What is our primary use case?
I have been using Proofpoint Enterprise DLP at my company for the last two or three years. When I joined, the organization was already using Proofpoint. I really appreciate it for the email security and their TRAP module and TAP dashboard, which provide pre-delivery or post-delivery protection. I value the post-delivery protection and all of the modules that Proofpoint provides.
Currently, I am using Proofpoint Enterprise DLP specifically for email security. I am planning to explore whether we can use it for data security, as I was not previously aware of that capability. In today's session, I learned about how we can use Proofpoint Enterprise DLP for data security, but currently, we are using it for email security only. We use it to find sensitive data in email and to restrict that sensitive data from being forwarded to external email accounts, thus providing email security.
Basically, I am using Proofpoint Enterprise DLP from the email security perspective. I use it to find sensitive data to ensure that no SIN numbers, credit card information, or other sensitive information is shared with external parties or unauthorized users. We have created rules in our email system so that users cannot forward company email to personal email accounts. This type of security has been implemented in Proofpoint.
I recommend using Proofpoint Enterprise DLP for email security because we have already successfully used it for that purpose. I would also want to use it for data security to have a better experience. My experience with email security has been really good, as it blocks thousands of emails, whether they are Business Email Compromise, confidential credential compromise threats, telephone-oriented attack delivery, or ransomware attacks. It protects us from thousands of attacks, and I really recommend this tool to others.
What is most valuable?
First, I really appreciate the dashboard. Proofpoint Enterprise DLP dashboard clearly provides me with a proper explanation of whether a user clicked a malicious link or not and how many emails we have received. If we see one alert that a user clicked on a malicious link and the malicious email was delivered to the user's inbox, we can check in the dashboard how many total malicious emails have been delivered in our environment. Another feature I appreciate is that if a malicious email is delivered to the user's inbox, Proofpoint Enterprise DLP TRAP dashboard, if in the sandbox environment the email is later considered as malicious, Proofpoint Enterprise DLP TRAP pulls that email from the user's inbox if the user has not opened that email and deletes that email from the user's inbox. I really value that quality. Additionally, we can use Proofpoint Enterprise DLP TRAP dashboard to quarantine the email from the user's inbox if the user reports an email. Another feature I appreciate is that sometimes if a user clicks a malicious link, we have the option in Proofpoint Enterprise DLP to automatically disable that user's account. We do not need to worry if a user clicked a malicious link at night, as Proofpoint Enterprise DLP automatically disables that account.
I have already explained the Proofpoint Enterprise DLP Protection Server, Proofpoint Enterprise DLP TRAP module, and Proofpoint Enterprise DLP TAP dashboard, and how we can have a unified view if a user clicked any link and how many emails are currently delivered in our account if those emails are malicious, how we can pull that email from the user's inbox, and how we can automatically disable that account if the account gets compromised. I really value these features.
Personally, I believe that Proofpoint Enterprise DLP really adds value among all of the security tools we are currently using in our organization. This is my honest opinion because I really appreciate the support that Proofpoint Enterprise DLP provides and how many malicious emails are blocked by Proofpoint Enterprise DLP, such as Business Email Compromise attack, telephone-oriented attack delivery, and other ransomware attacks. Proofpoint Enterprise DLP categorizes these emails and blocks them automatically in the sandbox environment. I really find it valuable and I believe that during the day, we block thousands of emails, which keeps our organization secure.
Frankly speaking, I currently do not remember the specific metrics, but I know that when I provide a report to my senior management from the last thirty days or a quarterly report, I categorize how many Business Email Compromise attacks, how many telephone-oriented attacks, and how many ransomware attacks have occurred. From the data from the last ninety days, there are approximately three thousand five hundred to three thousand seven hundred emails blocked that are Business Email Compromise attacks that are automatically blocked by Proofpoint Enterprise DLP.
I have not worked directly with a Proofpoint Enterprise DLP support engineer account manager. My manager has worked with that. Proofpoint Enterprise DLP definitely has a higher cost compared to other email security tools, but some good solutions come at a cost. The cost value corresponds with their functionality, but the cost is definitely more compared to other tools.
What needs improvement?
I would now like to use Proofpoint Enterprise DLP for data security. Since we are currently using it for email security only, I would like to expand to data security. In today's session, I learned that Proofpoint Enterprise DLP can be used for data security and for human-centric AI. I would like to use that module in our organization if possible.
The user interface is quite good and the dashboard is really good. Regarding the support that Proofpoint Enterprise DLP provides, that is already good. I would want to know if we can use it for data security and for Active Directory accounts. For example, if someone tries to log in suspiciously, that account should be automatically disabled. Additionally, if we can use Proofpoint Enterprise DLP data security on the file server, and if users try to encrypt the files, it will detect that and generate an alert, that would be helpful.
I have already explained that I have had a very good experience with Proofpoint Enterprise DLP. I am satisfied with the customer support and with the email security. I am also satisfied with the dashboard.
For how long have I used the solution?
I have been working at the Town of Milton since last year.
What do I think about the stability of the solution?
Regarding the effectiveness of Proofpoint Enterprise DLP, it is really good in cases of email security and analyzing user behavior. If an email is delivered to the user's inbox, I can check whether the user clicked a link or not. I can check in Proofpoint Enterprise DLP TAP dashboard whether the user clicked a malicious link or not and whether there is an effect on the user system by clicking the malicious link. It also automatically blocks that sender if the sender is malicious. I really value that feature.
What do I think about the scalability of the solution?
Proofpoint Enterprise DLP's scalability is good and we do not have any issues with that.
How are customer service and support?
The unified platform is really important to find the root cause of the issue, such as how the problem arises, when the user clicked a link, how many users received the malicious email, and what the impact is. To find the root cause and to analyze the attack pattern on how it is entering our environment is really helpful with a unified view.
I am not aware of the Autolearn classifier because perhaps my other team members are working on that. They are the ones configuring Proofpoint Enterprise DLP servers. I do not have any information about this. I am basically checking the alerts and how the email is delivered to the user's inbox.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I do not have any information about previous solutions because I have been working in the organization for the last year, and when I joined, the organization was already using Proofpoint Enterprise DLP.
How was the initial setup?
Previously Proofpoint Enterprise DLP was on-premises. Now we have migrated it to the cloud. Currently, we are in the process of migration and we have almost completed the migration to the cloud. Only the outgoing bound emails are still on-premises, and we will shortly move those into the cloud.
What about the implementation team?
The team evaluated other options as well before starting to use Proofpoint Enterprise DLP, but when they started using it, I was not yet in the organization. So I do not know which tools they evaluated, but they definitely evaluated other tools as well.
What's my experience with pricing, setup cost, and licensing?
I do not have any information about the investment because I am working on the security alerts and security metrics.
What other advice do I have?
I have provided my feedback on Proofpoint Enterprise DLP and I give this product a rating of ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.