Data protection has enabled confident blocking of patient records while policies stay intuitive
What is our primary use case?
My main use case for Proofpoint Enterprise DLP involved determining what classification solutions were in place in a couple of projects that we worked on, but the most important aspect was the critical data for the business, and building controls around those data sets and applying those policies was straightforward with Proofpoint compared to other solutions.
It was more about a medical institution that we were trying to help, and for that particular entity, the patient information was critical. The way Proofpoint Enterprise DLP allowed us to build the policies around protecting the data was straightforward and intuitive.
My main use case was around health data, and we knew where exactly the data was sitting. The kind of access towards that data on the communications part or the transfer of the data is where Proofpoint Enterprise DLP really helped.
What is most valuable?
The best features Proofpoint Enterprise DLP offers include the ease of building rule sets, which is quite intuitive, and comprehensive policies for the data sets and the channels. The way we were able to implement it was easy and testable, so I do believe that is the best feature of the product itself.
When I say the rule building process in Proofpoint Enterprise DLP was intuitive and testable, it made life quite easy while guiding us through the process, such as when you have the source, what to apply, and the kind of action you want to take, including alerting sets. It is quite elaborate compared to other solutions, giving you the absolute control that you require.
Being from the consultant side, I can say that the customer was really happy with Proofpoint Enterprise DLP as is. They had a previous solution that never moved into absolute blocking mode, but with this solution and the rule sets that we were able to build for them, we were able to build it out, and I would say within six to eight months, they moved into a proper blocking mode. So it's a win, because DLP solutions tend to drag on for a long time.
The unified platform aspect of Proofpoint Enterprise DLP is very important for our organization, as the customer used the suite of Proofpoint products, making cross integrations really helpful between different product lines, though other integrations can sometimes be tough, especially with CASB aspects.
Adaptive policy enforcement in Proofpoint Enterprise DLP aids my analysts in responding to data risk with greater accuracy, as we received feedback five or six months after deployment that the adaptive features helped in identifying false positives. Once the learning curve was achieved, it was straightforward.
What needs improvement?
In terms of improvements, I find there are some blind spots in Proofpoint Enterprise DLP; you can obviously add more channels for detection, and logging can be much improved, specifying exactly what action took place or what alert was generated. There is a bit of ambiguity in that area. Apart from that, I am quite happy with the solution.
From a user experience standpoint, the UI in Proofpoint Enterprise DLP can be a bit better. Integration-wise, it would be great if the API or document API could work better with other integrations, as that is a place where we have found it a bit lacking.
For how long have I used the solution?
I have had worked with the solution on two deployments.
What do I think about the stability of the solution?
Proofpoint Enterprise DLP is stable.
What do I think about the scalability of the solution?
From a scalability standpoint, the multi-approach does help, as there are probes for multiple datasets across the domain, though having a single pane of glass to maintain all that would make it even better.
How are customer service and support?
The customer support for Proofpoint Enterprise DLP is good and it did help.
When rating customer support on a scale of one to ten, I say seven because anyone can improve all the time; customers can never be 100% satisfied, and as a customer I would expect support to handle queries within minutes.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
As a consultant, I have had exposure to multiple DLP solutions, including Proofpoint Enterprise DLP, in my previous work with Forcepoint. Comparatively to others, I have worked on two or three deployments, and it is a good product.
How was the initial setup?
As a consultant, I have experience integrating, and I find the ease of deployment of Proofpoint Enterprise DLP at least two times better than previous solutions.
What about the implementation team?
The customer who bought Proofpoint Enterprise DLP actually worked with the channel.
What was our ROI?
I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing in Proofpoint Enterprise DLP was more about providing comparisons between products, and pricing negotiation was done by the customer, so I cannot talk much about it.
Which other solutions did I evaluate?
Before choosing Proofpoint Enterprise DLP, evaluating other options was my job as a consultant, where I would present different solutions to the customer, and it was up to him to choose which solution he wanted to go with.
What other advice do I have?
I assess the effectiveness of Proofpoint Enterprise DLP in detecting and preventing data loss through user behavior and content analysis, and I would say effectiveness is displayed in that they had a solution which they could never move to a blocking scenario; however, with Proofpoint Enterprise DLP they were able to do it. If the rule sets and data sets are not right, the customer would never have even gone to the blocking mode. It is a continuous process with false positives and negatives, and the solution helps a lot in figuring out what will not work, but there is a gap in pinning out exact problems with datasets.
We have used the auto-learned classifiers within Proofpoint Enterprise DLP, with around 60 to 70% accuracy, as we knew where the data is located, and while the crawlers helped, we faced some problems when different languages, such as Arabic, were in use, which was a challenge for us.
My advice to others looking into using Proofpoint Enterprise DLP is to understand the source they need to protect, then pick the solution that suits their environment and use case, understanding the product before buying. I would rate this product an 8 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Data protection has strengthened compliance and now needs deeper integration for risk insights
What is our primary use case?
My main use case for Proofpoint Enterprise DLP is to maintain a proper security portfolio and usage for our key data in our organization and to satisfy compliance.
A specific example of how I use Proofpoint Enterprise DLP for compliance and protecting key data is that we have two types of critical data. One is personal information with some credit card information that we need to ensure only certain users have access to and that is protected. The second type is certain data that only departments such as Accounts Receivable have access to, and we need to ensure that it is in use.
I don't think there are any other unique ways we're using Proofpoint Enterprise DLP; it's standard practice.
How has it helped my organization?
Proofpoint Enterprise DLP has positively impacted my organization by keeping us secure and making us aware of whether any critical information is in motion or at risk, and furthermore, whether there are employees that have malicious intent or malicious actions.
Proofpoint helps me detect those risky employee actions by showing alerts on the data that was moved, and it shows us who is doing that and what they are doing. If they have malicious intent, we can identify what they are sending and often who they are sending it to.
What is most valuable?
The best features Proofpoint Enterprise DLP offers, in my opinion, are the interface and the GUI and the interconnectivity of some of their other platforms.
When I mention interconnectivity, I specifically refer to the email product and also the full platform integration that Proofpoint offers. There are a bunch of their other products that we utilize and they have ease of use.
What needs improvement?
If I had to think of one area that could use a little more polish, I do think putting more and more things into the integration of the full platform and portfolio is great to take multiple risk variants and provide alerts to the security organization and administrators.
For how long have I used the solution?
I have been using Proofpoint Enterprise DLP for two years.
What other advice do I have?
Those integration aspects are great for our organization. I provided feedback on the features of Proofpoint Enterprise DLP and I appreciate the opportunity to share my thoughts. I gave this review a rating of seven.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)