{"id":126376,"date":"2023-03-15T09:00:00","date_gmt":"2023-03-15T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=126376"},"modified":"2023-09-18T08:48:56","modified_gmt":"2023-09-18T15:48:56","slug":"gain-flexibility-and-scale-with-a-cloud-native-dlp-solution","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/15\/gain-flexibility-and-scale-with-a-cloud-native-dlp-solution\/","title":{"rendered":"Gain flexibility and scale with a cloud-native DLP solution"},"content":{"rendered":"\n

We\u2019re living in a seismic era for data security. Chief information security officers (CISOs) have to contend with a digital landscape that seems to shift daily as more organizations move to remote and hybrid work, redrawing the boundaries for how data is used and shared. The cloud has enabled continuous collaboration, with employees creating and sharing documents easily through chat and email. This unbounded digital estate has also created new opportunities for data exfiltration, and that possibility has many organizations rethinking their approach to data loss prevention (DLP).<\/p>\n\n\n\n

Forward-thinking organizations are seeking to future-proof their DLP strategy with a comprehensive solution that scales across all applications, services, endpoints, and platforms. To help those that may be considering a DLP migration, Microsoft spoke to more than 300 data and compliance professionals to create the white paper “Data Loss Prevention: From on-premises to cloud<\/a>.” We\u2019ve presented some of the study\u2019s highlights here, including common DLP states in use, challenges in migrating to a new DLP solution, best practices, and the benefits of adopting a cloud-native DLP solution.<\/p>\n\n\n\n

\n\n

\u201cData is not confined in a certain area. In today\u2019s environment, it\u2019s everywhere: someone else\u2019s phone, tablet, data center, or software as a service application\u2014because of that, you definitely see a lot more breaches happening.\u201d<\/em><\/p>\n\n\n

\u2014Vice President, Information Security Officer, Financial Services<\/p>\n\n<\/blockquote>\n\n\n\n

The stages of DLP deployment<\/h2>\n\n\n\n

We can define DLP<\/a> as the people, processes, and technology that ensure data is not lost, misused, or accessed by unauthorized users. Our research revealed that 70 percent of companies see their DLP solution as a focal point of their overall data protection strategy. For that reason, a good DLP solution uses a holistic approach to protect the organization\u2019s data assets, aid regulatory compliance, and prevent data leakage by monitoring all endpoints, apps, services, and the cloud\u2014anywhere data is stored or shared. Most respondents said their ideal solution would be cloud-native DLP, which could provide scalability and flexibility, balancing protection and productivity.<\/p>\n\n\n\n

An organization\u2019s DLP can exist in five different stages with regard to deployment, starting from 100 percent on-premises (obsolete) and moving to 100 percent cloud-native (ideal). For this study, we focused on the three stages in the middle that involve some level of cloud deployment.<\/p>\n\n\n\n

    \n
  1. On-premises\u2014anchored: <\/strong>In this stage, an organization\u2019s DLP is roughly 40 percent cloud and 60 percent on-premises. These organizations often have concerns about cloud migration, whether because of misconceptions or real difficulties related to migrating a larger amount of on-premises data. They tend to be highly focused on maintaining their current infrastructure and managing device agents through on-premises DLP solutions. This stage is the costliest in terms of staff hours and infrastructure required. Organizations at this stage also report the lowest level of perceived success and confidence in their current DLP program.<\/li>\n\n\n\n
  2. Hybrid: <\/strong>Looking to push their program forward, these organizations currently have amostly equal split between on-premises and cloud DLP. They see their biggest challenges around custom integrations and tend to evaluate new DLP solutions annually, seeking improvements in scalability, flexibility, and accuracy. They expend a lot of effort stitching together and managing multiple DLP solutions to support their hybrid data environments.<\/li>\n\n\n\n
  3. Cloud-focused: <\/strong>These organizations are farthest along in their migration plans\u201460 percent cloud and 40 percent on-premises\u2014and have the highest level of confidence and perceived success in their DLP program. Their goal is to improve visibility into their data, and they tend to evaluate new DLP solutions at a slower rate (every two to three years). They also experience fewer challenges with their current DLP programs and have a clearer understanding of their data. Their main challenge lies in ensuring that employees are following DLP policies for handling sensitive data.<\/li>\n<\/ol>\n\n\n\n

    Overall, the study found that organizations in on-premises-anchored states are experiencing the most discomfort.<\/strong> Hybrid organizations report feeling like they\u2019re in a holding pattern, spending time and effort maintaining complex integrations and multiple DLP solutions across data environments. Fifty-nine percent of organizations with a hybrid DLP configuration report a desire to move to a cloud DLP solution<\/strong>.<\/p>\n\n\n\n

    The goal<\/em>\u2014cloud-native DLP: <\/strong>Beyond the cloud-focused stage, this is the desired destination. At this point, an organization\u2019s DLP solution is fully cloud-native and the firm can benefit from scalable, holistic data protection across applications, services, endpoints, and platforms\u2014all without hindering productivity or adding staff.<\/p>\n\n\n\n

    \n\n

    \u201cIt doesn\u2019t make sense to maintain two or three different solutions because then you have to keep them updated, you have to make sure that there\u2019s not a whole lot of difference between one, two, and three. So, you want to create the benefits and the economic savings of standardization. That\u2019s why consolidation is critical.\u201d <\/em><\/p>\n\n\n

    \u2014Director, Technology Services<\/p>\n\n<\/blockquote>\n\n\n\n

    Benefits of leveraging a cloud-native DLP solution<\/h2>\n\n\n\n

    In migrating your DLP solution, there are two options: a cloud-based or a cloud-native DLP solution. Both types will require the recreation of legacy policies, so how can you decide which solution better suits your organization?<\/p>\n\n\n\n