The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Protecting People
Protecting People artwork

The 1% Problem: Insights and Implications from the 2024 Data Loss Landscape report

Protecting People · 2024-04-02 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

30 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality5 / 20
Guest Caliber4 / 20
Specificity & Evidence9 / 20
Conversational Craft4 / 20

Proofpoint's new Data Loss Landscape report addresses a critical gap in cybersecurity: understanding not just how attackers infiltrate systems, but what they actually exfiltrate. The research found that 85% of organizations face data loss incidents annually, driven primarily by human behavior rather than technical vulnerabilities. The most striking finding is that just 1% of users generate approximately 90% of DLP alerts across cloud and endpoint environments, suggesting concentrated risk. The report categorizes data loss into three distinct patterns: careless users (71% of incidents, including misdirected emails and unauthorized cloud syncing), compromised accounts (96% of cloud tenants experienced precision attacks), and departing employees (87% of anomalous file exfiltration). Key macro trends amplifying the problem include cloud workflow adoption, hybrid work models, and generative AI tool usage. The report emphasizes that effective DLP strategies must move beyond blanket policies to risk-based, behavioral approaches that distinguish between user categories, implement forensic evidence collection, and address emerging risks like employees uploading sensitive data to ChatGPT or using GenAI for code generation. Industries like healthcare and finance require prevention-focused rules blocking PII, PHI, and PCI data movement, while education sectors may emphasize user education and justification prompts instead.

Key takeaways

  • →Just 1% of users are responsible for approximately 90% of DLP alerts, suggesting security teams should focus detection and response efforts on high-risk user populations with access to sensitive data like HR and finance.
  • →Departing employees cause 87% of anomalous file exfiltration in cloud environments, making offboarding programs - including contractors and third parties - critical to data loss prevention.
  • →Organizations should implement risk-based DLP strategies that distinguish between careless users (requiring warnings and policy education), compromised accounts (requiring incident response), and malicious insiders (requiring legal and compliance involvement).
  • →Generative AI tool usage is the fastest-growing area of DLP concern, with risks including employees uploading meeting transcripts to ChatGPT, developers inadvertently committing copyrighted code, and lawyers using AI-generated false information in cases.
  • →Data loss incidents result in significant business impact: 90% of affected organizations experienced negative outcomes including business disruption (50%), revenue loss, and reputational damage (40%), with regulatory fines up to 4% of annual revenue under GDPR.

Guests

Atir ClarkBrian Gleason

Topics in this episode

Multi-factor authentication (MFA)Data loss prevention (DLP)User behavior analyticsinsider threat detectionProofpointData Loss Landscape ReportGenerative AI risks (ChatGPT)Cloud data exfiltrationPrecision phishing attacksDeparting employee risk management

Questions this episode answers

What percentage of organizations experienced data loss incidents in the past year?

According to Proofpoint's Data Loss Landscape report, 85% of organizations experienced one or more data loss incidents in the last year, and more than 90% of those affected faced negative outcomes such as business disruption or revenue loss.

What is the 1% problem in data loss prevention?

Just 1% of users across sampled organizations were responsible for generating nearly 90% of DLP alerts, indicating that security teams should focus on identifying and monitoring high-risk user populations with access to sensitive data like HR and finance records.

What percentage of departing employees cause data exfiltration in cloud environments?

87% of anomalous file exfiltration among cloud tenants was caused by departing employees, making offboarding processes a critical control for preventing data loss.

How should organizations handle careless users versus malicious insiders differently?

Careless users (causing misdirected emails or unauthorized cloud uploads) should receive warnings and policy education, while suspected departing employees or malicious insiders displaying behaviors like large file downloads or visiting competitor websites should trigger involvement of compliance, HR, and legal teams.

What are the main risks of using generative AI tools like ChatGPT in the workplace?

Employees may unknowingly upload sensitive company information such as meeting transcripts, product roadmaps, or code snippets to public GenAI platforms, risking exposure of trade secrets, regulatory violations, and potential litigation from copyright infringement.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode contains a handful of concrete statistics (the 1% of users driving ~90% of alerts, 87% of anomalous cloud exfiltration from departing employees) that are genuinely interesting, but the surrounding discussion is padded with obvious DLP advice and generic category framing. The ratio of novel signal to filler is low for a 31-minute episode.

1% of users were driving almost 90% of the alerts in a sample of 30 organizations
87% of anomalous file exfiltration among cloud tenants was caused by, uh, employees who were departing

Originality

5 / 20

The entire episode is built on well-worn DLP frameworks - careless/compromised/malicious user taxonomy, departing employee risk, cloud sprawl, GenAI concerns - with no contrarian or first-principles arguments. The '1% problem' framing is a mildly interesting angle but is not developed into any novel thesis.

cloud workflows have really changed how organizations store, access and synchronize data. You know, needless to say, hybrid work has shifted the way people consume data
organizations really need to rethink their DLP strategies to address the underlying cause of data loss, which is ah, people doing things that they shouldn't be doing

Guest Caliber

4 / 20

Both guests are internal Proofpoint staff product marketing managers, not independent practitioners or operators who have built and run DLP programs at scale. This is a vendor promotional conversation dressed as independent analysis, which significantly limits the credibility and depth of testimony.

Atir Clark is our staff product marketing manager for Proofpoint and our information protection platform
Brian Gleason's also joining us. He's another one of our staff product marketing managers at Proofpoint

Specificity & Evidence

9 / 20

The episode cites a reasonable number of named metrics (85%, 1%/90%, 96%, 54%, 87%, GDPR 4%, HIPAA $1.4M ceiling), but these all derive from Proofpoint's own platform and a survey of just 30 organizations, with no external validation. Anecdotal examples (Russian subsidiary, legal firm, food and beverage company) are kept deliberately vague.

between January and September of last year, 96% of tenants were subject to precision attacks
under the laws such as GDPR, you can get fined as much as up to 4% of an organization's annual revenue

Conversational Craft

4 / 20

The host is a Proofpoint employee interviewing fellow Proofpoint employees about a Proofpoint report, producing an unambiguously promotional exchange. There is no pushback, no methodology scrutiny, no challenging of sample size or self-reported survey bias, and the host explicitly offers to give guests a 'plug' mid-episode.

I'll actually give you a plug here for a minute and a bit of a platform
I'll even give you a little bit of a lead in and a plug to some of the blog posts

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B48%
  • Speaker A37%
  • Speaker C14%

Most-used words

data62loss24brian21report21organizations17user15information14place13example13proofpoint12security12careless11policy11users11cloud11departing11

Episode notes

In the digital age, data loss prevention is a top concern in cybersecurity as organizations strive to safeguard sensitive information in the hands of careless, compromised and complicit users. Today’s episode of Protecting People dives into the inaugural Data Loss Landscape report. Our guests, Itir Clarke and Brian Gleeson shed light on the alarming statistics and insightful findings around data loss and people-based risk. One of the most surprising findings: a mere 1% of users were responsible for almost 90% of data loss alerts. The conversation also goes into exploring human-centric approaches to DLP, including: How understanding user behaviors can influence policy and shape effective controls to mitigate data loss risks The impact of departing employees on data security and the need for proactive strategies to prevent unauthorized data exfiltration The importance of continually evaluating and adapting DLP strategies to address evolving threats Tune in to discover actionable strategies and best practices for safeguarding sensitive data in an increasingly complex threat landscape.Resources mentionedData Loss Landscape report: Blog posts about generative AI

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Protecting People podcast. I'm Brian Reed, senior director of strategy here at proofpoint and your host. When we think about cybersecurity, we often focus on how attackers are getting in, rather than what they're actually taking out. But data loss prevention is a critical part of the cybersecurity equation. After all, attackers wouldn't bother infiltrating your environment if there wasn't something worth getting out of it. And according to a new report from proofpoint, a staggering 85% of organizations experience one or more data loss incidents in the last year. Staggering, yet in many ways. And not surprising, because no matter what kinds of technical walls we try to build around our most sensitive information, data loss is fundamentally a human problem. People need to access that data to do their jobs, but they're also careless with it. They can sometimes get compromised by attackers, or in the worst case, they can be malicious and complicit in stealing it. So joining me today to talk about the findings from the Data Loss Landscape report are two of our key members of the team that helped put together this inaugural edition of the Data loss landscape. Uh, Atir Clark is our staff product marketing manager for Proofpoint and our information protection platform. She's got 20 plus years of high tech and security experience, including more than six years here at proofpoint. And before proofpoint, Atir, uh, was in several roles at Cisco, Brocade and Sun. So Atir, welcome, great to catch up with you.

Speaker B: Thanks. Thanks, Ryan.

Speaker A: Yeah, and Brian Gleason's also joining us. He's another one of our staff product marketing managers at Proofpoint and he's got 15 plus years of experience in tech, most recently before Proofpoint, where he's been the last few years, uh, it was at Check Point and Marble Security. Proofpoint, ironically enough, had acquired back in 2015, uh, as well as a long stand at BEA Systems. So Brian, welcome to you as well.

Speaker C: Great to be here, Brian.

Speaker A: Yeah, and we've got, uh, we're over quota on Brian's, so that's a good thing, I guess. But so Atir, uh, and Brian, let's. This is the first time we're doing this report and this is the inaugural, as I mentioned, addition to this report. Would love to just get both of your takes on, you know, what, what drove proofpoint to create this report and what are we hoping to provide in value to those who are reading it?

Speaker B: You know, one of the things we wanted to do is sort of understand the scale of the problem. The drivers behind people put DLP programs together, of course, look at the common use cases that need addressing, also the type of behaviors. Who is behind the data loss problem? Right. And those were the ultimate drivers for the report because that can actually influence policy and it influence the controls you put in place and the types of problems you look for. Um, sometimes you can do more proactive dashboards to watch for these types of behaviors. Those were sort of the reasons why we decided to put this report together.

Speaker C: Yeah, and the way we did it in the report, Brian, was we really explored all the current approaches to data loss prevention and insider threats and, and how they are holding up against current macro challenges such as data proliferation, sophisticated threat actors, and most importantly, Genai.

Speaker A: Uh, yeah, I was waiting and we're about four minutes in and we tripped the AI buzzword bingo card so we can go ahead and fill in the uh, top right corner square, I guess is probably where that's at on most people's cards. But I know that we've got a lot of great data in this report. Report. I, I'd love to get both of your takes on what maybe were some of the more surprising findings that we uncovered as part of this report and the research.

Speaker B: So in some ways, you know, it wasn't surprising to me that we found out that 71% of the respondents said the main cause of data loss is careless users. I mean, I'm sure I tripped our, um, DLP systems at proofpoint myself. And it does happen. It happens. Uh, because, you know, I was trying to Send my own W2 to my own self for tax purposes and I couldn't get it through the system in that case. But there are other reasons. Right. Uh, you might end up sending a misdirected email. I caught myself sending an email to the wrong person the other day. That's a very common scenario. You might want to send something to your own personal cloud account, for example. I mean, in my case it was a W2 and my own personal. But I mean, what if you were working on a project and you wanted to continue working from home and decided to send that to your own personal account? Well, that, that is an issue. Right. That is, uh, that can be against the corporate policy. And hence, you know, you will have the DLP controls in place to prevent that from that type of data exfiltration from happening. But the thing that actually surprised me the most was the fact that 1% of users in a sample of companies, cloud tenants that we looked at, or endpoint tenants we looked at as well, were driving almost 90% of the alerts. So 1% of users were driving almost 90% of the alerts in a sample of 30 organizations. That was very interesting and in some ways, of course, supported our survey findings that said the most important people were to watch were the ones with access to highly regulated data, highly sensitive data like hr. Ah. And finance officers.

Speaker A: Yeah, and that's super interesting to me because again, like you said, 1% are responsible for 90% of the workload getting created. I think back, um, and I'll paraphrase here for a number of reasons, not the least of which would be profanity, but the, uh, late great George Carlin, one of the things that he used to say was, you know, these sort of euphemisms that we have in language and culture are really misunderstood. And one of the ones that he highlights is quote, unquote, it's the quiet ones you have to watch and you know, at the same time, while you're watching the quiet ones, some loud person, and again, I'm paraphrasing without the profanity here, but it's some loud person that's running around with a blanking hammer hitting people over the head. So, you know, again, I think shocking but not surprising that it's a very, very small minority of humans out there that are creating a lot of these security incident workload and a lot of the data loss incidents that teams are struggling to get their hands and their heads around. Brian, any, any thoughts from you on, on maybe some of the things that you thought were interesting from the research?

Speaker C: Yeah, that 1% figure is pretty amazing. But what really struck me, Brian, was in the report, you know, we, we gathered data from our own platform about the, uh, the risk to cloud tenants. You know, that's just a part of the study. And you know, we found that, uh, between January and September of last year, 96% of tenants were subject to precision attacks. You know, and, you know, what do we call a precision attack? It's like a targeted phishing attempt, let's say. You know, like a lot of these attacks were successful to the tune of 54%, uh, of tenants were breached at least once. And they were, they were after data. You know, that that is a huge percentage and it can be attributed to the use of things like social engineering and sophisticated toolkits that allow attackers, uh, to bypass advanced technologies like mfa, you know, multi factor authentication.

Speaker B: So in addition to careless users, we also have compromised users that are posing a risk to data. And of course we also have malicious users who pose a risk to data. And uh, when we looked at our Survey, definitely, you know, one of the leading causes of data loss was departing employees. And that's another, I think, important takeaway from the report.

Speaker A: Yeah, and I've talked to a number of customers and partners out there and it's really one of the things that a lot of organizations I think are really starting to take a hard look at is how do we onboard and off board not just employees, not just full time folks, but, but contractors and suppliers and third parties when these business relationships come to a close or contract ends, things like that, how are we looking at ensuring that we're offboarding not just identities but all of the attributes and the data that goes along with it? It's really building a process around that and having a platform or a number of platforms that can support it too. So it stands to reason that without that in place, you're going to see a lot of the types of incidents that Brian just mentioned. I know another one, one of the things, I think a tear that you mentioned at the beginning was around the report talking about 85% of organizations experienced one or more data loss incidents in the last year. And we see these incidents happen all the time. We try to look at them as maybe lessons learned. What can we do to improve our own security? But can you both talk about what are some of the impacts that the incidents actually had on business and did that actually take place? Did people, you know, learned from that? Were there, were there lessons to be taken from it and improve their security postures?

Speaker C: Yeah, something we learned in the report is, you know, of that 85%, more than nine in 10 of those affected, uh, faced negative outcomes such as uh, business disruption or revenue loss, uh, that was reported by uh, 50% of the uh, affected organizations or about 40% said that they uh, suffered reputation computational damage as a result of this data loss. All this is coming from uh, 1% of the users who are responsible for those 88% of the alerts there.

Speaker B: Of course other outcomes could be weakening of the organization's competitive positioning. If it's a regulatory violation, it can also result in fines. As you know, for example, under the laws such as GDPR, you can get fined as much as up to 4% of an organization's annual revenue. That's, that's GDPR. I know in the United States, HIPAA, for example, has a ceiling for fines. But I do believe it's like 1.4 million. And that could be detrimental to a hospital or to a, a small clinic and things like that. Right. So, and then if, if you find that the data was leaking multiple years, then, you know, the fine that you are facing can be doubled, quadrupled. Right. Uh, depending on the number of years the data was leaking. So from that perspective, fines are certainly a deterrent here for organizations and hence the reason why many of them have established data loss prevention programs in the first place.

Speaker A: Yeah. And I know one of the things that atir you and Brian both talked about is the different types of, of humans that get, you know, that we sort of categorize or bucketize. You know, we've got truly malicious users, we've got folks that have their, their credentials compromised and then we've got the careless users. But I'd love to kind of unpack the careless users in data loss incidents for, for a moment. From a prevention and control perspective, how should we be tailoring our defenses and our, our strategy to them? Should we have different sorts of profiles or policies or procedures in place for. Let's, let's handle a, uh, careless user a certain way. Let's handle a compromised or a suspected compromise of an account a certain way. Let's handle a truly malicious user a different way. What's some good guidance for organizations to take that and look at handling things on a category by category basis?

Speaker C: Well, let's take a look at what is carelessness. You know, it's, it's things like misdirected emails, visiting a phishing site, installing unauthorized software, and emailing sensitive data to a personal account. These are really all preventable behaviors that could be mitigated by implementing DLP policy rules for uh, email or web uploads, cloud files syncing and other common data exfiltration methods.

Speaker B: So of course we all understand, you know, data loss is policy based. So in some ways when you write a policy, the policy is not quite aware of whether or not a person is careless or a malicious.

Speaker C: Mhm.

Speaker B: So to distinguish a careless user from a malicious one, we at Proofpoint offer deep visibility to user behavior. So for example, if a user is displaying high risk behaviors such as downloading large quantities of data in a short period of time or in installing unapproved data backup tools, then the user risk might be higher. Right. So it's one of the reasons why we brought a DLP product to market that actually does more than DLP actually offers quite a bit of visibility to user behavior. And that could be additional things like installing hacking tools. It could be even websites and that person has visited if, for example, departing employee. Take a departing employee as an example. Right. You know, if you have the ability to see that uh, just before this person, let's say within a month of that, the period of a person downloading 500 to 1,000 files from their laptop, if that person has spent time at a competitor's website, especially their job site, and potentially maybe even uploaded their resume to that job site, there's a good indication that this person might be departing the company. Even if they haven't resigned yet. Right. There's a good chance that this person is departing the company and hence is taking some potentially sensitive information with them. Hence how you at that point handle the situation differs. Right. If it's a careless user, you may give them a warning or you may want to provide them an update on company policy. If it's a departing employee who, which, who looks like uh, taking uh, sensitive information with them as they're leaving the company, then you may have to involve compliance or HR and legal. So the response can change significantly. Now in the future we expect to see DLP to become more risk based and the rules to become more dynamic. In fact, our product team is working on such capabilities right now to the point that we can actually start recording more forensics evidence after let's say a particular alert is triggered. Right. So those are the types of capabilities that we are working on developing. So everything becomes a little bit more risk based and is more dynamic.

Speaker A: Yeah, absolutely. Brian, you had mentioned things like, you know, cloud certainly being an issue, hybrid work and back to our top right square of generative AI. I know those are some pretty big topic areas but there's also some, some pretty interesting implications there for data loss prevention and these data loss incidents that we looked at in the landscape report? What are some of the things that you're seeing from security leaders out there around some of these bigger macro trends like moving workloads to cloud and hybrid work and gen AI?

Speaker C: Well, cloud workflows have really changed how organizations store, access and synchronize data. You know, needless to say, hybrid work has shifted the way people consume data. You know, gen AI tools are absorbing common tasks and gaining access to confidential data in the process. You know, these are micro challenges, you know, that are really compounding the growing human problem Tyr was talking about. And you know, organizations really need to rethink their DLP strategies to address the underlying cause of data loss, which is ah, people doing things that they shouldn't be doing.

Speaker A: Yeah, I like to sum it up as good people making bad decisions with good apps and good data in the case of carelessness, at least here I'm going to actually Give you a plug here for a minute and a bit of a platform. You really have done a lot of work here internally and externally, particularly the latter part of last year, talking about generative AI and DLP together and what that looks like and some things to look for. I'll even give you a little bit of a lead in and a plug to some of the blog posts that you've written publicly last year, but would love to kind of give you the floor to take care of that. Top right buzzword. Bingo. Square of Genai and DLP.

Speaker B: Yeah. So of course earlier in the year when ChatGPT became a topic of discussion, uh, especially within the context of data security and risk it may pose to corporate data. Right. There were quite a number of news, news articles out there how people used Gen uh, AI and how it may have panned out well for them and may not have panned out well for them. I do believe one of the stories was a lawyer actually using a generative AI site to research. I believe he was looking for examples that he could use to build a case and he actually ended up with completely false information and he didn't fact check and used it and lost the case. So that was uh, uh, really a big no, no and basically a warning to people who are looking to use generative AI in the workplace. Now I can easily see a scenario where a completely well meaning person can say, oh, you know, I have these meeting notes that I got through a transcript from a teams meeting and I need to generate a meeting summary. Let me pop that into ChatGPT and ask for a summary. Well, if the meeting is about a new project that the company is working on, for example, there is uh, easily going to be some non public information in that particular transcript and hence you might be entering sensitive and non public company information into a public Gen AI tool just to get a summary of that information. And there are other circumstances of this. Like for example I was on an application trying to figure out how people were using Gen AI and one of the use cases is, of course software developers are using Gen AI to edit their code or maybe even ask for sample code. Right. And one of the risks of using ChatGPT for software development is the potential for the platform to generate code that is vulnerable to security threats, weaknesses and exploits, but also potentially, you know, people putting in copyrighted code in there, right, or trade secrets in there and that becoming part of your code and that uh, that can open the road to litigation in the future if somebody was to realize that another company's Code ended up in your code. So those types of things are really important. You know, generative opens is the door to those types of issues.

Speaker A: Yeah. And just to clarify and maybe set this up a little bit better, the data loss landscape report did mention that generative AI is the fastest growing area of concern for those that we polled, correct?

Speaker B: Yes. We actually looked at the top rules that were being configured in our, uh, threat library rule, in our DLP and insider threat library rule. And it was among the top five rules configured on the endpoint. So as you can see, it certainly was, uh, a very popular rule considering that it had recently been introduced and the rule itself was browsing to generative AI sites. So there's definitely interest in finding out who is going and using that tool and to what purpose they're using the tool.

Speaker A: Yeah. And I know you, you went through a couple of really great examples of generative AI and sort of how it can go bad quickly. We'll have some links in the show notes to both the, uh, part one and part two blogs that ATIR mentioned last year that we had published on proofpoint.com but want to shift gears here. One of the other big areas of concern I know is around departing employees. Like we mentioned, not just full time employees per se, but maybe suppliers and contractors and third parties and people that we might terminate business relationships with. So how do these departing humans pose a risk to data security?

Speaker C: Well, in our survey they were actually, uh, the third riskiest user category. And essentially, uh, departing employees do not always think they are acting maliciously. Some just feel entitled to leave with the information that they've produced during the course of their jobs. But our data shows that 87% of anomalous file exfiltration among cloud tenants was caused by, uh, employees who were departing. And it, it really underscores, Brian, the need for preventative strategies such as implementing a security review process for leaving their jobs.

Speaker A: Yeah, absolutely. I mean, you think about it, we're in such a time of, it's not just the things that hit the news, Right, the layoffs, the mergers and acquisitions, the change of control of business. But I think it's just the speed and velocity that humans are sharing information. We need to have some tighter controls and some tighter programs around what we're doing. Yo, go ahead, atir.

Speaker B: Over the past year, more than one organization that we worked with was concerned, for example, with their employees in Russia, because either they were doing divestitures there or they were concerned folks may be leaving that subsidiary with the concern that they may be closing that subsidiary. Right. Especially if they were European companies or they were, you know, American companies. So you can see where a large divestiture can lead to the loss of a lot of uh, good information. I do believe one of the companies was a legal firm. So you can imagine legal contracts, kind of legal documents leaking and putting the company into, into a difficult position with their clients. Another one had my, I do believe was a food, uh, and beverage company and that did a lot of research. So I'm assuming they were concerned with any kind of new products that they were working on, any kind of new, new research that, that they were doing and were concerned with losing that type of intellectual property.

Speaker A: Yeah, and if we look at maybe, you know, I meant, I mentioned some of the programs, some of the things that we can do. How do organizations vary in how they take that approach to dlp? Um, Brian, you mentioned, you know, being a bit more proactive and preventative, but how does that look across different industries? You know, Tyr, you just mentioned, you know, different countries using whole lot of business from Russia and the CIS states as an example.

Speaker C: Perhaps.

Speaker A: But does that look different based upon, you know, company profile and where they're doing business and what industry they're doing business in completely?

Speaker B: It certainly does. For example, if you are a highly regulated industry such as healthcare and financial institutions, DLP applies to everybody within the organization. You may have very strict rules about data exfiltration and you will have rules that specify prevention. So it would be, you know, preventing X type of data. So in this case it would be most likely pii, phi and PCI data, uh, from leaving the company. And that could be via copy, uh, to usb, a uh, web upload to a personal cloud account. It could be also rules like you know, preventing pii, PHI or PCI in certain applications, especially in the case of pci. You know, PCI can be only in specific applications and not others. So you may want to prevent the uploads of those applications of the, of that type of data, customer data, to say a specific Microsoft Office 365 folders and maybe allow it only in one place or only in one application. So that is pretty common. Whereas in education, I just talked to a, uh, university, you know, they were more concerned with education, right? Educating their users, making sure that they knew what corporate policy was so they would have maybe user justification in place rather than prevention. While, you know, they will have a pop up that says, hey, why are you taking this data? They won't necessarily prevent it, but they will have a statement about policy, corporate Policy or the uh, institutional policy in place to educate the user. So it's, it really varies pretty significantly. And then uh, another example I can think of is in research organizations, in organizations that have a lot of intellectual property, right. You may not want to prevent the user and impact their experience, user experience and, and bring down their productivity because they have to handle a lot of intellectual information, intellectual property, type of information. But at the same time you want uh, very close monitoring for those people who are handling. So those um, types of organizations may have insider threat programs in place that collect much deeper forensics evidence, including visual evidence to make sure that they can tell apart a ah, careless employee from a malicious employee.

Speaker C: And Brian, just to sort of punctuate what ITER was saying here is you know the report really revealed that the good news is that organizations data loss prevention programs are maturing somewhat. While you know, many programs as ATIR mentioned, you know, have been implemented as a response to legal regulations, you know, more than 50% of those surveyed cited protection of customer and employee privacy is the actual primary driver. It's very interesting.

Speaker A: Yeah, absolutely. Really want to bring this home and I think this last question and point of discussion is one that's going to be really interesting. So in the landscape report we look at some of the key steps that organizations have taken to improve their DLP capabilities. What are end user organizations doing here? What are they looking to as far as solutions?

Speaker B: For one thing, what I have seen people configure in terms of rules, the top rules that are firing are uh, of course the top rules that are also being configured which are copy to USB monitoring people when they're copying things to a USB monitoring people when they're uploading to the web. Because this is where you can actually move a lot of data, right? You can move more data today through email too. But there are still size limitations, amount limitations in place with email. So from that perspective it's really important to keep eye on channels and methods of data exfiltration that can result in very large quantities of data loss. But another place where I think we can have significant amount of data exposure is in cloud folders. We have uh, found when we did proof of concepts for organizations, sometimes we would find significant amount of sensitive information, including citizen data, including student data, customer data exposed in cloud accounts. Because people are careless when they create documents and they end up not sharing it with the whole company for example or the whole organization. What happens is when you have a single compromised account in the organization, you can expose all these files to that threat actor. Who has access to that compromised account. And it's really simple in SharePoint to search for W2 files, search for passwords, and you'll be surprised what you will find that is shared with the whole domain of the, of the organization. And hence, uh, there's a pretty significant data exposure risk when employees share files broadly across the whole company and sometimes with even anonymous links, which means they can be accessed, um, through these publicly available links as well.

Speaker A: Brian, any thoughts here?

Speaker C: Well, Tier really covered it there, but security teams should have processes in place to ensure the absolute minimum. You know, they have to really monitor people with access to sensitive data or have admin privileges and establishing a security review process for departing employees and you know, things like this in addition to regularly reviewing your DLP program and keeping in mind that adoption of things like Generative AI and other developments are really going to change, uh, user behavior in many, many different ways. So it has to be looked at continually.

Speaker A: Absolutely. Well, we'll go ahead and have links to the data Loss Landscape Report. It's uh, here. We'll uh, put some links in the show notes to both part one and part two of your blogs last year that were really good going into the uh, Generative AI part specifically, but just wanted to take a minute. Aer and Brian, thank you both for joining us on another episode of the Protecting People podcast. This was really informative and great job putting this report together.

Speaker B: Thank you, Brian and Brian, like I

Speaker A: said, we're over quota for our Brian's and maybe we could put those in the uh, the bingo card as well. We'll wrap this up. Uh, for the Protecting People podcast, I'm Brian Reed and we'll talk to you next time. Thank you.

Speaker B: Thanks for listening.

Speaker C: Thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Aaron McCray: Ferrari Security: Speed With GuardrailsKitecast · on Multi-factor authentication (MFA)88 / 100
  • AI Is Having Its Dropbox MomentAI Proving Ground Podcast · on Data loss prevention (DLP)85 / 100
  • AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy MerzaSecure & Simple · on insider threat detection85 / 100
  • AI Security: Gerald Auger on Shadow AI, Non Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Data loss prevention (DLP)84 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100
  • How to Talk About Cybersecurity to Clients & Prospects with Mark Lamb from HighGround.iothe RocketMSP Podcast · on Multi-factor authentication (MFA)82 / 100

More from Protecting People

All episodes →
  • Risky and They Know It: Unveiling Human Behavior in the State of the Phish Report 2024
  • Five-Minute Forecast for the Week of 01/29/2024
  • Five-Minute Forecast for the Week of 01/22/2024
  • Microsoft's Secure Future Initiative: A New Hope or Old Hype?
  • Five-Minute Forecast for the Week of 01/15/2024
Explore the best B2B Engineering & DevTools podcasts →
All Protecting People episodes →