Major investment firm uses MIND to secure financial, PCI and PII data and replace Varonis for DLP

Industry

Financial services

Location

Global

Founded

N/A

Challenges

Data sprawl esp. company and customer secrets
Unhappy with legacy DLP tool
False positives and inefficiency

Solutions

MIND SaaS DLP
MIND On-prem DLP
MIND Endpoint DLP

MIND has given this global investment firm newfound confidence in DLP. With more than $30 billion in assets under management across vast strategies, sensitive data is stored everywhere and always in motion.

Challenges
  • Sensitive data exists everywhere and can come in from anywhere. The cybersecurity team describes data sprawl as one of their most concerning issues.
  • The amount of sensitive data continues to increase at an alarming rate. This means keeping vital data and company secrets secure is a constant challenge.
  • The firm’s previous data loss prevention (DLP) solution, Varonis, was time-consuming, had archaic user experiences and required labor-intensive manual processes. It was described as inefficient and painful.
  • Too much time and resources were being spent dealing with false positives. Because their previous DLP was so frequently wrong, it was untrustworthy and “not worth the effort.”
Solutions
  • With MIND™, the security team has newfound visibility and control—of data at rest, in motion and in use—all from one single pane of glass.
  • Without the constant barrage of time-consuming false positives to investigate, the data security team describes spending very little time in the MIND platform, which is a good thing.
  • MIND uses AI and tailored algorithms to classify sensitive data. This eliminates manual efforts and provides better insights into data movement and user activities.

Needed to gain control of sprawling information

At this global investment firm, the data security team is responsible for keeping massive amounts of sensitive data secure. The firm manages more than $30 billion in assets around the world, with vital information coming from an array of portfolio companies and sprawling throughout the firm and its many platforms. Their previous DLP solution, Varonis, had never done a good job, but with the explosion of data in recent years, it was becoming even less relevant. The firm’s data security team knew they needed a new solution.

The most important thing is to know where the data is and what it is. That was a challenge because there weren’t any tools to do that unless the data was only in one place. That’s almost impossible these days.

Senior Security Engineer, Investment Firm

The cybersecurity team describes this explosion of sensitive data as one of their most pressing security issues. This includes more than just financial information. In addition to dealing with credentials, personal identities and HR information, they also need to protect valuable proprietary models and deal information, all of which must be kept safe and secure. With data growing every second, it was imperative that IT and cybersecurity teams get a handle on this information in order to prevent data loss. “The problem with deal data is that it might be on any one of a hundred platforms. It’s never all in one place,” says the firm’s Chief Information Security Office (CISO) and Chief Technology Officer (CTO).

MIND provides a centralized platform that gives the firm visibility and control over sensitive data and user activities. For the first time, the security team was able to track data at rest, in motion and in use, enforce security controls, investigate leaks and remediate as needed. All from one central place.

Data is what everyone is after and data is what nobody can control. What’s been missing is that central place that could put everything together. Tell us not only about data at rest, but tell me about data in flight.

CISO and CTO, Investment Firm

False positives with legacy DLP led to a lack of trust

The security team was also frustrated by having to deploy so many manual processes. Because their previous DLP solution was producing an exorbitant amount of false positives, the team felt like they were wasting time chasing these extraneous alerts. Investigations were time-consuming and cumbersome, and mainly served to confirm suspicions that their previous DLP solution was ineffective.

Everything was being done manually. The team had to run searches or queries and try to figure out what was going on. They might need to actually reach out to the owner of that file or data in order to understand it, and then apply the right tag or classification around it.

Senior Security Engineer, Investment Firm

MIND uses AI and hundreds of tailored algorithms to classify and categorize sensitive data. This eliminates manual processes and allows the cybersecurity team to streamline and automate. Now, instead of wasting time on false positives, they can trust MIND to intelligently monitor activities, stop data leaks and help remediate if there’s a legitimate problem.

Before MIND, the firm’s CISO had lost faith in DLP

The firm’s CISO spoke about painful past experiences with failed DLP programs. Having implemented them at previous companies, this was someone with deep knowledge and experience—and disdain. “The problem is they never work. There’s always ways around it,” he said. “Great, so you've encrypted this on your network. Now someone needs to send it externally so it’s de-encrypted. Okay, then what was the point in the first place?”

I bet you’ll get maybe 2 out of 100 CISOs to say they’ve EVER done a successful DLP program. There’s always ways around it, and they’ve never created enough value to justify the pain. There’s just way too much pain.

CISO and CTO, Investment Firm

In this CISO’s opinion, legacy DLP solutions weren’t just expensive and ineffective, they were also extremely painful to implement and manage. “I hate it, I’ve always hated it,” he said about their previous DLP solution. And yet, he used it for 15 years. Because until MIND, there wasn’t a better solution.

MIND provided value within hours and built trust

The security team describes an effortless experience getting started with MIND. Within hours of implementation, the platform was already showing results and proving its value. They describe the user experience as intuitive and sleek. “Even just going into it you can immediately see it’s modern. Our old DLP tool looked like it was from 1995 or something,” says one security engineer.

MIND makes our yearly attestation process that much easier. It reduced the amount of resources we need managing data security and allows those folks to go do other things.

CISO and CTO, Investment Firm

For this firm, MIND dramatically reduced the manual effort needed to protect sensitive data and ensure compliance. The automation and insights provided by MIND have simplified workflows, enhanced data visibility and improved the cybersecurity team’s ability to protect all kinds of sensitive information. Looking ahead, the firm anticipates continued improvements in efficiency, security and compliance as it further integrates MIND into its operations.

You may also like

Tell us what’s on your mind. Get a live demo or just reach out to us.