Sticker shock over data-loss prevention products could be short-lived

By Ellen Messmer, Network World |  Security, data breach, data loss prevention Add a new comment

Data-loss prevention products can potentially save organizations a bundle by preventing the escape of sensitive information. But the six-figure starting price for a typical enterprise deployment of host and gateway-based DLP is tough for many to swallow.

The good news is that prices are expected to fall heading into next year as more vendors enter the fray and more choices for how to roll out DLP emerge.

"If you're dealing with a couple thousand seats for DLP, expect $250,000 to half a million," says Forrester Research analyst Andrew Jacquith. "But we will see price erosion because of competition."

(Of course, vendors are fond of pointing out that even today's prices aren't too high when you consider the cost of responding to a data breach. A Ponemon Institute study has tagged this at more than $6 million on average, or $202 per customer record, plus the loss of good reputation and possible lawsuits.)

The market to prevent data leaks got going in the early 2000s and has gained momentum of late, though even successful vendors still tend to boast of customer numbers in the hundreds rather than thousands. The market is dominated by traditional antimalware vendors that bought out DLP start-ups, though independents such as Verdasys remain in the mix as well. Newcomers will include the likes of antimalware vendor Sophos, which is expected this fall to introduce a DLP offering of its own making.

Jacquith says when enterprises determine an immediate need for DLP, the usual course has been to first turn to a security vendor they already rely on for other things.

"If it's a big McAfee shop or a Symantec shop, they'll look there first," he says. In Forrester's analysis, the market leaders are Websense, McAfee, Symantec, CA, EMC security division RSA and Verdasys. (For more on DLP products, read our recent test on perimeter-based tools.)In addition to DLP becoming available from more vendors, it will wind up getting embedded in existing software and hardware, including switches, servers and even laptops. It may all lead to the "content-aware enterprise," a phrase coined by Gartner analyst Eric Ouellet, who says, "It's about sprinkling DLP everywhere."

Buying into DLP

For those investing in DLP today, the need is straightforward.

"We need to protect patient information or other business information," says Larry Whiteside, CISO at New York City-based Visiting Nurses, which has 13,000 employees, with 3,500 nurses providing home assistance and facilitating hospital transition care for some 30,000 patients in the greater New York area.

Visiting Nurses, which had already been making use of the Websense Security Gateway, recently added the vendor's DLP gateway functionality. Using the DLP discovery tool (technology deriving from Websense's acquisition of PortAuthority in 2007), Visiting Nurses has determined where sensitive data is located in its 30 file servers for the purpose of detecting and blocking breaches, including inadvertent ones.

Plans are to add DLP data-blocking capability into mobile computers used by nurses. Any alerts would be collected into the firm's Symantec security-event management system, Whiteside says.

"If a user attempts to send a file, we would want it stopped at the gateway, with an alert generated and sent to the [management system]," he says.

Support from business managers for DLP has been solid, especially as the IT department is also under constant pressure to grant more open access, Whiteside says. "From the data stewardship standpoint, it's on my staff to make sure people are doing what they're supposed to do," he notes, adding he does expect it to take up to half a year to deploy DLP widely as business processes are closely scrutinized.

And DLP does nothing if not give an organization a clear picture of how content gets distributed internally and to the outside. "The visibility you get is incredibly useful," Jacquith notes. "Some people even talk about using it for chargeback."

DLP shortcomings

While the accuracy of DLP products is regarded as good, the tools aren't impervious to being tricked. James Wingate, director of the Steganography Analysis & Research Center in Fairmont, West Virginia, says it's possible to hide a file inside another using steganography tools and "DLP tools will not detect it."

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question