Monday, May 11, 2009 1:55:25 AM
First off, Great Find on those additional Exobox reserved domain addresses. ExoAudit & ExoRecover added to the list. Bravo, BearsnBulls!!
To answer your question, there certainly is no reason for Exobox to hold for any type of bundle of an AV to complete the DLP solution. Case in point, before Symantec bought out Vontu, Vontu already had 1-in-4 Top Fortune 500 Companies using their DLP product. Vontu had no AV solution on hand. Neither did Provilla, prior to Trend Micro purchasing them out. Currently, there are no integrated all-in-one solution. DLP market is still pretty new & the folks using them now are still considered "pioneers" in using the technology, while DLP is still maturing. I really liked how Gartner emphasized that DLP is still maturing. That confirmed that DLP vendors are still in the early-mid R&D phase.
The AV Solution & DLP Solution are both complimentary to each other. As Punit stated in the video, Malware today is being used to profit by stealing data. Trojan Viruses are in the same boat as well, which means that the DLP solution is great for protecting against end-users, but does not protect against data leak from malware or virus. This is where the marriage of AV & DLP comes into play, to complete the DLP Solution.
In the video, Punit also stated that customers originally were looking for either or both a EndPoint & Network DLP Solution, but acknowledges that customers within the past 12-18 months were feeling more comfortable to just deploying an EndPoint. According to Gartner, "EndPoint DLP is the best technology available to address the malicious user use-case". Activity takes place at the EndPoint.
Current Problems Addressed from Gartner:
1.) Customers must educate employees who have access to sensitive data on how to handle data.
2.) Customers must change workflow, in order for the DLP solution to be effective.
3.) DLP is not a bullet-proof system that works automatically. Consultants & Engineers need to fine-tune Rules to achieve less false-positives results.
4.) Before deploying DLP, organizations must define what data is allowed & what data isn't allowed & which permissions to issue to end-users.
5.) DLP Solution will not be effective, unless the Organization/Customer comforms to the DLP Solution.
6.) Currently, DLP solutions can only see data being moved, copied or being used, but can not differentiate what data is allowed/not allowed of authorized users (false-positive results).
7.) Currently, DLP solutions can only see data being moved, copied or being used, but can not view the actual content of data. To make DLP even more effective, the next stage of development is for the DLP to be "content-aware".
I would also like to mention that Trend Micro is apparently delivering their DLP Solution both On-Premises of Customer Site & Cloud (SaaS). This really confirms that the future is really heading towards Cloud Technology and Exobox is definately headed the right direction. Again, Great Work Exobox Team!!
With everything I've researched on, I am quite shock on how I over-estimated the current DLP products currently sold on the market. It also looks like I under-estimated the deployment cost of a DLP solution (non-SaaS model) of actually being $70,000 or more. I have to concurr and stick by my statement of Exobox possibily being 2 years ahead of the current DLP leaders. I'm eagerly awaiting for the next PR or Gartner Review of Exobox.
Good Work, Everyone! Keep it UP!
To answer your question, there certainly is no reason for Exobox to hold for any type of bundle of an AV to complete the DLP solution. Case in point, before Symantec bought out Vontu, Vontu already had 1-in-4 Top Fortune 500 Companies using their DLP product. Vontu had no AV solution on hand. Neither did Provilla, prior to Trend Micro purchasing them out. Currently, there are no integrated all-in-one solution. DLP market is still pretty new & the folks using them now are still considered "pioneers" in using the technology, while DLP is still maturing. I really liked how Gartner emphasized that DLP is still maturing. That confirmed that DLP vendors are still in the early-mid R&D phase.
The AV Solution & DLP Solution are both complimentary to each other. As Punit stated in the video, Malware today is being used to profit by stealing data. Trojan Viruses are in the same boat as well, which means that the DLP solution is great for protecting against end-users, but does not protect against data leak from malware or virus. This is where the marriage of AV & DLP comes into play, to complete the DLP Solution.
In the video, Punit also stated that customers originally were looking for either or both a EndPoint & Network DLP Solution, but acknowledges that customers within the past 12-18 months were feeling more comfortable to just deploying an EndPoint. According to Gartner, "EndPoint DLP is the best technology available to address the malicious user use-case". Activity takes place at the EndPoint.
Current Problems Addressed from Gartner:
1.) Customers must educate employees who have access to sensitive data on how to handle data.
2.) Customers must change workflow, in order for the DLP solution to be effective.
3.) DLP is not a bullet-proof system that works automatically. Consultants & Engineers need to fine-tune Rules to achieve less false-positives results.
4.) Before deploying DLP, organizations must define what data is allowed & what data isn't allowed & which permissions to issue to end-users.
5.) DLP Solution will not be effective, unless the Organization/Customer comforms to the DLP Solution.
6.) Currently, DLP solutions can only see data being moved, copied or being used, but can not differentiate what data is allowed/not allowed of authorized users (false-positive results).
7.) Currently, DLP solutions can only see data being moved, copied or being used, but can not view the actual content of data. To make DLP even more effective, the next stage of development is for the DLP to be "content-aware".
I would also like to mention that Trend Micro is apparently delivering their DLP Solution both On-Premises of Customer Site & Cloud (SaaS). This really confirms that the future is really heading towards Cloud Technology and Exobox is definately headed the right direction. Again, Great Work Exobox Team!!
With everything I've researched on, I am quite shock on how I over-estimated the current DLP products currently sold on the market. It also looks like I under-estimated the deployment cost of a DLP solution (non-SaaS model) of actually being $70,000 or more. I have to concurr and stick by my statement of Exobox possibily being 2 years ahead of the current DLP leaders. I'm eagerly awaiting for the next PR or Gartner Review of Exobox.
Good Work, Everyone! Keep it UP!
