IBM is continuing to expand the capabilities of its business via acquisition. On Tuesday, Big Blue announced that it is acquiring privately-held security firm Polar Security. Financial terms of the deal are not being publicly disclosed.

While IBM's security business unit has a broad range of capabilities, apparently it was missing at least one area – the domain of data security posture management (DSPM), which is what Polar Security does.

"DSPM, while being a relatively new technology category, has attracted strong attention from customers and investors alike, largely due to the pervasive problem it addresses around data security in the cloud," Eric Maass, director of data security product management, IBM Security, told SDxCentral. "This acquisition allows IBM to quickly gain access to a technology that we see as critical for securing sensitive and unknown shadow data in the cloud and allows us to be the first amongst major security providers to make a move in this space."

What is DSPM and why does it matter?

While cloud security posture management (CSPM) has traditionally focused on cloud infrastructure and compute workloads, DSPM is focused wholly on deep data-related risks, starting with discovery.

For example, Maass said that a CSPM may look for “drift” in a configuration file in Kubernetes, suggesting that out-of-policy changes are being made. Meanwhile, a DSPM solution may find data hosted in that same workload and alert to vulnerabilities in the configuration that puts the data at risk.

Maass explained that data security posture management is focused on a few main objectives, all of which are centered on the movement of data to the cloud.

The first main objective is about discovering shadow data. With today’s rapidly-expanding cloud footprints, data is seemingly everywhere, and it’s become a large challenge for CISOs to protect data that they aren’t aware of to begin with. DSPM helps to quickly unearth those shadow data sources, which may be traditional data stores hosted on a hyperscaler, on middleware data services, or on SaaS applications like Slack or Office 365, and house large volumes of potentially critical, sensitive or regulated information.

Once data is discovered and classified, customers are faced with questions like who can access this data, or who has accessed a given set of data.

"In order to answer those questions, DSPM solutions like Polar will inspect access entitlements and audit logs to understand both the potential ways in which data can be accessed, along with the actual events that are occurring," Maass said.

Lastly, Maass explained that DSPM helps companies manage the posture, or configuration, of their data stores, along with any policy violations that may be occurring. To do this, DSPM solutions can compare configurations and events against rules and policies to determine if unsafe conditions exist or if policies are being violated.

How Polar Security will fit into IBM

Maass commented that Polar Security and its DSPM capabilities are a strong complement to IBM’s Guardium data security portfolio.

"While Guardium is known as a leader in data security use cases such as data activity monitoring, analytics and compliance, customers are increasingly concerned with [its] inability to manage security around the exploding volume of data in the cloud and SaaS properties, which Polar addresses," Maass said.