Data protection has strengthened email monitoring and prevents sensitive information leaks
What is our primary use case?
Proofpoint Enterprise DLP is helping us monitor who is doing what and who is sharing data over emails, whether within the organization or outside the organization. The most primary use case is securing our data and ensuring customer confidential information is not shared outside the organization.
One classic example is tracking whether any PII information, such as Aadhaar card numbers, account numbers, employee IDs, or professional email addresses in India, are being shared outside the organization.
Proofpoint Enterprise DLP provides many out-of-the-box use cases and best practices which help us utilize those and, to some extent, edit them as per our requirements to segregate the data.
What is most valuable?
Data recovery and classification is valuable, as it classifies where sensitive data such as PII information, IP, or financial data lives and helps classify it according to the data segregation or data category it falls into.
It has helped us tremendously to ensure our esteemed customers that whatever data our SMEs, security practice team, or SecOps team uses or may access from their customer data is being kept safe with us and is not being shared across the organization or outside the organization. That is one of the assurances we can give to customers while relying on Proofpoint Enterprise DLP.
I have examples where a few team members or employees mistakenly, or maybe intentionally, shared customer data over email, and those were caught by Proofpoint Enterprise DLP. This triggers an alert to our security team, and they immediately investigate those emails and the data. That helps us educate our employees and set up awareness trainings for them so that they are aware of which data can be shared over email and which should not be.
What needs improvement?
Currently, it seems to have all the features enabled. However, if Proofpoint could create some custom or out-of-the-box dashboards which help the organization, or CIO or CISO-level people, to get a view of how much data is being shared within a week or month, they could plan internal trainings or speak to their cybersecurity teams to improve the security posture or the use cases they have deployed.
Custom or out-of-the-box dashboards for CIO or CXO level people would help more.
For how long have I used the solution?
I have been in cybersecurity for ten years since 2016.
What do I think about the stability of the solution?
Proofpoint Enterprise DLP is quite stable. I have not seen any downtime or anything of that nature.
What do I think about the scalability of the solution?
Proofpoint Enterprise DLP is scalable and configurable and can support any kind of infrastructure and any kind of networks. Scalability-wise, Proofpoint Enterprise DLP is fine.
How are customer service and support?
Customer support is excellent. They provide support as per the SLAs they have, depending upon the situation and depending upon the case we open with them. Support is perfectly fine.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We are using Proofpoint Enterprise DLP currently. We did not work on another solution and migrate to Proofpoint.
How was the initial setup?
Integrations, support, and other things are easy to use, more user-friendly and architect-friendly. I do not have anything to add.
What about the implementation team?
We do have a partnership or alliance team who help us in setting up, initiating discussions, or taking them to the final stage or the solutioning stage.
What was our ROI?
The return on the investment is in securing the organization data, training the people, and making sure that the data which lies with our organization or our department is safe.
What's my experience with pricing, setup cost, and licensing?
The market value or market standard which Proofpoint holds means the cost is as per the services they offer. The licensing model is perfectly fine.
Which other solutions did I evaluate?
We did not explore other options because we know what kind of services or assurance Proofpoint gave customers, so we chose Proofpoint directly.
What other advice do I have?
Based on our experience and my experience, I usually prefer to recommend Proofpoint Enterprise DLP to customers and friends who are working in other organizations. I convince them with the level of services or level of assurance we are getting from Proofpoint Enterprise DLP. I share my experience with them to encourage them to opt for Proofpoint Enterprise DLP. I would rate this product a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Data protection has enabled confident blocking of patient records while policies stay intuitive
What is our primary use case?
My main use case for Proofpoint Enterprise DLP involved determining what classification solutions were in place in a couple of projects that we worked on, but the most important aspect was the critical data for the business, and building controls around those data sets and applying those policies was straightforward with Proofpoint compared to other solutions.
It was more about a medical institution that we were trying to help, and for that particular entity, the patient information was critical. The way Proofpoint Enterprise DLP allowed us to build the policies around protecting the data was straightforward and intuitive.
My main use case was around health data, and we knew where exactly the data was sitting. The kind of access towards that data on the communications part or the transfer of the data is where Proofpoint Enterprise DLP really helped.
What is most valuable?
The best features Proofpoint Enterprise DLP offers include the ease of building rule sets, which is quite intuitive, and comprehensive policies for the data sets and the channels. The way we were able to implement it was easy and testable, so I do believe that is the best feature of the product itself.
When I say the rule building process in Proofpoint Enterprise DLP was intuitive and testable, it made life quite easy while guiding us through the process, such as when you have the source, what to apply, and the kind of action you want to take, including alerting sets. It is quite elaborate compared to other solutions, giving you the absolute control that you require.
Being from the consultant side, I can say that the customer was really happy with Proofpoint Enterprise DLP as is. They had a previous solution that never moved into absolute blocking mode, but with this solution and the rule sets that we were able to build for them, we were able to build it out, and I would say within six to eight months, they moved into a proper blocking mode. So it's a win, because DLP solutions tend to drag on for a long time.
The unified platform aspect of Proofpoint Enterprise DLP is very important for our organization, as the customer used the suite of Proofpoint products, making cross integrations really helpful between different product lines, though other integrations can sometimes be tough, especially with CASB aspects.
Adaptive policy enforcement in Proofpoint Enterprise DLP aids my analysts in responding to data risk with greater accuracy, as we received feedback five or six months after deployment that the adaptive features helped in identifying false positives. Once the learning curve was achieved, it was straightforward.
What needs improvement?
In terms of improvements, I find there are some blind spots in Proofpoint Enterprise DLP; you can obviously add more channels for detection, and logging can be much improved, specifying exactly what action took place or what alert was generated. There is a bit of ambiguity in that area. Apart from that, I am quite happy with the solution.
From a user experience standpoint, the UI in Proofpoint Enterprise DLP can be a bit better. Integration-wise, it would be great if the API or document API could work better with other integrations, as that is a place where we have found it a bit lacking.
For how long have I used the solution?
I have had worked with the solution on two deployments.
What do I think about the stability of the solution?
Proofpoint Enterprise DLP is stable.
What do I think about the scalability of the solution?
From a scalability standpoint, the multi-approach does help, as there are probes for multiple datasets across the domain, though having a single pane of glass to maintain all that would make it even better.
How are customer service and support?
The customer support for Proofpoint Enterprise DLP is good and it did help.
When rating customer support on a scale of one to ten, I say seven because anyone can improve all the time; customers can never be 100% satisfied, and as a customer I would expect support to handle queries within minutes.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
As a consultant, I have had exposure to multiple DLP solutions, including Proofpoint Enterprise DLP, in my previous work with Forcepoint. Comparatively to others, I have worked on two or three deployments, and it is a good product.
How was the initial setup?
As a consultant, I have experience integrating, and I find the ease of deployment of Proofpoint Enterprise DLP at least two times better than previous solutions.
What about the implementation team?
The customer who bought Proofpoint Enterprise DLP actually worked with the channel.
What was our ROI?
I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing in Proofpoint Enterprise DLP was more about providing comparisons between products, and pricing negotiation was done by the customer, so I cannot talk much about it.
Which other solutions did I evaluate?
Before choosing Proofpoint Enterprise DLP, evaluating other options was my job as a consultant, where I would present different solutions to the customer, and it was up to him to choose which solution he wanted to go with.
What other advice do I have?
I assess the effectiveness of Proofpoint Enterprise DLP in detecting and preventing data loss through user behavior and content analysis, and I would say effectiveness is displayed in that they had a solution which they could never move to a blocking scenario; however, with Proofpoint Enterprise DLP they were able to do it. If the rule sets and data sets are not right, the customer would never have even gone to the blocking mode. It is a continuous process with false positives and negatives, and the solution helps a lot in figuring out what will not work, but there is a gap in pinning out exact problems with datasets.
We have used the auto-learned classifiers within Proofpoint Enterprise DLP, with around 60 to 70% accuracy, as we knew where the data is located, and while the crawlers helped, we faced some problems when different languages, such as Arabic, were in use, which was a challenge for us.
My advice to others looking into using Proofpoint Enterprise DLP is to understand the source they need to protect, then pick the solution that suits their environment and use case, understanding the product before buying. I would rate this product an 8 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Highly Flexible Solution Perfect for Large Organizations
What do you like best about the product?
Highly flexible, which is perfect for large organisations
What do you dislike about the product?
I don't believe there's anything I would dislike.
What problems is the product solving and how is that benefiting you?
Provides an extra layer of defence, and is truly our biggest protection against phishing emails. Attachment defense also protects us against malicious attachments. Internal DMARC policies can be fully customised to our needs, which is a great benefit when it comes to organisations consisting of multiple different companies, like ours. This for us was a huge help during acquisitions.