Opens in a new tab
vmblog logo 2024 wht (updated)

The Great Deflate – Plugging the Gaps to Reduce Data Loss

Share: 

David Marshall | Published: October 10, 2022

By Jaimen Hoopes, Vice President, Forcepoint

After years of experiencing a hiring frenzy, the tech industry became inflated with employees of all types be it sales, engineers, customer support, marketing and others. With present market dynamics in play, more than 30,000 tech workers have been laid off so far this year and even more leaving through voluntary resignations. We are on the heels of what could be coined “The Great Deflate.”

And as more companies look to cut costs and size down in the months ahead, or deflate, enterprises need to prepare and protect themselves, and nowhere is this more important than when it comes to protecting data assets. Companies across industries now find themselves in an increasingly vulnerable position when former employees can walk out the front door with more than their box of personal items.

It’s the job “leavers” who represent a big threat to Fortune 500 enterprises trying to protect their data and mitigate loss. Mission-critical data such as intellectual property, source code, scientific patents, and customer lists are just some of what employees can take when they depart. And given the average attrition rate of 18-20 percent year over year, that’s a significant risk for data assets to flow out of your company. In the midst of the Great Deflate, it’s time we rethink the approach for preventing critical data loss.

Understand Points of Vulnerability

It’s no surprise that the job functions and departments that handle data most critical to a company’s success tend to be where most data leakage incidents occur. Bad actors go where the gold is and the gold today is data, specifically, intellectual property. This makes departments like Engineering, Science/R&D and Sales such high-risk functions, for within these departments lie some of an enterprise’s most valuable data, which could cause significant damage if shared outside the organization.

While not every leaver will steal, lose or misplace your data, anyone with the right access privileges can download, email, or move valuable IP to their personal devices or cloud accounts. The leavers representing the highest risk are disgruntled or frustrated, ignorant of policy and confidentiality agreements, or feeling entitled to the proprietary data and want to use at their next job. The typical points of exfiltration are everyday business tools and services like emails, websites, cloud apps, and collaboration tools like Slack and Teams. With people and information spread far and wide, security teams need better visibility to everything, at all times.

Enhance Data Classification Accuracy with Artificial Intelligence

Organizations often turn to data classification technologies to identify all the types of data they own to prevent theft or misuse. However, traditional classification methods are highly manual, depending on individuals to make important decisions on the value of data. Inaccurate classification generates large volumes of false positives and false negatives in data loss prevention (DLP) policy enforcement. Sorting through these false alerts wastes time and resources, leaving you vulnerable to external threats like malware or ransomware and from insider threats like job leavers. Ultimately, you can’t protect what you don’t see.

A new wave of intelligent data classification solutions greatly improves both visibility and accuracy. Instead of security pros having to manually train the system, the modern data classifier uses AI and machine learning to mimic neural networks and learn automatically “on the fly.” The AI-based classification engine, then, is predictive and continuously self-learning, which becomes more accurate and efficient the more you use it over time. You can apply labels or metatags for everything from source code to employee email and automate controls for how this information can be accessed and shared. This level of automation can directly feed your DLP engine, which brings us to our third point, security enforcement.

Automate Policy Enforcement in Every Channel

If you know where your data is and who has access to it, you’re giving your security teams a fighting chance against inadvertent or malicious data theft. Don’t rely on detection of suspicious activity alone, which is what most DLP approaches have long focused on. Instead, shift your DLP strategy to proactive prevention and automated enforcement.

Start by unifying policy management for all the channels where you use data. By combining data classification with data security for web (SWG), cloud (CASB), private apps (ZTNA), network (SD-WAN with NGFW), a single policy can prevent proprietary data from leaving with the employee. Your HR and security teams can create an automated process that flags the actions of employees who are about to exit the company. Access controls with built-in data protection and threat prevention can stop confidential information from being downloaded and uploaded to websites, cloud apps, and private apps, including from unmanaged devices and BYOD.

You can incorporate analytics that help identify risky behavior-for example, an uncharacteristic transfer of a massive number of files or copy/pasting of sensitive data from a confidential document into another. By using DLP that adapts automatically to risk and is informed by self-learning data classification, you can be more confident that your data is secure and that your organization complies with privacy regulations (GDPR, CCPA and others) around the world.

Adopting a holistic data security program, which offers a broader view of where data resides within an organization, helps you close gaps you didn’t even know existed. Incorporating technologies that unify management, adapt to risk, and provide full visibility and classification more than even the odds. They can help you simplify security and automate prevention to mitigate the risk of data loss, especially from the threat posed by job leavers.

##

ABOUT THE AUTHOR

Jaimen-Hoopes 

Jaimen Hoopes is Vice President of Product Management at Forcepoint managing the data security business and suite of products. He has 18+ years of global experience in cybersecurity and has been focused on enterprise security, product innovation, and cloud transformation. In this role, Jaimen oversees continued innovation of Forcepoint DLP, cloud migration, endpoint technologies, the Forcepoint analytics platform and also the strategic integration of Forcepoint products into customer ecosystems.
 
Since joining Forcepoint, Jaimen led the new product introductions of Forcepoint Classification and Forcepoint Visibility which provide AI and ML to help identify sensitive customer data to reduce false positives where standard catalogues, libraries, and regular expressions have been falling short in the market.  Jaimen is also leading efforts to incorporate Forcepoint DLP into all of Forcepoint products including the SSE offerings providing the strongest DLP coverage across all egress vectors from a single vendor in the market.
 
Prior to Forcepoint, Jaimen led product management for Digital Guardian where he was responsible for their migration to the cloud, providing SaaS and MSSP services to customers. Jaimen also led product management for SIEM products at McAfee.
 
Jaimen received a Master of Business Administration and a Bachelor’s in Computer Information Systems from Idaho State University.