Proofpoint, Inc. announced the general availability of Data Loss Prevention (DLP) Transform, including GenAI use cases. Businesses struggle with the limitations of legacy DLP solutions that are fragmented across channels and are not designed to address today's most problematic use cases like insider risk, protecting cloud data and controlling the acceptable use of GenAI tools, including copilots and chatbots. In a recent Proofpoint study, 70% of security professionals cited visibility into sensitive data, user behavior and external threats as the most important capability for their DLP program.

Unlike legacy solutions limited to data classification or point solutions limited to one channel, Proofpoint Information Protection works across all major channels: email, cloud, endpoint, and web. The solution leverages all three critical analytical capabilities, including user behavior, AI-augmented data classification, and threat context. This has enabled over 6,000 organizations, including more than half of the Fortune 100, to mitigate all three major types of data loss risk: negligent user error, exfiltration by threat actors, and theft by malicious insiders.

DLP Transform brings together?in a single, economically attractive package?a cloud-native architecture that analyzes user behavior and content understanding to quickly assess and protect against data risk across channels. Critically, this enables organizations to consolidate their DLP point solutions, their insider risk tools, and their cloud DLP or CASB into a single architecture, agent and interface, adding capabilities and channel coverage as their data loss and insider risk programs mature. The uncertainty that has accompanied the explosion of GenAI tools has given the consolidation of DLP tools a new urgency.

The loss of data to a single party is bad enough but given the propensity of GenAI tools to train their models on user-submitted data and their tendency to disclose sensitive information via prompt engineering, sensitive data leakage to a GenAI tool may be the equivalent of making it public. Many organizations have crafted acceptable GenAI use policies to prevent privacy and corporate violations, ensuring confidential and customer information is not uploaded to GenAI tools and chatbots. However, such policies are near impossible to implement without an understanding of the content and employee behavior.

Proofpoint DLP Transform allows organizations to enforce those policies across all channels by allowing and disallowing interactions with GenAI tools based on user behavior, content, and data lineage. Unlike blunt tools such as legacy DLP solutions or web filtering that completely blocks all use of GenAI applications, Proofpoint can surgically allow and disallow interactions based on employee behavior and the content being input. Incidents such as uploading source code files or pasting corporate intellectual property can be detected, blocked and alerted upon.

In addition, end users can be provided reminders or nudges of the corporate Acceptable Usage Policies to reinforce awareness and adherence to such policies. Proofpoint will augment DLP Transform with a browser-based extension for content typed into Generative AI tools such as OpenAI ChatGPT and Google Gemini, expected to be made available at the end of Second Quarter 2024.