I have been dealing with Proofpoint Data Security Posture Management as a distributor. If you are speaking on the Proofpoint data program, that will be three years. However, if you are speaking to the DSPM, which is a point product on its own that was acquired from Normalize, then that is just recently.
What is our primary use case?
What is most valuable?
The features I find most valuable in the product include the AI-powered classification. When you scan your cloud repositories, it finds and classifies data. It does not just discover; it discovers and then classifies the data or the files that it discovers based on the content. For instance, if there is credit card data in a PDF file, it classifies that file as financial, depending on the naming convention. It could be financial, could be PCI DSS, or similar classifications.
It has helped my data security strategy very well because one thing is to set static DLP rules. However, how do you start setting rules when you have little or zero visibility as to where your critical or sensitive data resides? First, you need to discover your data. You do not want to take any actions until you have clear visibility over all of your data and where they reside. Once you have visibility as a result of the discovery, and the DSPM does the AI-powered classification, it is not just been discovered but also been classified. Then it is pretty much easy to set up your static DLP rules and get results instantaneously.
Normalize's real-time alerts influence my approach to mitigating data vulnerabilities because you get real-time notification on what has been discovered. Not only that, but it also gives you the monetary value on a dashboard. It gives you a monetary value of your data. If it discovers lots of data that had not been discovered over time, then it tells you that in this repository or in this cloud share, you are at the risk of X amount of dollars. You risk losing this amount of dollars. Better put, it quantifies and monetizes it as well.
What needs improvement?
In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced. I think they should ease it up a bit. When it comes to setting of policies, I wish there were a single policy that deals with multiple channels of exfiltration instead of having to do multiple policies to deal with maybe data exfiltration through web upload, data exfiltration through USB, data exfiltration through print, copy and paste, and so forth. It would have been much easier if I had one policy, and then I could turn on the light for all of these different exfiltration channels. A critical example is saying I want to put up a PII policy that will secure social security numbers. That is the condition, social security number. Then in the same policy, I should be able to state that I want this to block exfiltration through USB. However, I want it to allow uploads through web or uploads to a particular website or URL. I want it to allow that kind of granularity where you can flick around things on the same policy. Currently, with Proofpoint Data Security Posture Management, you have to build multiple policies for different channels. Most importantly, the Boolean logic in their policies is incomplete. It just has the AND function. Boolean should carry AND and OR. I am saying if this data contains PII data OR PCI data—either of them—it flags either PCI or PII. But what it has now is AND. For it to fire or trigger, both must be triggered. So if somebody puts only one, maybe PII, and does not put PCI, then it does not trigger. It should have an OR, so that I can have multiple policies and then differentiate them so that if this OR this OR this, either of these triggers. I have flagged that and raised that as a concern to the product team.
I expect additional features from them in the next release, specifically the OR feature for the conditions. However, I am happy with the agent, the lightweight agent, the amount of activities it captures. Beyond just the DLP, it looks at the sites and URLs you are going to, it looks at the file renaming, it looks at the attempt to uninstall, and it looks really deep even though it is user mode. I am happy with that. The Boolean logic is what I think is incomplete at the moment.
How are customer service and support?
I assess their technical support as satisfactory. I am happy with the support. When it comes to response time, there is some room for improvement. Overall, I give them an eight out of ten rating for everything.
What other advice do I have?
It has improved my compliance efforts absolutely because first and foremost, with the classification, it guides users with the auto-classification. It guides users as to data compliance or as to data security or data protection compliance, whether it is an internal governance thing or it is a regulatory, regional regulatory, or industrial regulatory compliance. With that single feature of classification, it helps. I would rate the product overall as a nine out of ten.
