Categories
How to buy the DLP system?
Enterprise security, including information one, is a special topic of study. For many managers it is a painful issue, as the final choice of strategy, tools of execution and drawing up the whole IS policy programme in the company takes a lot of resources, both labour and financial. However, this task shouldn't be underestimated. It is not uncommon, when an enterprise incurred huge losses due to the fact that it failed to provide an elementary Information Security structure. Today, in an article by Anexet analysts, we examine one of the most popular solutions for business: the DLP system and look at how to buy it.
What is a DLP system
A DLP system is a special software tool that is part of a set of measures to ensure the company's IS, provides security for internal information traffic and occupies one of the leading positions in the overall business security circuit.
This topic is quite relevant for all organisations, regardless of their size and specifics of work. Everywhere there is a share of confidential data that requires protection from external influence, everywhere there are security threats to this data coming from both outside and inside the company, everywhere there is a percentage of negligence in handling information, which can lead to tangible material and reputational losses. Modern DLP systems solve many specific, relevant business problems, so we find this topic useful.

No matter how colourful the descriptions in the presentation of the end-user product may be, in this case the company is interested in the practical part: what problems and critical points the DLP system will be able to solve.
Data protection
Of course, this is one of the main functions of the system. All its work is aimed at preventing leaks of confidential information outside the company's information security loop for any of the reasons.
Fighting insiders
The system tracks trigger actions in information flow and informs the security specialist about them. This can be deliberate copying of confidential files, moving documents with confidentiality tags, sending photo documents to social networks or other. DLP systems investigate the most traumatic situations and provide in advance a response scheme when they occur: informing responsible employees or blocking the action.
Creating an archive of business communications
DLP systems provide an up-to-date, accurate, easy-to-use archive of business communications that stores all information and the ability to use it for analytics.
Automating and digitalising the work of information security department employees
DLP systems offer many options for reporting and monitoring events within the security loop. This greatly improves the efficiency of the IS department and its employees, minimises human error and increases the objectivity of the assessment.
Maintaining the reputation and standards of a reliable partnership
The implementation of a DLP system increases the overall level of data security at the enterprise, which is regarded by partners as a positive sign and an indicator of reliability. In this case, the risks of negative impact on the partner's own data, the probability of leakage and pressure from third parties are also reduced.
Monitoring of employee performance and loyalty
The study of the security of confidential enterprise data in the functionality of a DLP system is closely related to the study of the efficiency of employee time utilisation. After all, the entire information flow is personalised, it is always possible to determine who, what, where, where, and when sent. Therefore, developers use this information to monitor employees. DLP systems can upload data about work efficiency, working hours, network activity, remember and analyse all information from personal accounts used by employees during work and much more. You can also use contextual search to determine the loyalty or disloyalty of employees to management and the company as a whole.
This is only part of the tasks that a DLP system solves. The software is so in demand simply because it provides high-quality analysis and reporting with complete freedom of data circulation.
Why is it a problem to buy a DLP system?
Why is the task of buying a DLP system out of reach for many people? Let's take a closer look at the problem.
Firstly, not all companies see insecurity of data as a problem.
Strange as it may seem, even in the 21st century, at a time of digitalisation of business and maximum linkage of all processes to Internet support, not everyone really assesses the need for IS and implementation of modern solutions in business. The same applies to companies that are confident in the uniqueness of their services and, having no direct competitors, believe that indirect competitors or Internet fraudsters will not pay close attention to their business.
Secondly, company specialists are not always ready to objectively evaluate software offerings on the market.
According to some responsible managers, this process requires certain costs (time, financial), personnel decisions even at the selection stage. However, this is not entirely true. Vendor companies present their product in sufficient detail, make presentations, answer questions and deal with objections. The burden of software training falls on the vendor's shoulders. And most importantly: many developers offer a test period, during which companies can evaluate in practice the usefulness of the product and the offer.
Third, companies may have objections to the legal support for the process.
The first unconscious objection from customers is how legal is this? And won't there be long-term legal consequences for the company? In fact, the consequences of introducing a DLP system are positive on the contrary. The employer has the right to assess an employee's productivity, monitor the fulfilment of work duties and adherence to schedules.
At the same time, DLP-systems ensure compliance with the regulations of regulators in the area of personal data security when processing and storing personal data in Information Systems.
Fourth, companies may only consider defence against external information security threats, believing that this is sufficient.
It is also a common problem in the process of solving the global task of ensuring information security in enterprises. As a rule, the more publicised and popular solutions are software products for protection against external impact (malware introduction), while internal threats of data leakage, insider risks are also possible in the general security loop.
Criteria for selecting a DLP system
The criteria for selecting a DLP system can be broadly categorised into three groups:
-
by reputation;
-
in terms of functionality;
-
on after-sales service.

By reputation
The first step in learning about a software vendor is to investigate its reputation. It is necessary to check whether the vendor has licences to provide services and certificates of compliance with the quality standards adopted for this area in the country.
The second step is to look at the software vendor's history: how long the development has been going on, what goals and corporate values the company supports, what team of employees is involved in the project. This will help you understand what experience the vendor has under his belt and whether he realises it within the product.
The third step is to review the company's social activity. Social networks today are the face of the company, its voice. You can find out about the company's plans, possible software updates and releases, how much the product is represented in the international market and in the developer community.
The fourth step is reviews on the Internet, review of functionality from third-party users and experts, and research into software ratings. Of course, it is now widespread practice to buy reviews, both positive for your product and negative for your competitor. However, there are also quite informative ones, which emphasise the shortcomings or advantages of the product in a matter-of-fact way.
Functionality
Functionality is the key of every programme, especially if it is used in a sensitive topic like information security. What is important to investigate when selecting a DLP system?
What channels for intercepting information are suggested in the version?
Obviously, the more sources there are, the more useful the implementation will be. The optimal solution will be one that combines web traffic sources, social networks, messengers, email services and more (both web and desktop versions). DLP systems can also take into account the use of external storage media, local and network printers, and cloud storage. In addition to sources, the formats that the system can analyse are also important. For example, it will be ineffective to analyse only web traffic on HTTP/HTTPS protocols, ignoring SSL traffic transmitted over encrypted protocols. Or refusing to analyse document copying to storage media when assessing overall network file sharing.
What type of analysis is used in a DLP system?
DLP systems should provide the highest level of analysis of captured information, regardless of transmission format, external and internal circumstances, events, device connectivity, and other factors. Therefore, developers strive to use different approaches to analysis. The most commonly used are content analysis (by words, phrases in the transmitted data) and event analysis (by the fact of occurrence of a certain action, which is prohibited or monitored). Popular types of information analysis in DLP systems are also statistical (by numerical indicators) and attribute analysis (by determining the attributes of the file, documents, and information that is transmitted). This is a fairly broad topic that is explored by each vendor separately, and the more extensive it is presented in the system, the better.
From the buyer's point of view, it is necessary to evaluate the real needs that exist in a company and their realisation by a particular vendor. Suppose a classic type of DLP system is good enough to handle content analysis, while taking into account multiple sources. However, only "correct" forms of text writing are used in searches, and linguistic analysis technologies do not take into account the peculiarity of a human being to make mistakes, to rush, to abbreviate, especially in informal communication. Some developers understand this peculiarity and offer analyses with correction for grammatical errors and word forms in the text.
It is also important to be able to recognise complex documents where text and image transmission (print, photo) analysis is combined. For example, ask the vendor if their system can recognise the transmission of a photo of an activity licence. For example, a web design company will be willing to purchase a DLP system only if the system detects the transmission of vector graphics across communication channels.
Does the DLP system have a means of quickly responding to the fact that information has been transferred?
For DLP systems, it is not enough just to detect the fact of information security breach, it is also necessary to offer an effective tool to suppress this action, blocking transmission. For example, the Anexet system provides the ability to block data transmission under various conditions:
-
content blocking (by text, word forms, etc.);
-
date, time blocking (data transmission on the specified date/number of dates, specified time);
-
blocking by document status (assigned in the system itself);
-
blocking by IP address (selectively for specified IPs);
-
locking by file parameter (based on selected file attributes);
-
blocking by site category (a predetermined range of sites) and other types of blocking.
How do blockades work? Quite simply, all intercepted data is checked against predefined blocking rules, and if it matches, the information is blocked from being transmitted further. You can also set up notifications to responsible users in advance in case security policies are triggered.
Price and cost of ownership of the system
Obviously, this is one of the important arguments. Modern DLP systems implement the current solution of system modularity. That is, the software is sold in packages of functionality, which allows, firstly, to buy exactly what is needed to solve the tasks of ensuring the company's information security, and secondly, to reduce the cost of DLP implementation. The price of the software itself should be inquired about from the developer.
Expansion of functionality
Because DLP systems actually have a lot of analytical data, vendors can offer additional features and advanced analytics capabilities. One common solution is to monitor personnel and their performance based on network activity data. Buyers of a DLP system may even find that the monitoring tools (timesheets, reports on time spent on tasks and inefficient time, and more) that DLP offers are sufficient, and additional software is not required. When selecting a DLP system, investigate the full functionality; it is possible that a single purchase will solve several strategic problems.
Pre- and after-sales service
In addition to the purchase price, there is the cost of software licence renewal and support.
DLP systems may require additional attention from the purchaser, and this cost item should be taken into account to ensure that usage and operational issues are resolved in a timely manner.
What areas of enterprise are required to install DLP systems?
So far, neither international nor domestic regulators have made it compulsory to install DLP systems. This is a completely independent decision, and it is completely on the shoulders of the enterprise, with no additional subsidies or tax incentives provided. However, the use of DLP can be safely recommended for areas where a large amount of sensitive and confidential information is used. Such areas include:
-
banking and insurance institutions, trading exchanges and so on (have a large amount of sensitive data that is constantly changing and affecting the efficiency of the organisation);
-
public sector organisations (involved in leading processes of society and the state, possessing a large amount of confidential personal information about citizens);
-
critical industrial enterprises, enterprises with a high level of production secrecy, enterprises that use hazardous and harmful substances in production, whose processes have a direct impact on society and its functioning;
-
Information society enterprises (telecommunications, media, social networks and platforms);
-
software developers;
-
transport, logistics and related infrastructure;
-
companies with a high level of competition in the market;
-
companies dealing with highly intellectual technologies, know-how, patents and so on.
As you can see, the list is quite long. However, this does not mean that other companies and organisations should not consider installing DLP systems. In today's digital world, almost any business has a need to protect information within the company, regardless of its size and operational purpose.
Practical problems that a DLP system solves
DLP-systems realise practical assistance to companies and solve specific tasks in the information security loop. Let's consider the solved tasks using Anexet as an example.
-
Identifying ineffective employees;
-
Detecting financial fraud;
-
Detecting fraud in a public school;
-
Identifying and preventing leakage of information about the company's promotions;
-
Preventing the leaking of company customer data;
-
Equipment repair fraud;
-
Drain incoming leads to a competitor;
-
Identifying freelance employees;
-
Detecting workplace misconduct in a remote workplace and other examples.
You can read more on the website.
Harmful tips when choosing a DLP
In addition to helpful tips, here are some harmful tips in choosing a DLP system that are best not to follow.
-
Choose a solution from a DLP system vendor that offers a software purchase without a free test period, allows your employees to try the product only after payment, and insists on an extremely complex implementation and configuration process.
-
A proper DLP system necessarily requires the purchase of additional equipment and capacity, requires a large period of time for installation and debugging, and is maintained by a large IS staff.
-
A modern DLP system requires employees to come to the office and work only on their own computer where the monitoring software is installed. No remote access, it is unsafe and precludes the use of DLP.
-
A competent developer will take care of his product. It is too valuable to remain in the user's hands after the licence expires. Not a second more, everything must be deleted at once.

















