Comparison

The Data Security Stack: Which Layer Each Tool Owns

April 22, 2026 Alexandre Genest 7 min

Your most valuable data leaves on access you granted on purpose. DLP, CASB, DSPM, EDR, CSPM, SIEM, and DDR each own a layer. A map of the data security stack and the runtime movement layer that sits across all of them.

The Data Security Stack: Which Layer Each Tool Owns cover image

A researcher copies proprietary code in small chunks, off-hours, through an approved transfer channel, over two weeks. Every chunk passes DLP. The user is allowed to use that channel, so CASB waves it through. The host is not compromised, so EDR sees nothing. The cloud is configured correctly, so CSPM is green. The data was never sitting in a public bucket, so DSPM has no flag. Each box did its job. The code still left.

That is the seam your stack hides. Your most valuable data leaves on access you granted on purpose, and the danger is never one move. It is the pattern across moves. Map the stack by the question each tool was built to answer and the seam shows itself.

What each box was built to answer

DLP (Data Loss Prevention). The content-and-channel layer. Watches for sensitive strings (card numbers, source files, classified documents) leaving through defined exits: email, USB, web upload. DLP answers one question: is this specific payload allowed to leave through this specific door? It is rule-driven. Strong on the patterns you wrote down, blind to the ones you did not.

CASB (Cloud Access Security Broker). The SaaS layer. Sits between users and cloud apps and governs who can reach which app and what they can do inside it. CASB answers: is this person allowed to use this SaaS app this way? It sees Salesforce, Box, and Workday. It does not see what happens on the host before the upload or after the download.

DSPM (Data Security Posture Management). The at-rest layer. Discovers where sensitive data lives across your cloud accounts, classifies it, and flags exposure: a public bucket, an over-broad grant, an unencrypted store. DSPM answers: where is my sensitive data, and is it sitting somewhere it should not? It maps the static estate. It does not watch the data move.

EDR (Endpoint Detection and Response). The host-behavior layer. Watches processes, files, and known attack techniques on endpoints and servers. EDR answers: is this machine compromised or behaving like malware? It is excellent at intrusion. A legitimate user moving data through an approved tool is not, by EDR's design, an intrusion.

CSPM (Cloud Security Posture Management). The configuration layer. Continuously checks your cloud control plane against best practice and compliance baselines: open security groups, disabled logging, risky IAM. CSPM answers: is my cloud configured safely? It governs the room the data sits in, not the data leaving the room.

SIEM (Security Information and Event Management). The correlation layer. Ingests logs from everything above and lets analysts query and alert across them. SIEM answers: what happened across all my sources, and can I prove it? It is only as good as the events fed into it. A permitted move that fit no dangerous rule rarely shows up as an event worth correlating.

DDR (Data Detection and Response). The newest category, the one closest to the seam. DDR follows the data rather than the infrastructure. The market is moving here because posture and access describe the room and the door, not the data in motion.

Every answer is a permission answer

Line the questions up. Content. App access. Where data rests. Host compromise. Cloud configuration. What the logs say. Each one evaluates whether a single move was allowed or whether a single state is safe. None of them scores a sequence.

The breach that costs you the most is not a denied move or a misconfiguration. It is a run of permitted ones. The researcher above is one shape. An integration pulls more records than it has ever pulled, to a destination it has used before. A departing employee reads broadly across high-value paths during their notice period, every read inside their access. The steps are allowed. Every tool in the stack correctly lets them through. The pattern is the breach, and no upper layer was built to score the pattern of movement itself.

Call it structural, not a vendor failure. A tool that judges one move, one app, one configuration, or one host at a time cannot see a pattern that only exists across moves. That pattern is visible at one place: at runtime, while the data is moving, resolved to the identity and the job behind it, scored against how that identity normally moves.

The layer that runs across the row

Runtime Data Movement Governance is not another box in the row. It runs across the row, watching the one thing every other tool treats as a side effect: the movement.

Hilt watches data movement at the kernel, metadata only by default, off the path. One lightweight collector runs single-tenant inside your own cloud (AWS, GCP, Azure, or Ali Cloud) at roughly 0.1% of one core and 4 to 8 MB of memory per host. It does not sit inline. It does not block, drop, or alter traffic. It does not have to read your data to see that a pattern is wrong. Content-aware inspection is there when you want it. It is not the price of admission.

Each move resolves to a probabilistic, source-dependent identity: which user, which job, which destination, and whether this fits what that identity normally does. The researcher from the top of the page shows up here, not because any single chunk is forbidden, but because the read is unusual for that identity, the volume is unusual for that destination, and both land in the same off-hours window. Any one signal is noise. Together they are a case, not an alert. Hilt writes the case and responds with host-level network isolation (quarantine) from the control plane.

How it fits what you already run

It is additive. The honest division of labor:

  • DLP still catches the obvious content on the wrong door. Hilt sees the slow, permitted movement DLP's rules never described.
  • CASB still governs SaaS access. Hilt sees the host before the upload and after the download, where CASB has no vantage.
  • DSPM still tells you where sensitive data rests and whether it is exposed. Hilt tells you when it starts moving in a way that does not fit.
  • EDR still owns intrusion and malware. Hilt sees the legitimate user, valid credentials, wrong data behavior, which a compromise hunter is built to ignore.
  • CSPM still keeps the cloud configured safely. Hilt watches the data leave a correctly configured estate.
  • SIEM still correlates and proves. Hilt feeds it a written case resolved to an identity instead of a raw event that looked permitted.

Hilt replaces none of these. It closes the seam between them, the one no posture or permission layer was designed to cover.

Reading your own diagram

Draw your stack and label each box with the question it actually answers. DLP: content and channel. CASB: SaaS access. DSPM: data at rest. EDR: host compromise. CSPM: cloud configuration. SIEM: correlation. DDR: data in motion.

Then ask the question none of the upper boxes answers: what did this user's data actually do, resolved to the job behind it and scored against how it normally moves, between 11pm and 2am on these three dates? If the diagram cannot answer that, the gap is not in any one box. It runs across all of them.

To see where that layer lands on your own stack, book a 30-minute call, engineer to engineer, and we walk one host and one real data path. No deck.