Proofpoint’s Brian Reed on the Data Loss Landscape
Proofpoint recently launched their inaugural Data Loss Landscape report, which showcases that humans are the cause of most data loss incidents. Brian Reed delves into the state of data loss protection and explains how enterprises can address the security risks posed by everyday workers.
Transcript
This is Text Strong tv. Hi everyone. Welcome back here to Techstrong tv and our next guest I might like to introduce you to Brian Reed.
Ryan is the Senior Director for Cybersecurity Strategy at Proofpoint. And uh, welcome to Text Drug tv. Brian, how are you, Alan?
Doing great. Thank you so much for taking the time to chat with it. Ah, it's my pleasure too.
So, Brian, you know, I said you're the senior director at Cybersecurity Strategy for Cybersecurity strategy, A proof point. A lot of people out here saying, oh, that sounds cool. You know, always this dude.
Um, tell 'em who this dude is. Yeah. Yeah.
So a little bit about me. So I've been in the cybersecurity industry since probably before it was called a cybersecurity industry. Uh, really interesting title.
I joined Proofpoint in October of 2020. Before that, I spent the last half decade at a little industry analyst firm called Gartner. Uh, I was the lead analyst and author for the last two enterprise data loss prevention magic quadrants and Critical Capabilities.
Those were actually published in 2016 and 17. Uh, I was part of the team that retired that magic quadrant at the end of 2017 as well, because, you know, data loss prevention, I mean, we can all go back to even when my friends and former colleagues used to call this the content monitoring and filtering market. It was sort of the, uh, you know, land of misfit boys and actually, Actually my, yeah, my good friend Rich Mogul used to have that bench.
Yep, Absolutely. Yeah. And Paul and Eric, Len Paul, yeah.
Very good, Fred. Yep. I was, uh, I took over after Eric had, uh, taken a brief hiatus from Gartner as well.
So, uh, yeah, I covered, uh, DLP from 2015 to to 17 and then moved on to some things like incident response and security awareness and CSO programs and some of those interesting things. Alan. So, uh, you know, again, I, before that I was a practitioner.
I deployed DLP, uh, in a number of different challenging environments. Biotech or you, uh, financial services. Yeah, I know.
Oh my gosh. Uh, like I said, the land of, uh, you know, unexpected challenges and uh, you know, unfulfilled promises, You know, but there is life after the magic quadrant, right? We have seen data loss prevention, you know, and I was always, I get into philosophically, is it data loss prevention or data loss protection?
Well, Yeah. And The other thing Too, yeah, I was gonna say the other thing too, I used to talk about it as DLP is the worst three letter acronym out there. It's, you know, data loss prevention or protection, whichever you call it, Alan.
Um, not all data types are covered. Not all loss scenarios are covered and you don't believe it or not, always wanna protect the data or prevent it from doing something. Particularly when you start thinking about things like insider risk and insider threat.
You know, if you've got a malicious insider, one of the worst things in the world you could potentially do to disrupt that investigation is tip them off. Or if you've got a careless employee, one of the worst things in the world you could do is not let them know they're being monitored. So there, there's a spectrum of control that the old DLP, uh, acronym doesn't quite cover very well.
Absolutely. Just thinking back, you know, I'm, I'm in the business probably longer even than you, Brian, 'cause it definitely was in cybersecurity when I started, but, um, I've seen so many BLP companies and, and, you know, different ways of getting that cat come and go. Anyway, we could spend all day talking about that.
You could what say is coming up in a couple weeks, we're doing the Security creators meetup, the old security bloggers meetup again this year. And if you're there, we we could raise a beer. Absolutely.
Ogle will be there. And, and we could talk DLP if you want. Absolutely.
But let, let's talk a little bit about Proofpoint, right? I think people have heard it, but they may not have heard it in the context of data loss. Um, but why don't you, if you had to, you know, yeah.
Assume they haven't heard a Proofpoint, Brian, what would you tell 'em? Yeah, Absolutely. And, and proof point's really been a, an interesting organization and I covered them obviously from my time at Gartner, my time as a, a consultant and practitioner before then.
You know, it's really an interesting company. A lot of people, a lot of your viewers Alan might know Proofpoint is, oh, that's that company that's really good at email security. Uh, it's certainly true and certainly the foundation for a lot of things we do.
But it's really been interesting, the shift that this company has taken from about 2017 to 2019 onward. The focus has really been on something Gartner talked about for a long time. People-centric security, uh, in human risk.
If you look at some of the acquisitions and, and where this company's gone, certainly doubling down on things like security culture, but also, you know, 2019 acquisition of Observe. It focused very much on insider threat. Looking at the acquisition in 21 of Intellis Secure, very focused on helping people get these DLP programs and insider risk, insider threat programs and cloud security programs going, uh, acquiring folks like Athena, very good at data governance and some really good, um, I hate to use the AI buzzword here, but AI ml, uh, sorts of ways to do data governance.
You made it, you made it seven, eight minutes. That's pretty damn good. And I'm not gonna try to, to say that again.
So, uh, No, it's, you need A shower after that word, but, Uh, yeah, you know what, it happens to the best of us. And then our most recent acquisition of tesson, which again, very well known, uh, for really functioning as, as what's called an an ICES or integrated cloud email security solution. But we see some really interesting use cases for that technology.
Some of the things we're going to be, uh, announcing and talking about at RSA, like our new adaptive email, uh, DLP capabilities, so bringing it back to, to DL and, uh, adaptive threat protection capabilities there. Excellent. Good stuff.
com is the website, if anyone. Absolutely. com.
And, uh, one of the big things, you know, again, has really been the shift, you know, using that great email foundation. But one of the things I know Alan we're gonna get into is our inaugural 2024 data loss landscape report that we, that we just conducted and release those results about some really interesting findings, uh, for your viewers that are, again, trying to get these, these sorts of programs started or trying to get sort of the technical capabilities and the, the, the details hired out in these programs. Just really good advice and guidance in, in that report that they can take back to their organization.
Well, you know, no pun intended, but you breached the subject, Brian. I know. Um, let's, let's jump into it then.
So this is a, this is an inaugural report. You haven't read one of these before. Let's first kind of scope it and then we'll dig into the results.
Fine. Yeah, Absolutely. Yeah, so this is a report we surveyed over 600 professionals across 12 countries, 17 different vertical industries.
So we really tried to, to paint this very wide swath of survey data to really get a feel, you know, again, if, if you sort of, you and I are both a bit old school and, you know, we've seen things like data security programs typically be applied to, you know, places that were very heavily regulated or had a lot of intellectual property. So again, think financial services, think healthcare, uh, think, you know, manufacturing, typically those were the sort of the big three verticals, but we really wanted to look at, you know, some other verticals that, that certainly have data security concerns and needs. Absolutely.
Um, you guys did this yourselves internally. Did you have a partner working with you? Uh, what's the story?
Yep. Yeah, we, we did manage it internally. We, we, for these kinds of survey results, we, we do partner with firms to be able to pull the, pull all this different data together.
Certainly things like language standardization, the like, so again, when you're, when you're talking across a do dozen different countries, not everybody, uh, is us English of course, or UK English. So, you know, we needed to do some internationalization and get some of those results together. But, uh, you know, really pretty proud of the, uh, the results that we've curated.
There's some really interesting, uh, key findings that, that we found and put together here. Perfect. Alright.
Um, let's dive into the findings. Yeah. Yeah.
So I, I think one of the big ones that's probably no shocker to anybody out there, right, is data loss is, is really a widespread problem, but it's largely preventable. But, you know, believe it or not, you know, data doesn't lose itself. You know, there's typically, I used to talk about this when I was an industry analyst.
There's either a person or a broken business process behind that loss scenario or that loss incident. And what we found in our survey is that the average organization experiences, uh, on a, on average 15 significant data loss incidences per year. So that basically works out to a little more than one a month.
One a month. Yep. And, and 71% of those people, it, it's just the careless user.
So if you think about, there's really three main types of users that that result from, from a data loss scenario. There's the, what I call the careless or the accidental user. You know, this is the good user making bad decisions with good apps and good data.
You've got certainly users that could be compromised. Their credentials could be, you know, hijacked by whatever sort of third party, you know, think, you know, evil proxy, some sort of man in the middle attack, malicious, so off token in, in our cloud app world. And then the third type is there's the truly malicious insider out there.
But the other point of the survey, 71% of those lost scenarios were careless activity. Again, the good users bad decisions with good apps and good data. Fair enough.
Um, wow, that is a lot. How do you define significant? Yeah.
And, and that was really something that we sort of left up to interpretation there. I would love to dig into that further. Um, you know, next year in, in our, uh, you know, running this report for a second year in a row and ask some more questions about, you know, how they define significant.
Is it a, um, you know, material loss? You know, certainly in, in the wake of, uh, the new security exchange commission rules here in the us we now have a four day disclosure rule, uh, in place. So, you know, some of the respondents probably took that into account.
Is this something that if we're a public company, is this some, you know, is this related to SEC materiality? Do we need to disclose this? That would certainly bubble up to major, but, uh, it was really a lot of that was left to the respondent to determine, and we could, we could definitely dig deeper into what would've been that motivation for clicking that response.
Fair. Um, next up, Brian, let, let's talk a little bit about what, you know, what enterprises can do. I think you've already outlined that the problem, unfortunately more often than not is the person behind the keyboard.
It is, Or people behind the keyboard designing the processes and flow, which control our data and data flos, uh, data flow. Um, so obviously the problem or the solution has to start there, right? With people, but, you know, sometimes we can use technology and process to, to compensate if you will.
But talk to us, what, how do you think what, what enterprise to do? I, I think one of the classic cases that nobody's really had a good answer for for years and years has been this notion of misdirected email. And we've all done it, right?
We've all sent the wrong email to the wrong address. Alan, I could have sent, uh, an email to your personal email as opposed to, you know, your one for tech strong TV happens all the time, especially in this world we live in where work and personal is so intermingled. So how do you stop that besides telling people, Hey, be sure to look over that.
Well, you know, it's great to have people be diligent before they hit the send button, but what happens, you know, after you hit send and up until that point through technology that could say, Hey, look, you've never emailed Alan's personal email before. Maybe we should flag that to the user and say, Hey, wait a minute, you know, you're emailing something to everybody at Proofpoint. Why are you emailing this to an external party?
So those sorts of things. Using some, some of the things that we've been doing for years, particularly around machine learning and smarts and understanding, you know, users', normal patterns of behavior. Are there things that we can create these speed bumps with technology to give people those moments of pause to say, Hey, wait a minute.
That's right. Let me go back and correct myself. And then on the backend, is there technology to catch that and say, Hey, this looks like it could be a classic example of misdirection.
Brian's emailing a bunch of people internally and he's got this one email to an external person with some sensitive data attached. And this backs up our findings too. Alan, what's interesting is, you know, we see misdirected email really being a huge problem out there.
You know, one in three organizations have experienced this in the last year, you know, ha have admitted to users sending one or two emails to the wrong recipient. What happens is 84% of the time there's an attachment on that email. So it's not just about the text of what's in the email, it's the data riding along with it.
Yeah, a absolutely. Um, look, it's confusing in a world where we seem to have multiple accounts, you know, all of us have multiple mail accounts. Yeah.
We are on multiple devices and I'll tell you, you know, the reply versus reply all thing has sunk more people. Yep, absolutely. Anything else out there?
I think, I mean, I've made that mistake. You've made That. Sure.
We all Done that. And, you know, so it's these little things and I, I tend to stay away from the normal male clients. I like to try weird stuff or new stuff or cutting edge stuff.
And so I've been trying a couple of these clients that, you know, sort of have a copilot in neighborhood, if you will. Yep. And I'll tell you that seems, believe it or not, to really help It does.
Absolutely. And, and what it does is, you know, it creates, like I said, those moments of pause, but it's also helpful because, you know, guys like you and I, were super busy. We're responding to stuff all the time.
We've got things flying at us a million miles an hour. One of the problems that we saw in the survey, again, and I'll mention that, that AI word, generative ai and the use of it is one of the biggest areas of concerns that respondents had. So, you know, you talked about using, you know, non-standard email clients, but using tools like Grammarly and Chat GPT and Google Gemini and Bing Chat and copilot all these different things.
There's a lot of power and utility and, and efficiency built into those, you know, but there's also a lot of concern. One of the, um, top five, uh, concerns that, that our respondents came back with was browsing Gen a gen AI sites. And, you know, how are they alerting that?
How are they controlling that? Uh, so again, anything that sort of takes you beyond maybe that non-standard client and has you go into that, that gen AI interface, you know, that's a concern if, if we think about how unified collaboration works these days, it's not all in the mail client. You know, how many times are we emailing links to where, let me go download something from SharePoint or Dropbox or Box to, to then, you know, our productivity is so interweaved with what I would call these anchor platforms.
I, I agree with you, man. Crazy stuck. Yeah.
Crazy stuck. Brian, we're almost outta time here. Yeah.
But for people who maybe wanna get the full report and, and dig in a little bit, where could they go? Yeah, certainly our website, we've got a landing page, uh, off of the front page. It's the 2024 data loss landscape report.
com, uh, to go download that report in full. And again, if you're looking at establishing a program, sort of you, you've maybe, you know, gone through DLP programs of years past and looking to, to think about things different differently. Or maybe you've got some competing pressures, uh, in your own organization where you might have an insider threat program, you might have a DLP program, a data governance program.
There's some really good metrics and guidance in there that really help you, you know, sort of build the technical case for why we need to do this. Absolutely. Brian, I want to thank you for coming on Tech Trunk tv.
Keep up the great work There is Life After Gartner. Certainly there's even a DLP or, or data loss, you know, market out there after the end of the, of the quadrant. Uh, maybe we will see at RSA are you planning on attend?
I will be there, Alan. So we'll, uh, we'll definitely catch up there in person, check out, Make that, there's something for that, uh, Wednesday evening is that, uh, meetup I was telling you about? Absolutely.
Thank you so much. Yeah. Alrightyy Ryan Reed, senior Director Cybersecurity Strategy at Proofpoint here on Textron tv.
We're gonna take a break. We'll be right back.