM functionality can enrich existing categories such as DLP, CASB, SIEM and identity controls with data context. Not every misconfiguration is equally critical. Its significance increases when it affects particularly sensitive data, permits excessive access or enables external sharing that conflicts with the processing purpose. For data protection officers, DSPM provides a bridge between the record of processing activities, the DPIA and the actual data landscape. Implementation aids such as the FADP checklist for SMEs show that documentation and risk assessment remain incomplete without a clear view of data assets.
Four criteria for deciding when and how to select a DSPM tool:
1) Coverage of the organisation’s data sources: The tool must cover the SME’s relevant cloud, SaaS and on-premises sources. A long feature list offers little value if the product does not support critical business applications or repositories.
2) Classification quality: Finding sensitive data is not enough. The results must also be explainable and verifiable from a business perspective. Teams must be able to process false positives efficiently. Moreover, representative samples, tests and business reviews should help identify missed findings.
3) Integration into existing controls: DSPM should connect findings to established processes, including ticketing, access reviews, DLP policies and SIEM analysis. It should also support data protection workflows and management reporting. Isolated lists of findings create work, but rarely lead to effective control.
4) Operability in the SME: A resource-constrained company needs clear roles, comprehensible priorities and manageable operating processes. If a solution continuously produces more findings than the organisation can review and remediate, it becomes a repository of unresolved risks. It no longer supports sound risk decisions.
Conclusion
Data security management delivers value for Swiss SMEs when they treat it as a recurring governance cycle. The organisation records data sources, classifies data, assesses access rights, prioritises risks, initiates measures and reviews results regularly. It cannot delegate the conceptual groundwork to a tool. Therefore, it must clarify the scope, classification scheme, data owners, legal framework and risk tolerance before selecting a product.
At the same time, performing technical data discovery entirely by hand is unrealistic in distributed cloud and SaaS environments. A robust approach combines both elements: governance defines the questions, while DSPM functionality helps find reliable answers within real data assets. For SMEs, the decisive factor is not a Big Bang. Instead, they should begin iteratively with the most critical data sources and expand gradually according to verifiable criteria.
Initial consultation on DSPM preparation
Would you like to introduce data security management, but first clarify the scope, classification scheme, roles and FADP requirements? TECHWAY helps Swiss SMEs prepare methodically on a vendor-neutral basis. We support the prioritisation of data sources and the definition of robust criteria for subsequent tool selection.
🎯 Key takeaways for decision-makers
Summary for senior management, CISOs and data protection officers:
✓ DSPM begins with governance: Scope, data classification, data owners, purpose limitation and risk criteria must be clarified before tool selection.
✓ Manual work has limits: In distributed cloud, SaaS and on-premises landscapes, comprehensive data discovery is no longer realistically achievable by hand.
✓ The FADP connection is central: The record of processing activities, DPIA, data security and purpose limitation form the legal framework for discovery scans and risk assessments.
✓ Tool selection follows the requirements profile: Data-source coverage, classification quality, integrations and SME operability matter more than the sheer number of features.
✓ Start iteratively: A minimally viable data security management approach begins with the most critical data sources and expands controls gradually.
Frequently asked questions about data security management
What is the difference between DSPM, DLP and CSPM?
DSPM starts with data: it discovers data assets, classifies their sensitivity, assesses access rights and prioritises risks. DLP focuses more closely on preventing or controlling data exfiltration through defined channels. CSPM primarily examines cloud infrastructure, configurations and policy gaps. In practice, these categories complement one another.
Does a Swiss SME necessarily need a DSPM tool?
Not for the governance groundwork. Scope, classification scheme, responsibilities, legal framework and risk criteria must be defined independently of any tool. However, technical data discovery across cloud, SaaS and on-premises environments usually requires tool support because manual assessments rarely capture Shadow Data and dynamic access rights comprehensively.
How does DSPM relate to the FADP record of processing activities and the DPIA?
DSPM replaces neither the record of processing activities nor the data protection impact assessment. However, it can improve the underlying factual information by revealing storage locations, data classes and access rights. This information supports the documentation of processing activities, risk assessments and the definition of technical and organisational measures.
How can a resource-constrained SME start pragmatically with DSPM?
A pragmatic approach begins iteratively with a few critical data sources, such as central cloud repositories and business systems containing sensitive personal data or trade secrets. The next steps are a lean classification scheme, clear data owners, defined success criteria and a pilot of the discovery functionality. Expansion should proceed according to risk rather than as a Big Bang.

