* DatAdvantage from Varonis Systems
Your company has a lot of information in unstructured file formats. Think of all the word processing documents and the PowerPoint presentations that hold the secrets to your business. There’s the CFO’s presentation to the financial analysts. And the business development manager’s report on the new market you plan to enter. And the employee evaluations just completed by the Human Resources group.
Some 80% or more of the information your company relies upon is in unstructured files. The question is, do you know, beyond a shadow of a doubt, who has access to those files? Do you know who has viewed, copied or edited them lately, and can you control exactly who does have such access? If your company has private or sensitive information in unstructured files, you might be at risk of letting inappropriate people get to that information.
Like many other security issues, compliance with government regulations is driving many companies to address the concern of unauthorized or inappropriate access to information. But even companies that don’t have to deal with HIPAA or Sarbanes-Oxley are aware of the need to protect intellectual property and other highly sensitive forms of information.
Steve Peltzman, the CIO at the Museum of Modern Art in New York, was worried about protecting the information stored on his organization’s network. MOMA is a nonprofit organization, so Sarbox compliance isn’t an issue. Nevertheless, MOMA is audited every year, and Peltzman wanted to assure the integrity of the museum’s files by controlling who can access them. He chose DatAdvantage from Varonis Systems.
According to Peltzman, the museum is most concerned about protecting access to data about patrons, retail sales, and operational processes. Although the museum has never had a known data breach, the CIO felt the investment in the Varonis software was a good proactive move to head off any problems before they can arise. His justification for installing DatAdvantage? “We can’t afford to compromise the data,” Peltzman says.
DatAdvantage works on all kinds of unstructured data files in the Microsoft environment. (A UNIX version is due out this fall.) As the MOMA CIO puts it, DatAdvantage fills the gaps of a feature set that Windows doesn’t have.
By default, when you create a data folder in a Windows file share, the “Everyone” group has access to that folder and its contents. This is OK if you’re going for maximum collaboration, but it’s not OK if you need to protect access to certain files. As a result, most users in an organization are way oversubscribed to file access. It’s not uncommon for people to have access to folders and files that they have absolutely no need to work with, and this is a red flag for auditors and security experts.
DatAdvantage allows you to cut off that unnecessary access, and it does so in an intelligent way. When we viewed a demo of the product, the phrase “business intelligence for data access” came to mind. What DatAdvantage provides is visibility into file access, sliced in different views. You can see which users have access to specific folders and files, and you can see which folders and files a specific user has access to. The business intelligence part comes to play when DatAdvantage performs a statistical analysis of users’ behavior patterns to suggest who legitimately needs access and to a file and who doesn’t. The administrator can simply “right click” to remove permissions for people who don’t need access to a file or folder.
For example, you can view a report on all the files belonging to the Finance department. The report will show you who has accessed each file, when, and for what purpose (e.g., to view, to edit, to copy, to rename, etc.). From this report, patterns of “misappropriation” emerge if they exist. Suppose you discover that an employee in the Marketing department occasionally peruses Finance department files. You can further explore this activity to determine if there is a legitimate business reason. If there isn’t, you can remove that employee from further access.
Using another view, you can see which files John Doe accesses. This view can show you if John strays into folders that he has no business using. And let’s say John once unintentionally accessed a folder owned by the Human Resources department. DatAdvantage’s statistical analysis will suggest to you that you should remove John’s permissions to this file to prevent him from going there again.
If you are old enough to have worked in a mainframe environment, you can liken the capabilities of DatAdvantage to ACF2. The whole idea is to lock-down access to files, and only let legitimate users have the access they truly need. With security and compliance of high concern for most companies today, Varonis tackles the problem of protecting unstructured data.
By the way, Network World identified Varonis as one of “10 enterprise software companies to watch” this past April.




