From the CISO’s Diary #3 — Ghosts in the Servers: The Shadow Data That Breaks Your Most Expensive DLP

From the CISO's Diary #3 — Ghosts in the Servers: The Shadow Data That Breaks Your Most Expensive DLP

Every DLP vendor has a slide with a padlock on it. Every CISO has sat through the pitch: “We see everything. Every file, every share, every byte that leaves the building.” I’ve sat through that pitch more times than I’ve rehearsed a bachata routine, and I’ve learned the same lesson both places — the moves you rehearsed aren’t the ones that get you in trouble on the floor. It’s the step nobody choreographed.

Let me tell you about a bank.

The Audit That Found the Wrong Thing

A few years ago, during a risk assessment for a financial institution, my team was mapping data flows the boring, correct way — interviewing app owners, pulling data classification policies, checking the DLP console. The DLP was excellent. Real-time, tuned, alerting on every credit card pattern that dared cross an egress point. Millions of dollars of engineering. A Formula 1 braking system on a car that, it turned out, had three doors nobody had bolted shut.

While scanning storage as part of the exercise, we found something the DLP had never seen: 46 forgotten file shares and eleven cloud storage buckets, some dating back nine years, containing full unencrypted customer records — ID numbers, account histories, even loan applications with signatures. Nobody owned them. Nobody remembered creating most of them. They were survivors of migrations, decommissioned projects, and a merger from 2016 that “we’ll clean up later.” Later never came. This is what I call the ghosts in the servers — data that technically exists, has real regulatory weight, and is completely invisible to the tools built to protect it, because those tools only watch data in motion. Nobody was watching data at rest, forgotten, unclassified, and multiplying quietly in the dark.

Why the Most Expensive Tool Missed It

DLP is a checkpoint. It inspects traffic crossing a boundary — email, USB, upload to a SaaS app. It is brilliant at catching the intern who tries to email a spreadsheet of salaries to their Gmail. It is structurally blind to the spreadsheet that’s been sitting quietly on an old file server since 2019, never moving, never triggering anything, just waiting.

IBM’s Cost of a Data Breach report has quantified this for years: breaches involving shadow data cost, on average, roughly 16% more than breaches involving data organizations knew they had — and they take significantly longer to identify and contain. Longer detection time compounds directly into dollars: every extra day of undetected exposure is a day of potential exfiltration, regulatory clock-ticking, and reputational erosion nobody’s tracking yet because nobody knows the exposure exists.

Shadow data isn’t a technical curiosity. It’s a business risk hiding inside a business risk. You’ve budgeted for the front door. The ghosts live in the basement you forgot you had.

From the CISO's Diary #3 — Ghosts in the Servers: The Shadow Data That Breaks Your Most Expensive DLP

DSPM: Turning the Lights On, Not Adding Another Lock

This is where Data Security Posture Management enters — and I want to be precise about what it is, because the acronym gets thrown around like confetti. DSPM isn’t a new gate. It’s a floodlight. It answers three questions that DLP was never designed to ask: Where does sensitive data actually live — across cloud, on-prem, SaaS, forgotten test environments? Who can touch it — including that service account created for a project that ended in 2021 and was never deprovisioned? And is it classified correctly, or is a bucket labeled “temp-backup” actually holding production PII?

In the bank’s case, once we ran a proper data discovery pass, the picture changed completely. We weren’t managing “customer data protection” as a slogan anymore — we had a real inventory, real ownership, real exposure numbers. Two of the eleven buckets were internet-facing with misconfigured access. That’s not a hypothetical risk on a heat map. That’s a headline waiting for a slow Tuesday.

The Boardroom Translation

When I bring this to executives, I don’t open with “unstructured data governance.” I open with a question: “Do you know exactly what would be in the breach notification letter if someone found bucket #7 before we did?” Nobody knows. And that uncertainty — not the malware, not the exploit — is the actual reputational risk. A breach you can scope and explain within 48 hours is a bad week. A breach where legal has to ask “wait, what else is in there?” is a bad year.

This connects to something I always come back to: cybersecurity as a business enabler, not a cost center playing defense. A BIA — a Business Impact Analysis — done properly asks not just “what happens if this system goes down” but “what data do we hold that we don’t even know we hold, and what does its loss actually cost us — in fines, in customer trust, in the deal that falls through during due diligence because a buyer’s security team found the ghosts before we told them about them.”

From the CISO's Diary #3 — Ghosts in the Servers: The Shadow Data That Breaks Your Most Expensive DLP

Data Poisoning’s Quiet Cousin

I’ll add one more layer, because I spend a lot of my time now in AI risk conversations. Shadow data isn’t just a breach risk — it’s a training risk. If your organization is feeding internal repositories into an LLM for a copilot or search tool, and nobody has mapped what’s actually sitting in those repositories, you may be teaching your AI assistant on data you didn’t know existed, classified or not. That old HR export with salary bands from 2018? It’s now embedded in a vector database, answerable to the wrong prompt from the wrong employee. The ghosts don’t just haunt your storage anymore. They start talking back.

What Actually Works

  • Run a discovery pass before you buy another control. Most organizations invest in prevention before they’ve mapped exposure. Flip the order: know what exists, then decide what to protect.
  • Assign an owner to every repository, not just every application. Data without an owner is data nobody will ever delete or defend.
  • Treat classification as a living process, not a one-time project. The bank’s oldest ghost bucket was nine years old because classification happened once, at a kickoff meeting, and never again.
  • Fold data discovery into your BIA and AI governance work. The same map that tells you what a breach would cost also tells you what your AI tools are quietly learning from.

Closing the Lights

I keep thinking about that flashlight walk through the server room — the one every CISO takes at some point, metaphorically or literally, at 2 a.m. before an audit deadline. The DLP dashboard was calm. Green across the board. But calm isn’t the same as clean. The ghosts don’t set off alarms. They don’t need to. They just wait in the rooms nobody thought to check.

Turning on the lights doesn’t mean buying one more expensive lock for the front door. It means finally walking through the whole house — the basement, the attic, the storage unit you forgot you rented — and writing down, honestly, what’s actually in there. That’s not a technology project. That’s a discipline. And it’s the one that actually keeps you off the front page.


I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.

From the CISO's Diary #3 — Ghosts in the Servers: The Shadow Data That Breaks Your Most Expensive DLP

לפרטים נוספים מוזמנים לפנות אלינו