Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Data Breach Nightmares

Q&A: Data leak prevention pros and cons

Industry analyst says business processes, not products, stop data from leaking
By Cara Garretson , Network World , 01/07/2008

Anti-data leakage vendors make bold claims about how far their products can go to protect enterprises from unauthorized information sharing. This irks Nick Selby, head of enterprise security research at The 451 Group, who believes these tools are helpful with some tasks, but far from “the solution.”

Selby declines to use the industry term “data-loss prevention” to describe these products because he believes such words instill a false sense of security. Network World Senior Editor Cara Garretson recently spoke to Selby to find out more about where these tools deliver, and where they fall short.

What are anti-data leakage products good for?

These products are very effective at giving enterprises a great amount of visibility into what’s going out of the building. While that seems like a simple thing, it’s in fact a sea change – the idea that you can now quantify and see who is sending what where is a tremendous advance.

They can do a great deal with stopping stupidity [users sending out sensitive data without realizing it]. Most customers are using these tools in monitor-only mode to reduce the noise and help internal security do its job by removing stupidity, and that’s an extraordinary benefit to businesses.

What’s not so good about these products?

Enterprises don’t know where their unstructured data is, let alone where their sensitive data is. Putting a box at the gateway doesn’t solve the problem, but highlights it. What do you do once you’ve identified what’s going out the door, run around the building hitting people over the head with newspapers?

What’s more, now you’re subjected to litigation problems. Imagine the person who has to answer the plaintiff lawyer’s question `You knew three years ago that this stuff was going out the building and you didn’t do anything about it?’

Some anti-data leakage products say they help customers discover and identify their sensitive data, is that valuable?

The time it takes to classify that data that already exists is such that by the time you’re finished, a new mountain exists. Every day information workers create more unstructured data measured in gigabytes if not terabytes … to keep up with the flow while classifying what’s already been done is a very difficult challenge.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.