The Digital Guardian Platform from Fortra (formerly HelpSystems, acquired in late 2021) is a cloud-delivered data protection platform purpose-built to stop data loss by both insiders and outsiders on Windows, Mac and Linux operating systems. Additionally, Digital Guardian User Activity Monitoring enables users to detect, investigate and mitigate suspicious user actions to ensure sensitive data doesn’t get out. And Digital Guardian for Data Discovery provides visibility and auditing of sensitive…
N/A
Microsoft Purview Data Loss Prevention
Score 7.1 out of 10
N/A
Microsoft Purview Data Loss Prevention is used to provide intelligent detection and control of sensitive information across Office 365, OneDrive, SharePoint, Microsoft Teams, and on the endpoint. It also helps prevent data loss through identifying and preventing risky or inappropriate sharing, transfer, or use of sensitive data on endpoints, apps, and services.
Digital Guardian consists of an elite team of professionals, who easily [identify] any threat and the possibility of cyberattacks. Further, Digital Guardian has the ability to prioritize the handling of the database, based on the risk that each carries. Finally, Digital …
DG is the only DLP platform I've used at my current employer. I used it at my previous employer as well, and we ended up abandoning future deployments of it due to many problems caused by it, especially with web browsers. This was in 2015, rather than the 2018 version I used …
Varonis provided great visibility into file permissions and audit records. It did not provide DLP controls for things like email, and endpoints therefore making it incomplete to provide proactive controls against DLP threats.
Symantec or now? Brocom. Forcepoint, GPV. I'm trying to think of, there's a couple more. I can't think of the top of my head. I would say closer to the bottom then rather than the top. So because of the fact that yes, it integrates well. But in terms of the actual …
Not used any product other than Microsoft Purview Data Loss Prevention. As I mentioned in my earlier point that we did all the researches for the best suitable product for our environment, but Microsoft Purview Data Loss Prevention proved to be best and is working as per our …
There are much more comprehensive and granular DLP solutions out there like Trellix and Sophos but ultimately they are expensive and require significant administrative oversight for implementation and deployment. For a company of our size, they are just not economically …
The DLP in Exchange Online and Purview by proxy is okay, but fails to catch a lot of HIPAA-specific information. We supplemented with Barracuda to make up for it. Purview is still better at identification across the entire tenant though, Barracuda is just doing our email DLP.
The DLP was already part of our tenant so we saved money by using it. With others, we would have to built/implement VMs to connect to the tenant, which we were not willing do. Since we had access to it, we decided to stick with it and we are happy with that result
As the customer already had Microsoft Office 365 E5 license, it made sense to implement Microsoft Purview Data Loss Prevention instead of other products.
When Digital Guardian works well, it really is fairly seamless. You may notice a tiny bit of additional lag on some programs, but for the most part, when it functions properly, it's fairly unobtrusive. Therein lies the rub...when it functions properly. We had frequent program conflicts with Digital Guardian. We had one issue that caused Digital Guardian to completely cripple Microsoft Outlook, and similarly cripple Microsoft Excel. It took Digital Guardian weeks to even release any kind of fix for the issue, and the first several fixes did not, in fact, resolve the issue. We ended up having to completely remove it from our environment and are still waiting for a confirmed more stable version, as it simply caused far too much disruption to our user base, and also consumed an extremely large amount of time from our admins dealing with user issues related to these problems.
I would highly recommend Microsoft Purview Data Loss Prevention for companies that are utilizing Microsoft technologies based on the strong integrations. If a company is using other technologies (e.g Google Workspace), then Microsoft Purview Data Loss Prevention would not be a good fit and would be difficult to implement/manage.
Email data leaks - DLP software must prevent certain actions to work well. Let's say you try to copy and paste an SS # to an email, or upload sensitive data to your personal email account. Guardian Edge can prevent that, and then alert administrators that it happened
Unauthorized file copies - Guardian Edge can also prevent users from copying files from a sensitive restricted area to somewhere else where they might be able to more easily exfiltrate it. A good example would be from a company file share to a less secure server or their own home drive
Alerting Administrators of suspicious activities - Any time a user uploads a file to an upload service or personal email, it is logged and reported as an event to be reviewed. If it found nothing in scanning the data, it will still notify you that it happened so you can review it yourself to confirm it wasn't a false negative.
It's a great product from an information protection perspective, as it can identify different types of data across tons of different locations.
It's great at applying standard regulatory frameworks, like HIPAA, to management actions so you can work towards being as compliant as possible.
The eDiscovery tools are very helpful when it comes to managing legal holds and discovery requests, as it's simple to freeze accounts or hold at points in time for discovery.
Digital Guardian consists of an elite team of professionals, who easily [identify] any threat and the possibility of cyberattacks. Further, Digital Guardian has the ability to prioritize the handling of the database, based on the risk that each carries. Finally, Digital Guardian has [an] attack sequence that is detailed, progressive, and sustainable.
Symantec or now? Brocom. Forcepoint, GPV. I'm trying to think of, there's a couple more. I can't think of the top of my head. I would say closer to the bottom then rather than the top. So because of the fact that yes, it integrates well. But in terms of the actual functionality of DLP, there are other requirements that they just don't have the features for yet.
I think it's integral to everything, it has to be positive and the positivity has to be the ability to use Purview in a situation for an organization. For us as a provider, we're not sure if we need your services or we think we're doing this thing correctly. We also evaluate compliance team. So first thing that we may do is if we don't have a footprint in the organization and we don't know what their data parameter or their data flow capabilities are, if we don't think that they're controlling it confidently, we validate and verify. We may do a content search and that content search immediately will be the most revealing thing. They'll be like, "alright, so right here on this diagram, this and this area are the areas that you have protected that are capable of protecting CUI. How come your CUIs in all of these 18 other different areas in which you see as like scope creep happens because the enforcement mechanisms haven't been tested, validated or whatever, or haven't been effective." It allows us to do quick cleanup, quick discovery, and things like that for new onboarding clients.