Home > Security News > Websense, Reconnex top Forrester ranking of DLP vendors
Security News:
EMAIL THIS

Websense, Reconnex top Forrester ranking of DLP vendors

By Robert Westervelt, News Editor
12 Jun 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The data leakage prevention (DLP) market has come a long way from protecting data loss as a result of a stray email message. Vendors are now focused on automating data classification, protecting data at rest and device management.

DLP vendors need to sell their technologies to customers based on what their pain points are, because not everybody needs a complete DLP solution.
Thomas Raschke,
senior analyst, Forrester Research Inc.

Websense Inc. garnered the top spot in a new report from Cambridge Mass.-based Forrester Research Inc. that tracks the DLP market and ranks the vendors based on market strategy and features. In all, 11 vendors were evaluated between December 2007 and February 2008.

Forrester said Websense did a good job integrating its PortAuthority acquisition and had the best overall market strategy. The merger increased its features beyond Web threats to include safeguard customer data and intellectual property leaving the network perimeter. Forrester said that while Websense offers strong features to identify structured and unstructured data in hundreds of file formats, it needs to be more advanced so data can be classified and categorized properly. It also lacks an endpoint agent, and needs to be interoperable with other knowledge management systems.

"Websense clearly shines on the strategy side," said Thomas Raschke, a senior analyst at Forrester. "Their product is decent, but they're lacking an endpoint piece."

Data leak prevention tools are being coupled with encryption and endpoint security technologies to gain control and lock down data, Raschke said.

Raschke said implementation of DLP has been difficult for companies. Many enterprises are starting to take steps to protect intellectual property data at rest in various parts of the network, such as manufacturing documents or CAD drawings. Implementing the technology is fairly easy, but classifying data and defining policies around the data can be difficult because it involves multiple people, such as business managers and IT.

Data loss prevention:
Is DLP coming of age? Reconnex hopes to ease path: Firms have grappled with DLP, but after a hard experience, ING's Andre Gold tells why it may be ready for prime time. Meanwhile, Reconnex says its new product can ease the path.

Panel: Firms can't manage DLP with products alone: Data protection is about fixing broken business practices rather than bolting on DLP products, three security officers said during an RSA Conference 2008 panel discussion.

McAfee merges encryption, DLP with new suite: The antivirus vendor repackaged SafeBoot's endpoint encryption and encrypted USB tokens with its existing data loss prevention products.

"DLP vendors need to sell their technologies to customers based on what their pain points are, because not everybody needs a complete DLP solution," Raschke said.

Reconnex Inc. also scored high marks, and is on Websense's heels, Raschke said. Forrester was impressed with the vendor's automated data classification and analysis engine, he said. The engine stood out because it could do the job without prior knowledge of what needs to be protected, according to Forrester.

"Their automated discovery features and forensics features are really strong," Raschke said. "They're helping people to automatically put the different data pieces together, and understand the most important parts of the puzzle that need protection."

According to Raschke, Reconnex has an uphill battle to climb. It hasn't been good at differentiating itself and explaining why its features are so compelling, he said. Websense has the advantage since it's a bigger company with more money and talent to build out a richer feature set, he said.

Other vendors that scored well were Verdasys, RSA, a division of EMC, and Vericept for their balanced DLP coverage and strong analysis features, according to the report. Verdasys scored high marks for its use of software agents to protect data in use at the endpoint, and RSA, which acquired Tablus in 2007, was the first major vendor to step into the market. Forrester said it has the strongest discovery features in the market.

Symantec, which declined to participate in the study, also has a very strong offering, Raschke said. It was the second major vendor to jump into the DLP market by acquiring Vontu last year for $350 million. Symantec is also partnering with GuardianEdge for full-disk and removable storage encryption to go with Vontu's gateway products.

McAfee also recently entered the market. It acquired Onigma and SafeBoot and in January, it repackaged SafeBoot's endpoint encryption and encrypted USB tokens with its existing data loss prevention products. Forrester said it needs to continue to integrate SafeBoot and build out a data analysis engine.



Tags: Enterprise Data GovernanceDisk Encryption and File EncryptionClient securityData Loss PreventionVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Enterprise Data Governance
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private
Compliance in the cloud
How to write technology outsourcing contracts

Disk Encryption and File Encryption
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Should developers create libraries of common cryptographic algorithms?
What is an encryption collision?
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
Voltage, RSA spar over tokenization, data protection
Truth, lies and fiction about encryption
What are new and commonly used public-key cryptography algorithms?
What are the export limitations for AES data encryption?

Client security
DLP technology challenges security costs
Endpoint protection best practices manual: Combating issues, problems
Kaspersky update for SMBs in wake of free Microsoft Security Essentials
Microsoft makes free antivirus software widely available
Security best practices in hotels
Best Antimalware Products
Perimeter defense in the era of the perimeterless network
Microsoft Security Essentials (MSE) shows no vision, expert says
Smart tactics for antivirus and antispyware
Top tactics for endpoint security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cut-and-paste attack  (SearchSecurity.com)
data masking  (SearchSecurity.com)
data splitting  (SearchSecurity.com)
deperimeterization  (SearchSecurity.com)
Google hacking  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
snooping  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts