Windstream Enterprise launched new data loss prevention (DLP) services underscoring the importance of DLP in secure access service edge (SASE) architectures.

Gartner defines DLP as “a set of technologies and inspection techniques used to classify information content contained within an object—such as a file, email, Packet, Application or data store—while at rest (in storage), in use (during an operation) or in transit (across a network).”

The DLP engine provided by Cato Networks – which the vendor added to its security services edge (SSE) 360 service in July – will enable Windstream’s SASE users to gain loss prevention for more than 350 data types covering globally sensitive information like health records or credit card and social security numbers, as well as country-specific information such as postal codes.

According to IBM, 90% of the world's data was created in the last two years. “Regardless of how ‘new world’ your business is, you're most likely receiving and storing some sort of private information that needs to be held private,” Windstream Director for SD-WAN and Security Chris Alberding told SDxCentral.

“You're going to get burned at some point. It's going to happen,” Alberding added. “And the costs that are associated with a data breach are exorbitant.”

One noteworthy example of getting “burned” occurred in April when Meta reported a data leak which exposed the information of more than 533 million of its users. On November 28, Ireland’s Data Protection Commission hit Meta with a $276 million fine, the third penalty the DPC imposed on the company this year.

Solutions to DLP are getting simpler and more cost-effective. Alberding said in the past, DLP generally required an “out-of-band solution,” meaning it needed a piece of network architecture and a software solution put in place specifically for the technology. But now that DLP is included with infrastructures like Cato’s, it's a “simple activation of a software feature.”

“That's a great inflection point to be at – the cost is going down, the ease of implementation is going up, along with the threat of data breaches,” he added.

Cato was joined this year by other providers like Juniper Networks and Citrix in adding enhanced DLP features to their security portfolios.

DLP Bolsters Cloud Access Security Broker Security

Windstream’s DLP works in conjunction with another key component of SASE, CASB, which provides visibility between users and an organization’s cloud services to apply security policies as they access cloud-based resources.

For DLP to function, CASB is necessary to provide visibility into the applications being requested or approved for access.

It's “critical that the two interact together,” Alberding said. “We're looking at seven different security interactions at any given time. And this is just another way to further that detailed inspection and compliance requirements for our customer.”

Alberding specified that due to the layered nature of the security stack, CASB and DLP solutions must come from the same provider to work together.

DLP as a SASE Afterthought

Gartner defined SASE in a 2019 report as the convergence of network access and security in cloud-native environments.

CASB is one of four components that make up the security piece of SASE, or what the analyst firm coined security service edge (SSE), a cloud-native suite that also includes zero-trust network access (ZTNA), Firewall-as-a-Service (FWaaS), and secure web gateway (SWG).

DLP is often mentioned as an afterthought to the four core SSE capabilities – a helpful but not entirely mandatory requirement to building out a SASE security solution. However, Alberding said enterprises should consider DLP as more essential to the SASE conversation.

“I think with SASE we're all learning that there is a massive desire to explore SASE from a customer's perspective,” he said. “I think DLP absolutely has to be part of the conversation.”

Alberding also acknowledged that not all enterprises can prioritize DLP. “It comes down to a risk-cost analysis. It drives the cost of the entire SASE solution up – not by much, it's incremental, but there is a cost increase there,” he explained.

But every organization should at least be planning ahead to build out a solution – complete with DLP – whenever they can.

“Every customer should take 100% of the SASE solution, but their budget may not support that,” Alberding said. “Focus on the areas of your highest risk, and then over time as your business evolves, plan to budget to cover things like DLP and CASB, and other things that might become more critical to your business.”