Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Persistent Data Security that Enhances DLP Processes and Technology

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

Data loss prevention (DLP) processes and technology prevent unauthorized data exfiltration and are a critical component of data breach detection strategies. Traditional DLP decision points include allowing and blocking transmissions or redirecting transmission to another party for additional decision making. But as more organizations adopt end-to-end encryption solutions, their DLP processes and technology become less effective. This results in more blocks and redirects, which in turn hinder business velocity.

Organizations need flexible data security solutions that work with existing DLP to satisfy audit and compliance requirements. This includes the capability to inspect encrypted content and provide encrypted remediation as an additional decision point. PKWARE’s PK Protect suite integrates with DLP for both sensitive information discovery and encrypted remediation. Download this solution overview to learn more.

Persistent Protection Travels With the File

Most security controls protect a location. Persistent protection is applied to the file itself, so it survives the transmission, the recipient’s mailbox, the download to a laptop and the copy somebody takes to a partner.

That property is what makes it complementary to DLP rather than competitive with it. DLP governs what may leave; persistent protection governs what the data is worth once it has.

Automatic Encryption at the Point of Sending

Outlook integration encrypts email attachments automatically, using the recipient key and the policy key, which removes the step that depends on a person remembering to apply protection under time pressure.

The policy key is the part that matters for DLP. It gives authorized security personnel a route to inspect content the organization has encrypted, so protection and inspection are no longer in opposition.

How the Two Systems Work Together

A message leaves the sender already encrypted, passes through the exchange server, and reaches DLP with the policy key available for inspection. DLP scans the content, applies its rule, and either passes the message on with the encryption intact or stops it.

Content remains end-to-end encrypted throughout. Nothing is decrypted into an intermediate state that a third system has to be trusted to protect.

Sensitive Information Discovery, Not Only Transmission Control

The same integration serves discovery. DLP is naturally focused on data in motion, which leaves the stored copies that generated the transmission unexamined.

Scanning repositories, endpoints and servers for sensitive information, and remediating what is found according to policy, addresses the source rather than the symptom. A file that should not exist unprotected is a recurring DLP event until something protects it at rest.

Why This Satisfies Audit and Compliance

Auditors ask two questions about data leaving an organization: what controls exist, and what evidence shows they operated. A control that blocks what it cannot read answers the first question and fails the second.

Inspecting encrypted content, applying policy to what is actually inside it, and recording both, produces the evidence. It is also what allows an organization to adopt end-to-end encryption broadly without degrading the detection capability it already paid for.

Protection That Outlives the Perimeter

The assumption behind perimeter and network controls is that data inside is safe and data leaving is the risk. Remote work, cloud storage and partner integrations have made that division largely notional.

Persistent protection accepts the new shape instead of defending the old one. A file that carries its own protection is equally safe inside the network, on a contractor’s laptop and in a cloud folder somebody shared more widely than intended.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.