Risk Adaptive Protection with Enterprise DLP – what is it and why do you care?
Download resourcesAbout this session
Randy Sjolin, Forcepoint's regional account manager for Canada, opens by defining risk-adaptive protection: instead of a binary DLP rule that fires on every social insurance number, the platform scores each user's risk from recent behaviour and decides dynamically whether to allow, coach, notify or block, claimed to cut security-operations workload by about 75 percent. Senior engineer Joseph Karas then takes over. He maps the DLP channels (cloud, network, endpoint, data at rest), then explains the indicators of behaviour, more than 200 signals collected by the Neo agent and rolled into a 0-to-100 score over a 30-day window, with five risk bands each tied to its own action. His running example is a flight risk: applying for jobs on LinkedIn, disabling the Windows firewall, hoarding files, then uploading them. A live demo shows the score climbing from zero to a coaching prompt, plus the console with 128 predefined policies and GDPR classifiers. Audience questions cover BYOD and mobile (handled by the CASB or Forcepoint ONE rather than an agent), VDI, on-prem versus cloud components, OCR, certifications and Forcepoint's Raytheon history.
Do you have any idea how much time it will take to scan, identify, and secure every organization file containing sensitive information? Me neither, data are everywhere! Fortunately, you don’t need this information to implement an effective enterprise program. In this session, we’ll focus on the scope, processes, and roles & responsibilities. Join Benoit for a pragmatic conversation based on lessons learned and emerging practices.
Key takeaways
- Move DLP out of monitor-only mode by tying enforcement to a per-user risk score: routine business use by HR or finance stays allowed while the same action from an unusual user is coached or blocked.
- Look for the insider-exit sequence (job applications, disabled security controls, bulk downloads, then uploads) as a chain of behaviours rather than a single DLP event.
- Reduce false positives by adding context to classifiers: a nine-digit number alone is noise, a nine-digit number next to a name and address is an incident.
- Restrict local admin rights and enable agent tamper protection; risk-adaptive controls are moot if users can disable the firewall or uninstall the endpoint.
- Cover BYOD and mobile through a CASB or zero-trust broker that blocks downloads and encrypts files, since behavioural analytics require an agent that unmanaged devices will not accept.