What is our primary use case?
Netskope Data Loss Prevention (DLP) is being used as a Secure Services Engine (SSE) solution for the CASB solution, Shadow IT detection, and Secure Web Gateway capabilities.
The primary focus is on detecting sensitive data. A classification system has been implemented in terms of data sensitivity, and the solution is utilized for capturing instances where users attempt to upload sensitive data to unsanctioned applications. Rules have been put in place to prevent such uploads.
What is most valuable?
The most valuable features are DLP, CASB, and Secure Web Gateway functionality.
Netskope Data Loss Prevention (DLP) provides predefined templates, indexed data matching, EDM, and OCR capabilities. The role functionality provides significant information, and considerable automation has been built on top of the platform using the available APIs.
There are extensive integrations with different tools, making the overall experience smooth.
What needs improvement?
Data in transit works quite well and operates in near real-time.
However, data at rest scanning operates under separate licensing, and it would be beneficial to examine applications where the location of sensitive data is unknown. Netskope Data Loss Prevention (DLP) could improve data-at-rest scanning capabilities.
Regarding DLP-specific improvements, data-at-rest scanning could be enhanced in terms of the applications supported, as coverage is currently limited to a restricted set of enterprise applications. Expanding application coverage would be beneficial. Additionally, data-at-rest scans should be made easier and faster to execute.
Most solutions lack Data Security Posture Management (DSPM) functionality, and this capability is not yet mature.
A significant limitation is that Netskope Data Loss Prevention (DLP) does not support out-of-the-box data classification. Third-party integrations must be relied upon instead, whereas having built-in data classification support would be advantageous.
For how long have I used the solution?
What do I think about the stability of the solution?
Netskope Data Loss Prevention (DLP) operates smoothly, with extensive integrations across different tools functioning well.
What do I think about the scalability of the solution?
No scalability issues have been observed, and the solution receives a rating of eight or higher in this regard.
How are customer service and support?
Technical support has been rated low. Numerous bugs have been discovered in terms of functionality, and the support team takes considerable time to resolve these issues.
Support receives a rating of five to six.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Symantec is no longer being used, as the organization moved away from it.
How was the initial setup?
From a setup perspective, the implementation is acceptable. Most products such as Zscaler or Prisma have similar initial setup processes.
However, data protection and DLP configuration always require significant time for fine-tuning. A minimum timeframe of six months is considered necessary because, depending on the data type, the model requires time to train and undergo fine-tuning.
When implementing a DLP solution, the rate of false positives should ideally be low. However, numerous variables must be adjusted, including proximity settings and other parameters.
For example, with a Social Security number, which is a nine-digit identifier, a DLP solution cannot be expected to flag every instance because this would result in excessive false positives. Proximity settings should be used strategically to reduce the number of false positives.
What about the implementation team?
A third-party implementation partner was engaged to manage the deployment.
What's my experience with pricing, setup cost, and licensing?
The cost structure depends entirely on which features are utilized.
Initially, when the product is not yet mature, implementation begins with basic features. As maturity and adoption increase, advanced features are then added. Pricing varies based on the features used, but the overall cost is on the higher side.
Which other solutions did I evaluate?
McAfee, Zscaler, Prisma, and Netskope Data Loss Prevention (DLP) were all evaluated. Netskope Data Loss Prevention (DLP) was selected as the winner.
Given the evolving SASE landscape and current market conditions, this choice receives a rating of eight.
What other advice do I have?
Remediation involves blocking specific communications when users attempt to upload sensitive information. Users should be provided with an interface to request exceptions in real-time for business-critical scenarios.
Such automation mechanisms are already in place. Overall, the solution receives a rating of six in this area. The review rating for Netskope Data Loss Prevention (DLP) is eight.
Which deployment model are you using for this solution?
SaaS-based
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other