The complexity of cloud environments and the speed and scale of operations in the cloud drive the multitude of challenges organizations face in securing their cloud-resident sensitive data. The most difficult challenges include discovery and classification of data as well as ensuring compliance with regulations. Despite confidence in their data security tools, organizations continue to lose data due to misconfiguration, misclassification, and unknown (shadow) data. Implementing a defense-in-depth strategy that combines third-party and CSP-native tools and controls can overcome these challenges in securing cloud-resident sensitive data.