THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, October 19, 2022
Organizations are now implementing robust DLP practices to prevent rising attacks and enterprise data breaches.
FREMONT, CA: The DLP approach has undergone significant changes over the last few years to keep pace with the complexity of managing cybersecurity. Data inspection, discovery, notification, enforcement, and management have all improved over the past few years.
Based on our internal research and interviews with a panel of diverse experts on data loss, three bleeding-edge trends in Data Loss Prevention (DLP) are identified that will have the biggest impact on this market within the next three to five years.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Let us understand the three priority areas of data loss prevention.
Analyzing behavior and context: Large organizations with sophisticated machine-learning capabilities have begun identifying, flagging, and characterizing potentially malicious activities using contextual information. A behavioral analytics approach collects data from multiple endpoints, passes it through behavioral-analytics tools, and infers context, such as intent and secondary actors.
Integrated contextual information can be incorporated into in-house and vendor DLP solutions, and identity and access management tools can use to determine user access to data. Access control enforcement and incident triage can also be informed by it. DLP systems can automatically revoke access to an organization's suspected actors and the inferred secondary actors upon detection of an incident.
The organization needs sufficient telemetry to collect data across the technical estate and advanced analytics to enable this capability. High-tech companies are exploring this functionality today, using mostly custom solutions, while many vendors offer nascent versions as part of their DLP tools.
Integration of privacy and regulatory compliance: A growing number of compliance management solutions combine common data-management capabilities with dynamic alerting and rule-based enforcement.
Data is tagged both manually and automatically per regional regulations. Existing DLP infrastructure can encode rules controlling data transfer based on tags. These rules can then be automatically enforced and notified.
Regulatory reporting technology can also be integrated with DLP solutions to automatically generate audit-ready compliance reports, reducing compliance burdens and increasing transparency.
A global compliance solution that can integrate with policy decision points and data classification tools is key to achieving this capability. The requirement is especially challenging for large, global organizations. The lack of automated integration has resulted in few organizations achieving this milestone.
Audio-data exfiltration: DLP can be implemented to safeguard audio data by combining natural-language voice recognition and AI-based text-to-speech technology. Analyzing audio and video files within a network can complement optical character recognition and regular expression matching for detecting keywords and patterns in text documents.
Some organizations are reluctant to add these capabilities since employees and clients may perceive them as intrusive. Before implementing it, it is important to consider the potential impact of live audio inspection on the company's culture.
More in News