
Proofpoint Security
Centralized policies have reduced data leakage and optimize investigations across channels
What is our primary use case?
Proofpoint Enterprise DLP primarily protects email and web channels in our organization. We have implemented both Proofpoint Enterprise DLP and cloud DLP solutions. When someone sends an email outside the organization, it first goes to email exchange and then to Proofpoint Enterprise DLP. The system scans all content of the email, including attachments, and takes necessary action based on our configured policies. Once approved, the email goes to the email gateway and then outside the organization to the recipient server or email ID.
For cloud usage, we are using OneDrive and SharePoint where Proofpoint Enterprise DLP functions as a CASB solution. Whenever someone shares an external document or external data containing sensitive information such as PII, the DLP performs real-time scanning and blocks the external connection.
Regarding our main use cases, due to regulatory requirements, any customer PII data going outside the organization is monitored and blocked if it exceeds our specific threshold. Additionally, we have blocked encrypted data over email because no DLP solution can read encrypted data. These are our major implemented use cases.
How has it helped my organization?
Proofpoint Enterprise DLP has positively impacted our organization by helping us with compliance. We have set up a workflow where whenever anyone attempts to send blocked data according to our policy, we receive notifications and all alerts. The tool helps us prevent data leakage across channels, maintaining exfiltration prevention, compliance, and the auditing process.
The positive impact includes various measurable metrics. Business operations continue as usual while we have reduced false positive detection to approximately 30 to 40 percent with the predefined templates or configurations available in Proofpoint Enterprise DLP. Additionally, whenever someone sends data that is blocked, the system directly sends an email to the reporting manager who can release the data if it is a genuine activity, thus not impacting normal business operations. Overall, operation calls have been reduced by approximately 20 to 30 percent. The numbers demonstrate that false positive detection with the predefined template is reduced to 30 percent, and operation calls have decreased by 20 to 30 percent with Proofpoint Enterprise DLP.
What is most valuable?
Proofpoint Enterprise DLP offers coverage for email, endpoint, and cloud solutions, along with a centralized policy and investigation workflow. The centralized approach provides significant relief for both the investigation process and policy creation. The solution also includes a useful insider threat investigation capability.
The centralized policy and investigation workflow has helped our team significantly on a daily basis. When we deploy any policy, we do not have to create separate policies for different channels such as email, endpoint, and cloud. A single policy can be implemented across all three channels, which are the major channels through which data is exfiltrated. During investigation, if a user is performing insider threat activities or has malicious intent, we can see in a single console which channel they attempted to use to exfiltrate or send data if it was blocked. This gives us better visibility and a superior investigation capability in one console.
For how long have I used the solution?
I have been using Proofpoint Enterprise DLP for more than two and a half years.
Easy to Use with Instant Policy Updates, but Downtime Alerts Could Be Faster
Effective Daily Protection Against Most Email Bourne Threats
Keeps My Inbox Clean from Spam and Malware
Complete Email Protection from Proofpoint
Virus Protection & Email Fraud Defense