What do people mean when they say Data Security Posture Management [DSPM]

If I asked you right now where every copy of a customer’s personal information and engagement history was located across your business, could you tell me?
Picture of Rocco Scaturchio

Rocco Scaturchio

Quick takeaways

  1. DSPM answers three questions: where sensitive data lives, who can access it, and what is exposed right now.
  2. Dealership customer data is routinely duplicated across the DMS, F&I paperwork, email, and legacy shared drives.
  3. The OAIC’s 2026 compliance sweep assessed around 60 entities, selected partly on prior breach history.
  4. Since 10 June 2025, individuals can sue directly for serious invasions of privacy, not only complain to the regulator.
  5. The fix is four habits (discover, classify, restrict, detect) rather than another security platform.

If you were asked where every copy of a customer’s personal information and engagement history was located across your business, could you answer?

Recently I had the opportunity to meet with a Dealer Principal of a busy, multi-brand, automotive franchise. During the meeting I took the opportunity to ask a simple question, a question I ask all of my clients, “If I asked you right now where every copy of a customer’s personal information and engagement history was located across your business, could you tell me?”

This was responded by an awkward pause, then the response of, “Probably not.”

Honestly, he is not irresponsible nor careless. But that pause, is the whole problem in one breath.

Think about what data actually sits in a client file. It includes such personal detail as their name, maybe their company’s name & BSB, residential and offices address, phone numbers, email addresses, date of birth, driver’s licence details, occupation and employment details, credit score, banking, finance and insurance details, purchase details, trade-in history etc. etc. Multiply that by every sale, every service booking, every finance application, going back years, that’s a lot of data, kept somewhere on record within the company.

Data that is often replicated on the Dealer Management System (DMS), Finance & Insurance paperwork, email threads and general correspondence, and potentially residing in a shared drive that was set up in 2019, that nobody’s has opened since.

Most principals I speak to have no real understanding or a “map” of where any of this data lives, it’s validity and/or who can access it. Data, if was stolen or released to the public domain would breach privacy regulations resulting in a negative reputational impact and financial loss.

This is what people mean when they say, Data Security Posture Management, DSPM. Strip the acronym away and it’s just three questions I think every business owner or principal should be able to answer:

 

  1. Where does our customer data actually reside?
  2. Who can access it? and
  3. Is any of it sitting exposed right now?

I’ve asked these questions on a regular basis and rarely do I receive a fast or reassuring answer. It’s not because anyone’s asleep at the wheel. It’s because a busy dealership has a hundred more urgent things to do than worry about an old, shared folder, a folder that just sits there, quietly, until someone finds it who shouldn’t. You don’t need to be hit by a sophisticated cyber-attack for things to go wrong, all you need is one unlocked door nobody remembered was open.

The fix isn’t a new tool. It’s four unglamorous habits:

  • Know where the data is,
  • Know and define what is sensitive,
  • Restrict who can reach it., and
  • Detect and alert when something “moves” that shouldn’t.

Dealerships don’t need to become cyber security experts. They just need to treat their customers’ data the way they expect their own personal data to be treated and that’s the conversation I keep having.

I am curious to understand how many other business owners could answer that first question positively? If you can’t, then that’s exactly where, I and my team at DFNCE, can assist you. We will work with your team and run an initial DSPM assessment, map where your data resides, identify what is exposed, and who can reach it.

From there it’s your call on how we move forward. We can either partner with your team and design and implement a suitable DPSM program, or if preferred, we can take on and manage your entire IT environment, end to end. At the end of the day, the choice is yours, and either way, you walk away knowing the answer to the original question.

Should you wish to have a deeper conversation on this or other IT, network and/or security related topics, we would love to talk with you. Please reach out and we can schedule an initial discussion.

Picture of Rocco Scaturchio

Rocco Scaturchio

Melbourne-based IT Operations Specialists

Related Service

IT Operations & Management

Want to see how DFNCE delivers this for Melbourne businesses? Start the conversation.
Log a support case