Symantec Data Loss Prevention is an enterprise-level solution and we utilize it for its customization, and flexibility across the platform as well as the excellent support and feature levels compared to other similar solutions.
Manager at a financial services firm with 1,001-5,000 employees
Helps to meet all regulatory requirements, is customizable, and flexible
Pros and Cons
- "The detection capabilities are comprehensive."
- "From a management perspective, it takes a lot of time to manage the infrastructure."
What is our primary use case?
How has it helped my organization?
There is still potential for improvement when it comes to data discovery over a network. How successful the process is depends largely on the network configuration and connectivity to the destination. Utilizing a detection server or network discovery can help facilitate the data discovery process. Recently, I discovered around 15,000 to 20,000 shareholders for Symantec using DLP for data discovery. Agent Discovery is also highly effective, with no performance issues showing up when performing endpoint discovery for the Symantec database.
I have not had much experience working with Macs, but they come with an in-built security feature. This can be challenging to work with, as not all features are supported in comparison to Windows. However, the solution recently became compatible with the Linux operating system, allowing us to deploy agents on this system as well.
Symantec Data Loss Prevention is a globally accepted product that provides an enterprise-level view of an organization. Although some of the features the solution offers are being utilized, there is still more potential to be explored if the organization puts more focus on using them to their fullest potential. Recently, the ICD or ID features, which cover all increase points and every other technology, were introduced. The solution provides features that correlate all events and generate top results. In DLP, the role bit and success management are present, allowing us to escalate incidents. We can also define an escalation process, allowing data owners to view incidents and escalate them as necessary. This functionality is provided by the solution. The primary goal of the DLP is to monitor and control the organization's data usage, as well as to facilitate audibility and accountability. Symantec Data Loss Prevention is well-suited to fulfill these needs.
The solution helps us find sensitive data and apply policies based on user risk. We can use indexing for highly confidential documents that are not to be published or shared with more than two to five people outside of the organization, such as the board of directors. Indexed Document Matching is a useful feature that can help ensure that the document remains secure. We can create remote detection over the product and map the UNC part. The data owner will put the file of a particular document, which will be converted into IDX format. We can then apply the policy remotely so that the data will not come to the DLP admin or any other person and will remain protected.
The solution offers a range of pre-defined data identifiers to meet all regulatory requirements, such as those mandated by the GDPR, PHI, PCI, and USUN. These data identifiers can be used to identify and protect personal data globally.
The solution helped reduce the time our DLP administrator spends on data loss protection. Spending time monitoring the data is essential. We have to stay up to date and investigate any issues that arise in order to improve health monitoring by fine-tuning incidents and reducing false positives because automation is not available.
What is most valuable?
The solution offers a one-click view from a single console, with detailed incident investigation capabilities that capture activity from end users, the web, and email. Symantec Data Loss Prevention provides comprehensive information conveniently and efficiently while also conforming to good architectural standards.
Compared to Forcepoint DLP, we can see that the email is not available. In Symantec, we are dependent on other products, such as DashMagiq, to release quarantined emails. This is because DashMagiq is able to do this through its API integration with the Office 365 email box. Unlike Forcepoint DLP, we don't have the option to release quarantined emails ourselves.
The detection capabilities are comprehensive. The solution covers all channels and supports cloud scanning. Additionally, the cloud-based solutions provided by CASB offer additional functionalities and now include AdvExt.
Symantec Data Loss Prevention has good detection accuracy. In some instances, the solution can produce a false positive. The solution's Application Monitoring feature allows us to monitor data that should be uploaded through an application; however, it can trigger an incident when the application is opened. The features provided by Broadcom are generally practical, but some of the less-used features may not be as accurate.
What needs improvement?
Before the release of version 16.0, some features were missing. Location-based detection and USB print blocking are still not available. This means we cannot configure the blocking of a USB printer, and we also cannot identify whether a system is on the network or off the network in a large environment. Additionally, the feature that is currently available is not fully operational. The domain-based resolution can sometimes take time to determine whether the system is accessible over the network or not.
From a management perspective, it takes a lot of time to manage the infrastructure. It seems that having cloud options available would reduce the overhead of managing infrastructure. Depending on the organization, we can choose to have the solution on-premises or on the cloud. If we choose the cloud, we can focus more on data loss prevention instead of managing the infrastructure.
Buyer's Guide
Symantec Data Loss Prevention
May 2025

Learn what your peers think about Symantec Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
For how long have I used the solution?
I have been using the solution for seven years.
How are customer service and support?
Both the free and paid technical support from Symantec are good.
How would you rate customer service and support?
Positive
What other advice do I have?
I give the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

System Admin at a government
Algorithm prevents users from copying or sending sensitive data, and UX saves me time
Pros and Cons
- "For detection, it has a great algorithm. It can recognize ID numbers and everything that you put in a policy for the end-users. That is really great for us as an institution where we have sensitive data. It recognizes all the sensitive data when someone tries to transfer it or put in other data."
- "I would like to see changes to the analytics."
What is our primary use case?
We have some sectors that have sensitive data, and for that reason we use Symantec Data Loss Prevention. We have some policies on those sectors so that if somebody uses an ID number or some other sensitive number, we record it in our system.
How has it helped my organization?
The benefit is that users can't copy or send sensitive data to another user outside our organization.
It has also helped save so much time. For me, as an administrator of the agents, who installs and puts group policies and rights in place, it saves me 20 or 30 percent of my time.
What is most valuable?
We can see everything about the users, meaning what kinds of data they use on their computers. When you install the Symantec agent on users' PCs, you define a role for the users and set the policy. We have set rights such that users can't copy sensitive data or send it via email or to USB. After, you can search monthly or yearly and see what kind of data they have used or shared and where they shared the data.
We also like the analytics and reports. We can get yearly reports, six-month reports, and monthly reports for analytics that we can export.
And for administrators and system engineers, it's easy to use, install, maintain, and upgrade. It's also easy for end-users.
For detection, it has a great algorithm. It can recognize ID numbers and everything that you put in a policy for the end-users. That is really great for us as an institution where we have sensitive data. It recognizes all the sensitive data when someone tries to transfer it or put in other data. When that happens it sends me a notification that somebody needs to use an ID or sensitive data. Its accuracy of detection is high.
Another positive aspect is that the speed of discovery is very high. We are very satisfied.
What needs improvement?
I would like to see changes to the analytics.
For how long have I used the solution?
I have been using Symantec since 2018, making it about five years.
What do I think about the stability of the solution?
It has constantly worked fine for me all these years. I haven't had any problems with it. It's highly stable.
What do I think about the scalability of the solution?
It's also highly scalable.
How are customer service and support?
The support could be more knowledgeable.
However, the firm we bought it from supports me very well. I would rate that firm a 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have only used Symantec File Share Encryption and Data Loss Prevention.
How was the initial setup?
We have it installed on-premises on virtual services.
Deploying it to the end-users was not complex. It was very easy for me. I installed it on about 40 computers, each used by two users, who are all in one location. It took two or three weeks in total.
In terms of maintenance, I maintain the agents and all the servers where Symantec is installed.
What other advice do I have?
I would highly recommend Symantec DLP. This is the best algorithm that I have seen compared to other products.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Symantec Data Loss Prevention
May 2025

Learn what your peers think about Symantec Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Senior Consultant at a consultancy with 10,001+ employees
The data-at-rest features help identify data infected with ransomware and prevent employees from being exploited through phishing attacks
Pros and Cons
- "The data-at-rest features are the most valuable because they let us identify data infected with ransomware and prevent employees from being exploited through phishing attacks. If an employee is compromised, the attacker can access servers and deposit ransomware. This enables the attacker to exfiltrate data remotely using employees' credentials. It might be valuable data that could cause a business reputational and financial damage if stolen and publicized. It could also be credit card data or personal health information stored on critical servers."
- "The upgrade process is convoluted. The server and database software must run in line with third-party providers like the Oracle database. If an Oracle database reaches the end of its life, then servers must be decommissioned, and you need to bring new servers online. When the maintenance packages are deployed to the management server, they don't get pushed to the detection servers. Each detection server must be manually installed rather than automatically made from a single server. If it's a large enterprise, you need to manually install it or use a GPO or some other technology, which I never use."
What is our primary use case?
We use DLP to monitor network traffic and prevent sensitive data from being exfiltrated outside of the company. Symantec also helps us discover data at rest in an environment that may be sensitive. The solution covers more than 10,000 users across various business units and layers, including endpoints, networks, and storage.
How has it helped my organization?
DLP is a control instrument for ensuring that an organization complies with regulatory requirements. For example, banks have requirements for storing credit card data, GLBA regulations, etc. DLP can help a bank avoid fines and protect it from civil liabilities.
Companies are audited annually, and DLP improves their risk posture. It ensures business operations won't get shut down because we don't know what we don't know. There are also internal threats, such as people leaving with privileged information on a USB. For instance, an earnings report could be stolen by a disgruntled worker and leaked to competitors. Symantec provides good definitions in the rule set. It can be customized to scan inside documents and pattern-match any unstructured data to comply with what the company needs.
What is most valuable?
The data-at-rest features are the most valuable because they let us identify data infected with ransomware and prevent employees from being exploited through phishing attacks. If an employee is compromised, the attacker can access servers and deposit ransomware. This enables the attacker to exfiltrate data remotely using employees' credentials. It might be valuable data that could cause a business reputational and financial damage if stolen and publicized. It could also be credit card data or personal health information stored on critical servers.
The false positive rate is excellent. It's about 90 percent accurate and gets better as we fine-tune the rule sets. When we have new incidents, we can work to lower the overall risk based on user behavior on the endpoint, the kinds of data we out on SharePoint, and the type of web or FDP traffic generated internally. I assess the effectiveness of a policy based on the number of false positives generated. We need to tune the rule set if it's greater than 20 percent.
The solution's data recovery is fast. It depends on the size of your storage, but I have no complaints about the speed of data recovery because there are several detection servers with the necessary horsepower to handle the amount of data that needs to be discovered. It could be remotely scanning a SharePoint server or a file server. The local agents can process data in the expected timeframe.
What needs improvement?
The upgrade process is convoluted. The server and database software must run in line with third-party providers like the Oracle database. If an Oracle database reaches the end of its life, then servers must be decommissioned, and you need to bring new servers online.
When the maintenance packages are deployed to the management server, they don't get pushed to the detection servers. Each detection server must be manually installed rather than automatically made from a single server. If it's a large enterprise, you need to manually install it or use a GPO or some other technology, which I never use.
The vendors should also give a heads-up long before updates are released so internal teams can meet their change management lead times. Some vendors don't provide enough notice. They often announce a new version or a vulnerability that needs patching a week before it comes out. It should be a month before.
The upgrade packages should have better documentation on the upgrade procedure instead of prerequisites spread throughout multiple documents. The wording should be more precise.
For how long have I used the solution?
I have used the solution for ten years.
What do I think about the stability of the solution?
Symantec DLP is highly stable. I've operated on Linux and Windows. Linux is stable and doesn't require much patching, but Windows requires more patching, and the service sometimes needs to be restarted.
What do I think about the scalability of the solution?
Symantec DLP has unlimited scalability if you buy enough licenses. Symantec has servers in the USA, Canada, Asia, and Europe that manage policies differently. For example, Europe has its own compliance rules for GDPR. Incident response can be managed well and segmented away from the rest of the world. You can implement Europe-specific policies.
How are customer service and support?
I rate Symantec technical support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used an appliance called Websense to analyze traffic for data loss. I used other Broadcom tools before Broadcom bought Symantec called Broadcom Proxy and CloudSOC Gateway. I didn't switch from Websense to Broadcom. It was just something I tried, so it wasn't a full deployment. Symantec DLP is head and shoulders above the competing on-prem DLP solutions.
How was the initial setup?
There are a few tricky parts when setting up Symantec DLP, but it's straightforward overall. We used an integrator for the deployment and didn't experience any hiccups after they were finished. About ten people from my company were involved.
We have two or three people doing maintenance on the solution, like weekly health checks to ensure services are running and traffic flows through the console dashboard. We need to check the incidents generated from the detection servers and verify that everyone can log in. The main part of maintenance is periodic system updates and vulnerability patches.
What was our ROI?
We see an ROI. During testing, I found it captures and blocks immediately. DLP is able to perform the necessary alerts. We can work with the business and get them on board to see what kind of data they use. We can assign the right roles and manage each business to assess its performance in terms of data loss. Symantec enables us to generate reports to show if their security posture or data loss is changing over time. It's a valuable tool that does what it claims.
What's my experience with pricing, setup cost, and licensing?
The price of Symantec DLP is fair. I don't recall the cost of the license, but it wasn't outrageous enough that it was an obstacle to approval. I'm not concerned with how much per seat or server, but I know they charge a lot.
If you're thinking about going for a cheaper solution, I suggest a close comparative analysis of the strengths and weaknesses of each solution by researching online and reading the vendor's documentation. You have to define your security requirements and look at factors like false positive ratios and whether it meets your compliance needs. Some companies only need to meet the minimum regulatory requirements, so a cheap solution that ticks all the right boxes might work. However, if security is the primary goal, you should compare the strengths and weaknesses of that cheap vendor against two or three other DLP vendors.
Which other solutions did I evaluate?
I didn't evaluate other solutions before choosing Symantec DLP this time, but I evaluated other DLPs for different projects. However, those were cloud-based DLPs, so it's not an apples-to-apples comparison.
What other advice do I have?
I rate Symantec Data Loss Prevention an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical lead at a tech vendor with 10,001+ employees
Straightforward to set up and easy to expand with good indexing features
Pros and Cons
- "The solution can easily scale."
- "We need to have agent auto-parsing."
What is our primary use case?
We primarily use the solution to follow a process that's already come in. If anyone takes a snap of anything, we can see that. Anything sent through email, uploaded to a drive, or shared to a public drive can be extracted by the DLP agent.
What is most valuable?
Whatever features Symantec has provided have all been valuable. The indexing features, where if anyone captures the image of the data, then it can be extracted to any of the channels, is quite useful. If you have a point DLP, email DLP, network DLP, et cetera it can capture that.
It offers a pretty straightforward setup process.
The solution can easily scale.
It is stable.
The support has been pretty decent.
What needs improvement?
The sensitivity to the agent path could be improved. Some of the false positive reporting could be detected by Symantec DLP better.
Auto-parsing is required. We need to have agent auto-parsing.
We need better clustering. Right now, the total amount of clusters depends upon Oracle. Instead of Oracle, the application-level cluster would be ideal.
Beyond that, we don't really need any new features as Symantec already offers pretty good items.
For how long have I used the solution?
I've been using the solution for four years. The last time I used the solution was six months ago.
What do I think about the stability of the solution?
It's been stable and reliable. There are no bugs or glitches, and it doesn't crash or freeze. I'd rate stability eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It expands easily. I'd rate the ability to scale nine out of ten.
We have about 15,000 people using the DLP part of Symantec.
How are customer service and support?
Broadcom acquired the Symantec DLP, and they're supporting it nowadays. Since they are now giving the support via a partner, we find we get support right away.
Which solution did I use previously and why did I switch?
I've also worked with Forcepoint DLP. It has a feature that allows for time-based user transfers.
How was the initial setup?
We have found the initial setup to be straightforward. I'd rate the ease of deployment nine out of ten. It's not overly complex in any way.
What about the implementation team?
Symantec already provides onsite authentication, Magneto integration, and email integration as a part of the product.
What's my experience with pricing, setup cost, and licensing?
I don't handle the pricing. I'm not a part of the sales or purchasing team.
What other advice do I have?
We're a Symantec partner.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
CEO at RISE Technologies
A solution with superb capabilities and administrative controls but its reliance on Oracle is limiting
Pros and Cons
- "The solution is simple to use with good administrative controls and a console that is easy to understand."
- "The solution relies on and Oracle database which is not financially feasible for many customers."
What is our primary use case?
Our company is a partner and deploys the solution for customers as a management server and email network.
What is most valuable?
The solution is simple to use with good administrative controls and a console that is easy to understand. This is particularly important because end users are security engineers, CSOs and compliance managers with minimal technical knowledge.
The DLP is very effective on the application side because there is a control on both endpoint and network storage. These components are separate from each other which needs to be planned out carefully but reduces server needs.
What needs improvement?
The solution should integrate with other databases because it relies on Oracle which is not financially feasible for many customers, particularly in small or poor countries. Oracle is very expensive on the cloud side.
Operational costs are too high for small offices that rely on Microsoft Office, so they instead opt for free yet powerful databases such as MySQL.
Data tagging and classification would be useful because multiple agent roles are needed solve issues.
For how long have I used the solution?
I have been using the solution for ten years.
What do I think about the stability of the solution?
The network and storage are very stable.
I've experienced a few issues with the DLP agent on the windows side when operating systems are mismatched or there is an issue with a group policy.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The effectiveness of technical supports depends on the agent. Support from America is good because they immediately direct you to a person or department knowledgeable in your issue.
For example, American support asks if deployments are new or old and then opens the appropriate case type which speeds up the process.
I rate customer support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup and implementation are very straightforward.
Setup is very clear and much easier than McAfee or Forcepoint.
I rate setup an eight out of ten.
What about the implementation team?
We implement the solution for our customers.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is based on a license model.
Which other solutions did I evaluate?
The DLP category is very competitive and we implement tools based on our client's needs such as the solution, Forcepoint, and Microsoft.
What other advice do I have?
Competitive products don't even compare to the solution with regard to its capabilities.
The only reason to choose another solution is budget because the solution requires licenses for the product and the database.
I rate the solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator / Partner
Great data matching capabilities, stable with file integration features
Pros and Cons
- "An excellent solution for data classification."
- "Different departments should manage administration, reporting, normalization and incident management."
What is our primary use case?
We use this solution for exact and index data matching, vector machine learning and endpoint prevention. We can use USB, make the solution notify a block policy and make response rules. It allows us to add the directory indication, make the agent configuration from the DLP, and then enforce them.
We can also complete different types of single-tier, two-tier and three-tier installations. For single-tier installation, it can enforce or recommend detections servers on the same servers. For two-tier, it can enforce on the same server and the detection server. And for three-tier, Oracle enforced, and the detection server is on separate servers.
What is most valuable?
The most valuable features are file integration and optical character recognition. It is a new technology integrated in DLP. File recognition technology mainly uses DLP, and we can use encryption technology to integrate the endpoint detection servers. The solution also helps to integrate the cloud access service broker in the DLP console, and we can complete information-centric tagging. For example, we can tag the files as private or public and protect them on the DLP console. In addition, we can classify data according to the environments and handle the files per the policy created from the console.
What needs improvement?
Different departments should manage administration, reporting, normalization and incident management. For example, for incident management, escalation can be completed in a specific department, and we can notify a manager and send an email when an incident has been triggered. In addition, confidential files that shouldn't be sent as a CV are managed. A DLP is a confidential solution that cannot be used to send unauthorized organizations' data to others.
The previous versions had a flaw when we installed the agents. We can install the agents manually or by the SCCM and easily manage the database and incident services. We can make several rules if we have a network or endpoint. We can also manage dashboards and administrators, super users and view roles. The larger administrator that manages the activities and daily reports has access to the best access tools. We can utilize user roles for the view access tools and to make policies.
For how long have I used the solution?
We have been using this solution for ten years and are using version 15.8. It is deployed on-premises, and the cloud is used for network payment for email.
What do I think about the stability of the solution?
This solution is very stable.
What do I think about the scalability of the solution?
It is very scalable, and there are no issues with maintenance.
How are customer service and support?
We can easily manage technical support unless we need clarification on a version of data or a task for principal clarification. I rate the technical support a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward. First, we had to install the Oracle database, which requires 19C if you use version 15.8. Then, we had to deploy and make the info server. After that, we had to complete the Oracle and listener configurations and connect the database. We then had to install the Windows Server and add the detection servers from the endpoint server.
During the installation, we imported different templates in .VSP format. The solution allows you to make policies and procedures with built-in templates, and there are templates for multiple sectors, such as energy, banking, financial, and telecommunication. It can be downloaded from the portal during the installation of the Oracle added to the enforce server. We can make different policies like data matching, index data matching, vector machine learning, and desktop content matching. For example, we can use proximity matching to detect data for 70% matches, 50% matches, or 20% matches. We can also upload different documents for index data matching. Exact data matching is for structured data, and index data matching is for unstructured data. Vector machine learning is for positive and negative threats, and the threshold is set for that purpose. I rate the deployment a ten out of ten.
What's my experience with pricing, setup cost, and licensing?
There is a perpetual license for three, five and two years. There is also a one-year renewable license for different parts. In addition, there are licenses for different consoles, namely Endpoint Discover, Endpoint Prevent, and Network Prevent. So it is an easy tool per the budget firewall and not difficult at all.
What other advice do I have?
I rate this solution a ten out of ten. Regarding advice, it is the best solution and has the best reputation. It is easy to manage and an excellent solution for data classification. It is the best solution I have ever used. We prefer Symantec to other solutions because their products are not difficult to integrate with a single console that is easy to manage.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Security Specialist at TT Systems LLC
Installation was straightforward and technical support was good
Pros and Cons
- "What we like about Symantec Data Loss Prevention is that it's a very good product. We never faced any problems with its performance. It has very good performance. There was this RAM issue, but it was an internal issue which we've sorted out. Apart from the RAM issue, there are no other issues with Symantec Data Loss Prevention."
- "What could be improved in Symantec Data Loss Prevention is its security. It should be more secure."
What is our primary use case?
We use Symantec Data Loss Prevention mostly for preventing and protecting against email threats. The tool tracks internal to external emails. Whatever attachment there is that's moving from internal to external is also tracked. If someone's sending a file, it would also be forwarded to the team lead or manager. The password for signing into the email should not be shared because when shared, it will be blocked. We have configured these policies in Symantec Data Loss Prevention. The tool also tracks whenever a user transfers data from one machine to another. These are our use cases for it.
What is most valuable?
What we like about Symantec Data Loss Prevention is that it's a very good product. We never faced any problems with its performance. It has very good performance. There was this RAM issue, but it was an internal issue which we've sorted out. Apart from the RAM issue, there are no other issues with Symantec Data Loss Prevention.
What needs improvement?
What could be improved in Symantec Data Loss Prevention is its security. It should be more secure.
For how long have I used the solution?
I've been dealing with Symantec Data Loss Prevention for almost four years.
What do I think about the stability of the solution?
Symantec Data Loss Prevention is a stable tool.
How are customer service and support?
The technical support for Symantec Data Loss Prevention is very good.
How was the initial setup?
The installation for Symantec Data Loss Prevention was straightforward. It took almost fifteen days to completely roll it out.
What other advice do I have?
I have experience with Symantec Data Loss Prevention. I've implemented it. I was the Symantec expert, and I've also implemented Symantec Endpoint Protection, Symantec Mail Security for Exchange, Symantec SharePoint, and Symantec network storage devices, in my previous projects.
Symantec Data Loss Prevention was deployed on-premises only because the customer requirement was to not forward the logs through the cloud directly, so the solution was installed on-premises.
In terms of the number of clients my company has for Symantec Data Loss Prevention, there are currently two thousand clients.
I would surely recommend the tool to others. Whenever my company goes to the customers, the team always recommends either Forcepoint or Symantec Data Loss Prevention.
My rating for Symantec Data Loss Prevention is nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Team Leader - Network Security Engineer at a tech services company with 11-50 employees
A robust platform that provides comprehensive support for features across network stages and email but needs to improve its support team
Pros and Cons
- "Among the many features, I like the comprehensive support for features across network stages and email. Customers are very happy with its prevention capabilities, as there is no delay in action when new policies are applied. Regarding incident response abilities, it is helpful, although we receive about 10%-20% false positives."
- "In my opinion, Symantec DLP could improve by offering a better online service option, making it more competitive compared to Forcepoint. Performance could also be enhanced, especially in terms of prevention capabilities. Additionally, it would be beneficial to add features that allow for better policy integration with GDPR, such as international credit, bank account, or identity management. This would make it more straightforward for IT, especially in regions like Indonesia."
What is our primary use case?
The main usage of Symantec DLP is concerned with its baseline performance. Also, from my experience, their support SLA seems slower compared to Forcepoint.
What is most valuable?
Among the many features, I like the comprehensive support for features across network stages and email. Customers are very happy with its prevention capabilities, as there is no delay in action when new policies are applied. Regarding incident response abilities, it is helpful, although we receive about 10%-20% false positives.
What needs improvement?
In my opinion, Symantec DLP could improve by offering a better online service option, making it more competitive compared to Forcepoint. Performance could also be enhanced, especially in terms of prevention capabilities. Additionally, it would be beneficial to add features that allow for better policy integration with GDPR, such as international credit, bank account, or identity management. This would make it more straightforward for IT, especially in regions like Indonesia.
For how long have I used the solution?
I have been working with Symnatec Data Loss Prevention for the past three months.
What do I think about the stability of the solution?
For stability, I would also rate it a seven out of ten.
What do I think about the scalability of the solution?
It can be complex to scale the product, especially for services. I find it suitable for enterprise-level companies with over a thousand employees.
I rate Symantec DLP a seven out of ten for scalability.
How are customer service and support?
In terms of support from Symantec, I have had a positive experience with their Data Loss Prevention (DLP) support. The support is helpful, but in Malaysia, we sometimes face delays due to integration policies.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up Symantec DLP can be complex. From the initial check and invitation, deploying Axion solutions requires human-added calls by email. If they provide more information, it would save us time and be less costly. We often deploy performance on Windows servers, AWS, web applications, and other platforms. Users find it easier when we restart with the fit for the OCA, avoiding a complicated installation process. If they added a feature that allows us to refresh it easily, it would be much better.
We typically use a SaaS model, but our other option, cloud office base, can be frustrating, so we often deploy on-premises.
What's my experience with pricing, setup cost, and licensing?
For pricing, I rate Symantec DLP an eight out of ten.
Which other solutions did I evaluate?
Comparing Symantec DLP to Forcepoint, I prefer Forcepoint for its more intuitive dashboard, better reporting, and smoother deployment process.
What other advice do I have?
Overall, I rate Symantec DLP a seven out of ten and would recommend it to other users.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Symantec Data Loss Prevention Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Data Loss Prevention (DLP)Popular Comparisons
Zscaler Zero Trust Exchange Platform
Varonis Platform
Microsoft Purview Data Loss Prevention
Forcepoint Data Loss Prevention
Digital Guardian
Code42 Incydr
Safetica ONE
Trellix DLP
Netwrix Endpoint Protector
McAfee Total Protection for Data Loss Prevention
Trend Micro Integrated Data Loss Prevention
Palo Alto Networks Enterprise Data Loss Prevention
Netskope Data Loss Prevention (DLP)
Amazon Macie
GTB Technologies Inspector
Buyer's Guide
Download our free Symantec Data Loss Prevention Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which solution do you prefer: Symantec DLP, Proofpoint DLP, or Microsoft Purview DLP?
- Can someone provide me an outline, or keep topics to consider when writing DLP procedures, in support of a policy?
- How do I integrate Zscaler DLP with Symantec DLP via ICAP?
- Symantec Endpoint vs. McAfee Complete Endpoint Protection: Technical Comparison Between Data Loss Protection Solutions
- When should companies use SSL Inspection?
- What software solution would you recommend to monitor user machines?
- What is the difference between "data protection in transit" vs "data protection at rest"?
- Looking for recommendations and a pros/cons template for software to detect insider threats
- Endpoint DLP for Mac Network
- Best alternatives to Digital Guardian for data protection?