logo

NJP

Managing DLP Alerts from Proofpoint in ServiceNow DLP Incident Response

Import · Jul 25, 2023 · video

hey Brian good morning to you hey Aaron how you doing hey great great good to see you you too all right let people roll in a little bit um and thanks for thanks for joining me today folks we'll get started in just a minute I'm gonna uh launch a quick poll and we can see uh what brought everybody here today and then we'll introduce ourselves and get started right you know we've got some folks trickling in and and as you join uh Aaron's got this poll that's uh populated about uh you know what brought you here today two simple questions so feel free I know we've got some people starting to respond to that so yep good stuff give us a good idea of uh you know what you're currently using um you know what you're familiar with uh I I really am mystify it as to how people find out about these webinars so um you know it's great it's great to you know see that the topics got some interest obviously we listed in our community but um you know that's good to see all today all right yep we've got we've got some people who use servicenow security operations against people that use proof points uh Sigma Information protection platform uh we'll talk about both those we've got some people that use neither so uh hopefully this is a bit of new information for those uh who already have some of these capabilities and for those that don't hopefully this is a really good use of time and learning experience but we'll uh Aaron and I'll get this kicked off here in a couple minutes we'll let uh everybody trickle in I know it's a little early particularly on the West Coast it looks like the responsive slowed down so I'll just go ahead and share the poll I was correct um more people find this find this content by an alternate route then um than necessarily by our blogs in the community so that's awesome um thanks everyone for joining we do have um it seems like uh some people familiar with security operations but not necessarily familiar with um with dlpir itself so look forward to talking about how proof point and servers now are working together on that so I'll go ahead and um introduce myself hey everyone my name is Aaron Bennett I'm uh part of our corporate development team here at servicenow focused on Partnerships uh in Security in other areas and a proud partner of proof point for a couple years now server snail has released the proof Point integration and um happy to have Brian from proof point on today Brian go ahead yeah thanks Aaron uh Brian Reed I'm the senior director of strategy over at proof points I've been over there for about three years now I've been in the security space a long time uh previous uh previously at Gartner as an analyst covering DLP among other topics like Cloud security and the like for about a half decade before that so uh again Aaron uh look I think we're going to walk everybody through the integration and how you know you hear this Better Together phrase a lot when companies come together uh and offer an integration or a way to take uh two platforms and bring them together and do some things but servicenow is doing some really interesting things on the the servicenow side with the DLP IR capability uh and proofpoint a lot of people are probably very familiar with proofpoint from an email security standpoint but that's really not what we're going to talk about as much today we're really going to talk about some of the information protection uh capabilities some of the DLP and Cloud security capabilities within proof point and how we bring that information uh over into servicenow and work with servicenow to help optimize uh DLP incident response specifically so uh yeah dovetails from that email use case everyone's familiar with just like with servicenow most people are familiar with RIT service management and not so familiar with our or their offering so I think we'll get into the weeds a little bit and see how proof point is protecting across dimensions of data when it comes to data loss not a servicenow how we've got this new capability where we can we can help you manage those detections and uh and kind of provide the workflow overlay to that yeah this is uh you know this is probably a bit of a Captain Obvious moment for a lot of people looking at this uh obviously protecting sensitive data is a huge challenge uh the explosion of data out there uh is is well recorded well documented I think everybody understands that you know what's certainly changed in light of the way that we change how we work uh the this uh notion that we work from anywhere and it seems like our data is seemingly everywhere users have access to a lot of different information whether it's across different channels whether it's email Cloud applications endpoints mobile devices as well as different applications and tools that that you use a lot of us use these world-class productivity platforms out there like Office 365 and Google workspace and servicenow to help do I.T service management but also other things like you know your governance risking compliance platform might be part of servicenow as well and you might have a number of different constituents and parties involved there and there's certainly a wealth of sensitive data when we're talking about something like a GRC platform the other thing that's that's no shock to anybody uh and this comes straight from uh proof points 2022 state of the fish report we since uh released our 2023 version uh here recently but the numbers are basically the same a little under half of users leaving their jobs admit to taking data with them when they depart so we have this huge problem that we call the levers use case where people are leaving the organization and they're taking things with them uh because they have this this sense of ownership the sense of uh the ownership mentality hey I created this information even though I worked at Acme Corp uh I own this this is this is intellectual property I created I might want to use it as proof that I'm capable in my next role uh but all of these things combined together really make information protection a top priority for Security leaders in csos globally so uh Aaron anything you want to add on top of this I think it's just a you know you're the experts in this area obviously we're focused on process and protecting data within the platform and that's one of those things where once it leaves those you know like sort of digital warehouses in the company or applications that's when you know you can lose track of what information is out there you know we can we can obviously you know control things with um you know roles and permissions within service now but what about what happens when those when those you know when that information starts to get copied and you know sent out by email notification that sort of thing that's when we have to you know um create a layer of protection around that well and you mentioned a key word in all of that which is process and and really documenting the process is really at the heart of how the integration works together you can throw tools at the problem all day long and there's a lot of great tools particularly that that proofpoint offers that other providers in the space offer uh I I've covered DLP for a long time for a number of years I was the the lead analyst and author of the last two Gartner Enterprise DLP magic quadrants and I personally I hate the acronyms of data at rest data and use data in motion I think there is a terrible way to describe the problem but it's a very simplistic way for us to understand that uh you know we've got data in different repositories we've got data that's exchanged and moves around and there's all these different Integrations Point integration points where we have visibility into the level of security we have the level of access and usage of data we have things like identity and access management identity governance systems we have endpoint detection and response capabilities get visibility to things like file moves copy create delete manipulation sorts of events that happen at endpoint and potentially mobile devices even through app access we have things like Sim and security orchestration and automation capabilities and and then we have classic uh you know the the network in motion uh data in motion elements which is really you know following encrypted information the other problem we have the cyber security industry is hugely fragmented uh Richard steinen who's another former Gartner analyst actually publishes every year uh the security yearbook and we're at over well over 3 100 cyber security companies uh in this space uh we have a lot of of like I said world-class collaboration platforms like Microsoft 365 like Google workspace and we almost have this fallacy that the platforms build in the security and it's good enough and they should be able to protect themselves you have 3 100 plus cyber security vendors would probably have something to say about that certainly proof Point included but the one of the issues with security and why it remains complex is this is a highly fragmented Market where we've tried to to solve this a lot of times in a channel-based way let's solve exfiltration at the end point let's solve uh data movement via web channels or email or let's try to do things to improve Security operation or you know let's let's Outsource our security to a managed service provider there are so many different markets in here and it becomes a really heavy lift to try to figure out the mappings of how all these things work together that's why Integrations like this that are both highlighted um you know by vendors like servicenow and proofpoint and ones where you're not paying a huge fee to do these things where it's included with the licensing of what you're already paying for it is such a huge uh benefit the average organization out there is using 50 plus security tools uh it it so again another point that these Integrations become a really important uh thing yeah and by the way I did say three thousand plus security firms uh a little over 3 100 is is what uh was noted in the most recent security yearbook published so uh I've actually got a copy of the 2020 yearbook where it was about 2 900 vendors out there so there are thousands of cyber security vendors out there the average organization has dozens of security focused tools this is a huge problem so so this is why folks like Aaron and I this is why integration is so important about getting tools talking together and ultimately making the value prop for you as as practitioners you know having that one plus one equals something more than two yeah I'll add to that too or uh I'll add to that that you know even if you're using a thumbnail like the 80 20 year old Brian um that's still over 600 companies that are going to be relevant in the security Market with a significant install base and um even like say using service now as an example we have hundreds if not possibly thousands of Integrations when you count the custom Integrations that are built by customers with a platform so the the technology sprawl is is is real you know and obviously um you know we probably need to focus down on you know reliable way to you know create that fence around the organization where we can keep data in um at least to you know roll you know applications and areas where we can control the roles and permissions like Office 365 and service now um and keep that data you know with in-house at least yep absolutely absolutely so um and again the the use of all of these different providers and Technologies all these different disjointed tools that don't have that level of integration I like you said Aaron it's it's that lack of visibility it makes things like investigation times longer uh and more efficient and one of the other things that's been pretty well documented in in the cyber security landscape last couple years has been burnout uh burnout by practitioners that are hands on burnout by csos and Security leaders you can go out and look at LinkedIn um just search CSO burnout and you'll see uh active csos at Fortune 500 companies talking about burnout both you know at the security leadership level but also the rank and file the practitioners the people that are Hands-On console and eyes on glass and it's because of this disjointed and fractured mentality so like I said these Integrations help alleviate some of these channels challenges they help improve uh metrics that we care about when we talk about security incident response so things like mean time to contain the mean time to remediation uh mean time to detection it really matters when you can start shaving minutes and hours and days off of your investigation cycle because you've got a lot of good two-way integration and information sharing between two really powerful platforms like servicenow and proofpoint you can make your lives a lot easier yeah and you can use that prioritization and automation you know because we're asking Security Professionals to do more I mean you know um I've seen in you know in his security operations center where you know we've got people focused on and specifically things like malware and you know obviously email security has been a long-standing you know focused focal point or locus of you know security events and now we're throwing all these other things in the Pod so um having a way for um these security practitioners to create a workflow where you know especially because dlp's user user heavy you know we have to interact with users who are owners that are custodians of the data um you know it it can become cumbersome so it's it's important to have ways to prioritize these things automatically and you know provide self-service portals for you know the responses that are needed for this kind of stuff so that we can take down the you know like obviously the workload that can be created by adding something like this like this practice to a security group yeah so Aaron we've done a great job in the first 10 15 minutes of uh doing what I would call admiring the problem let's let's actually dig in and talk about the integration of what we can do here so um yeah I mentioned not a big fan of data at rest data use data in motion but it's probably the easiest way to describe uh the Enterprise DLP problem out there so I know we've got a couple of customers of proofpoint uh on here uh we have a couple of platforms at proofpoint we recently rebranded our information protection platform which covers data loss prevention Insider risk and threat as our proof Point Sigma platform we have a unified what we call a unified incident manager unified alert Management console and we'll talk about that that centralized management and analytics capability on the proof Point side here in a minute uh but we're doing things like consuming uh via data at rest we're doing things like looking at files that you might have either labeled with something like Microsoft information protection labels uh or used our own proof points uh what we call intelligent classification and protection or picp to to scan that that content so the nice thing about our data at risk capabilities we can go through and we can scan files that you might have already MIP labeled and give you some guidance on how to make those labels better again not trying to necessarily say hey it's got to be proof Point labeled across the board we'll work with the content that you have if it's already my labeled we can provide some guidance to say hey maybe you're either mislabeling this or over labeling or under labeling or the like but really looking across our DLP capabilities we have capabilities at the endpoint our endpoint agent is the same agent whether you do DLP or Insider threat so we really look at Insider threat as a superset of DLP DLP again is all those those endpoint actions like file moves and copies and creates and executes and deletes and all that that sort of file level manipulation with data including things like on the windows and making changes to the the registry on the Mac side making changes to system extensions those sorts of things Insider threat management goes a step further we can do things like take screenshots of evidence and again if you're in a privacy sensitive uh place that might be something you you don't want to turn on we can also capture additional metadata we do some things where we can also on the unified management side we can do things like obfuscate usernames and file paths so that if you're investigating somebody you might not know that that person's an executive you might not know who that person is you might be investigating somebody's suspicious and we want to preserve the Integrity of that investigation by saying hey I see somebody staging a bunch of data um you know come to find out you know the investigation process that's your CIO doing it or your CFO you certainly would take a different view if you saw their name in the logs versus you know user Dash 82345 so it's really about preserving the integrity of these investigations uh obviously people know us for email security we've had email DLP as something at proof point for a dozen plus years now we also have capabilities around uh casby and we're going to talk more about this in a minute uh casby is a cloud access security broker and a great way to think about this is It's a a piece of cloud software that sits between your users and the cloud applications that you use so whether those Cloud applications are o365 Google workspace Salesforce servicenow uh it's it's a piece that sits in between there and spoiler alert servicenow uses proofpoint internally to help protect their employees their partners with the information that they share back and forth between the uh the servicenow cloud as well and again a key integration here we integrate with a lot of different providers on the identity side folks like OCTA and sailpoint and cyber arc on the privileged side folks like crowdstrike and Sentinel one at the end point folks like Palo Alto and zscaler at the network folks like Splunk for for things like Sim and security operations but servicenow really for that that IT service desk management and the DLP incident response piece uh is a really key integration point for the capabilities that proof plan offers and Aaron you want to chime in here a little bit uh deeper on the the integration that we have yeah I would just say that you know um the server's now integration you know the dlpir workspace we can I can share a screenshot of that um and sort of intersperse that when you're ready brain but the the you know the workspace abstracts away so you have you know analysts working in proof point and resolving you know taking actions you know doing the more complex tasks what we what we do in service now is we um we synchronize with those incidents that rise to the level of you know requiring a response and tracking and Reporting up to it management so this is a way to you know remove uh the swivel chair aspect of DLP management from you know the responders life and from the you know the oversight um person who's you know trying to manage this and a you know a number of other different security topics so um yes well you know there's a workspace within servicenow where you can actually see the information from proof Point status is updated bi-directionally um so it's it's really a way to you know create that sort of seamless um you know workspace approach so that we're not you know causing people to you know like break context and move between different you know screens and that sort of thing yeah Aaron if you want to share that screenshot I know I've got a couple here uh in a couple of slides I can I can hammer on those again but I'll let you uh I'll stop sharing because I think this is where yeah this is where your your slides will be sort of showing the um overview you know the view from the sort of the bird's eye view from the management layer but really where it starts is you know the detection you know obviously proof points got the different dimensions of those you know coverage areas with email endpoint DLP we can take those events and basically by rule bring them into service now so that you can you know you can filter out um things that are either less important or you know based on different attributes from the from the DLP alert so we're bringing in all these different fields you'll allow you to sort of customize like what you um track and respond to in your environment so types of you know um types of data you know which user Etc we can create you know specific rules to handle all that and then that lands in the DLP workspace so this is where someone in service now who's you know working you know security there may be like you know um you know different analysts like that that sort of work as the inbound team for these and you know decide whether things can be escalated or if they can be you know closed as is that you've got a layer of you know visibility on on these events as they come through and um you know once the person sort of works the event you know um checks the data um you know checks the status that sort of thing um they can create an additional record to have you know a sort of a higher level analyst work on or or security responder work on it or they can um you know basically you know do the close method the close workflow to to get this closed out you can create playbooks around these incidents as they come in so that you know some of these may go to an automated response and notify a user or some of these may go to a queue where you have people actually looking at the more critical alerts we also support I think uh you know the notifications so that users can respond you know to you know questionnaires on you know why they have the sensitive information in this particular you know storage area or on their laptop or on their phone they can they can see those alerts through their email um notifications from servicenow and then respond to those directly so that interaction is a little bit um you know it's a little bit less cumbersome so it's easier to get those you know to get that data and to like basically cycle down close the alert so then we can go back to you know um obviously looking at you know more important you know you know security incidents and that sort of thing yeah no this is a the integration here is is really key Aaron I can actually step through what that Enterprise DLP alert flow looks like between 100 point servicenow and the steps that uh we take and I've got a couple more screenshots in here as well right now that we can jump into all right you want to take the screen back yeah I'll uh I'll jump in so I'll just walk through a little bit and Aaron feel free to jump in here at each of these phases so DLP IR is is an add-on capability within the servicenow platform uh if you have the proof Point Sigma Information protection platform in place you have Enterprise DLP you have access to the proofpoint unified alert management or Incident Management System and what that looks like when you when you experience that that event is we're feeding in that DLP event whether it's email DLP whether it's endpoint DLP endpoint Insider threat casby we're feeding some Telemetry into our system what ultimately happens is the DLP rule engine gets matched a DLP alert violation gets fired off to the unified alert uh management system we then create an incident to happen we if it's something where we need to block uh or quarantine or do something like pop-up a justification uh notification at an endpoint that remediation takes place but at the same time that remediation takes place we also fire over via API to servicenow in the into the dlpir module that investigation context so that a ticket gets opened up uh on the dlpir side once that becomes resolved if it's something that's immediately blocked and things like that you can automate that incident resolution confirmation you can then feed that through the rest of the the IT service management stack but the real magic is being able to take that servicenow information however it's worked if there's additional things you need to do as Aaron mentioned on the process side you might need to go through and say hey I need to go sync up with my identity management platform and you know reset somebody's MFA or resent their credentials or change their ACLS or or do some other task related to potentially access of apps or data we can then take that information back from DLP IR into proof point and we can say hey this was resolved here's a link back to servicenow giving the entire description of things that might not be security specific they might be operation specific they might be HR and people specific that's recorded in servicenow and say hey look servicenow's got the full record of what transpired outside of the security operations team the security operations team doesn't necessarily want to get involved in HR kinds of things or legal or privacy or some of these other areas it's often best recorded over in that it service management system of record which is standardized on servicenow so it's really about putting the right things in the right platforms and the right places to make sure that you're fully working through yeah real quick yeah there was a question so a good opportunity to you know kind of clarify you know which you know uh modules and service now we're talking about when we're talking about this integration between point in service now so um uh proof point is still the system of you know you know obviously detection and action when it comes to resolving the DLP alerts and servicenow is going to be your work management layer um for those DLP alerts so that we can get that information similar to how we get events from uh you know like a Sim platform or vulnerabilities from a vulnerability scanning tool bring those into service now for um you know basically like um you know initial investigation um putting those through like a Playbook or a workflow on the servicenow side for notifications slas and the other sort of things that service now is really good at a workflow piece and then obviously synchronizing that information back with proof points so that you know those working in the proof Point side um doing the security you know configuration investigations can you know understand where you know there's still an open Event versus you know like a closed event and like we have like parody of information on both sides the DLP module is an add-on to our security operations uh Suite so if you're if you own uh if you own um we'll answer this one too if you own itsm or if you own security incident response you would still need to um to you know acquire the dlpir module in order to get this integration stood up and running because it's a specific module you know it's sort of purpose built to um you know get this type of alert and provide this type of workflow so it's sort of beyond the traditional like you know malware detection or um you know spam or phishing detection and it goes into this sort of specific data protection use case and that's where where this is so it's not itsm it's not you know security incident response or soar it's really this dlpir product that we've built specifically for this type of uh this type of workflow yeah hopefully that answers those questions yeah I went ahead and typed in there and paraphrased uh Aaron as you were talking there but what is yeah what is dlpir in action look like I know Aaron you shared the other uh slide here a minute ago of what that looks like these might be a little dated but uh this is the the workplace experience so being able to drill into open incidents by different severities looking at top offenders uh and this pulls back from proof Point uh that that people information the endpoint information the device information of where those DLP policy violations took place we can look at a list of those different uh DLP uh IR tickets that get opened we can see the policy name that matched the current state when they were opened uh critical high medium low being able to really drill in and who that's assigned to uh and working through and I know Rakesh has his hand raised and we'll uh we'll get to that but and again the detail here of really being able to see as far as working through the entire process what do you need to do to remediate and close out uh close out those instants you might need to create additional this might be an incident where where it spawns other things that need to happen I very quickly glossed over the example of privacy or legal issues or HR issues those might need to be things where on the servicenow side you would want to create uh you know dependent or child instances uh or incidents uh related to that that's not something you necessarily want to put in proof points so one of the real value points I see in servicenow dlpir is is taking a bit more of a DLP governance view uh where there are things that your security operations folks on you you know your DLP administrator will definitely want to be very hands-down uh involved in the information proof points Gathering whether it's from email whether it's from endpoint whether it's from cloud but there's a lot of other things DLP is kind of a unique animal in the sense that it touches things outside of security HR legal privacy business unit uh kinds of of topic areas Etc and that's really the power of dlpir is really being able to sort of chain those those incidents together and being able to see that from from a bigger picture standpoint yeah totally agree that's the that's the key takeaway Brian I think is that we can we can enable those additional processes you know that you know are required to close and you know create resolution on the DLP the DLP side at proof Point um in the platform you know link those workflows together in in one platform and you know create that connectivity I think that's really where you get your you know your game that the game that efficiency over manual process yeah all right all right um good stopping point to see I want I know it's bottom of the hour so some folks may have to may have to drop or you know leave us so I wanted to um basically find out if anyone's interested in you know getting a deeper dive into the dlpir integration and we can go through our last little bit of content so I'm going to launch a quick poll and then um Brian you can go through the slides as planned so here you go everybody absolutely yeah so we've got the poll we'll leave this up here for a minute to uh let everybody respond there and while you're responding in case you do need to run at the bottom of the hour I did want to skip up here so there are some things proofpoint offers a complimentary DLP and Insider risk Workshop you can reach out to proofpoint you can reach out to me directly be read b-r-e-d proofpoint.com happy to route you uh internally to the right folks but within the servicenow platform there's a landing page for DLP IR to learn more about that on the docs site at servicenow and then the the servicenow store actually has the DLP integration module for proof Point published out there so you can search just simply at store.servicenow.com search on proofpoint it should pop up there right in the store front and center for you yeah and you know just the you know other sort of news if you're a proof Point uh customer and planning on attending the you know company event in September you know servers now is planning to be the they're planning to bring demo station so that we can you know look at this in depth so if there's any interest in like learning more and you're planning to be in the event anyways please stop by and see us yeah we'll also be I know we've got the upcoming block hat conference in Las Vegas in August uh proof point will be there as well we'll have uh our our engineering team will be uh in the in the booth area happy to talk about any of our Integrations including servicenow uh there as well so um you know be able to show that unified alert Management console of bringing all those things together so if you are a servicenow customer and a proof Point Customer yeah be there right Brian we will we will um you can come see us in person if you'd like we'd love it yeah perfect all right so we've got some good uh responses back on the poll here uh Aaron I've got a couple other things that I wanted to share I'll go ahead and backtrack really quickly with a couple more headlines but um really I talked about that Sigma Information protection platform and again this is really looking across you know Windows Mac endpoints looking at all that user activity file activity it's in a single little unified alert management interface it's a great way to conduct the investigations in that that singular platform uh but I wanted to talk for a moment really quickly about the additional layer of security that's within service now so I I mentioned and kind of teased this a little bit that servicenow uh via API utilizes our Cosby capabilities as well so being able to Via that API connection uh we can we're actually protecting servicenow and looking at things like file movements and and suspicious Cloud user activity we're also doing things with with what we call AAC or adaptive access controls and we're looking at you know user and device risk so uh there's a really nice piece of this where it's not just a straight uh you know one or zero a lower block we also offer the ability that let's say you're connecting to servicenow from a risky area we could potentially redirect that to an isolated browser session where you know maybe you're not allowed to upload or download files within servicenow but you can view it systems management tickets and things like that so we could do a lot of things with the granularity of control and visibility into the servicenow platform to really help make that platform security I mentioned a couple times things like you know Microsoft 365 Google workspace sales force servicenow these are these anchor Cloud platforms that are really helping enable you know it productivity within all of our environments and it's really on us to help support the platform uh and make it more secure that's really the mission that we have at proof point is you know we don't think that security should fall solely uh at the feet of these these world-class platform providers you know like Microsoft and Google and servicenow you know we're here to help we're here to provide that additional layer of security uh and context visibility to help make those platforms as secure as they can possibly be and be that second set of eyes and really have these platforms back the way as servers now fully expect that customers will want a single system to you know obviously there's an email relays within the platform we generate a lot of email traffic because we're sending out you know notifications and getting responses to you know tasks within incidents and that sort of thing so we do fully expect that customers are going to aggregate that data in one system of security to scan and you know secure all those messages and determine you know the sensitivity and that sort of thing so yeah fully you know fully expected customers will want to hook hook into that email relay with proofpoint now perfect yeah and again just I know we touched on this here briefly a few minutes ago but if you are interested in those next next steps I I wanted to leave this slide up here for everybody so they could capture uh these URLs on the servicenow side where to go to find additional documentation uh and supporting resources to help get started with DLP IR all right we had a couple of questions so please keep them coming we'll be here and available as long as as long as you'd like to go with the content we can dive back in and dig deeper on any specific topics I'll run through some of the ones that were asked so that they're in the recording um so a couple about like which module this is in service now a couple different bytes of that Apple so it's not you know the itsm it's not part of the itsm module sort of the base you know where everyone usually starts with the platform it is part of our secop suite but it's not part of our security incident response like it's not an additional capability in there it's actually a separate module with its own data model and uh you know sort of architecture so it is part of secops but it is an additional module where you can actually you know just be specifically you know a DLP user if uh if that's if that's what you want to do and then um another question I think that we need to get to so on the servicenow side is this available now from Utah or the next one so the way we release um even if you know this is built within you know specific family release like Tokyo I think it was released for we make it backwards compatible to um prior releases so when it's released it'll be compatible for everything that's supported currently in you know in service now so I think it was like the last two uh if you're on San Diego or uh Tokyo um so it will continue to be you know certified going ahead as a service now integration so you should be able to expect that it's available you know it's not a it's not a limited GA product it's like fully released in GA so it should be available for whatever version of the platform you're using all right so we took note of those folks who did want a a follow-up and we're going to be glad to follow up with you um I think Brian got an answer typed in there so no I was just going to eat you at Estes it's available now from the Utah family or the next one and you had just answered um yeah great intentional for backward compatibility to you know hit all the open questions I don't see anything in the chat um there's uh somebody else get um probably needs to get going so yep Brian uh it's been great um you know talking about this topic with you today it's been it's been trying to find your super expert on the DLP side of things and I look forward to seeing you at Black Cat hopefully um people who joined us joined us today will um you know come see us in person whether at blackpat or the proof Point event um Brian anything you want to add yeah the uh proof Point event that that Aaron's mentioned is our protect 2023 conference that will be in New York City uh the uh week after Labor Day so uh if you're interested in attending that and you're a proof Point Customer please reach out to your account manager and they can get you additional information on that I did not have a link to the uh proof Point protect uh conference handy but you should be able to find it at the root of our website at www.proofpoint.com perfect and then obviously you know just final parting thought we were acting continuing to work on the integration PM is is you know adding capabilities we should see those within this quarter maybe August maybe September so continue to look for those we encourage you you know like as part of the follow-up um you know try the application get a demo and um we look forward to you know further interaction thanks again Brian for uh for presenting today yeah you got it Aaron thanks again for having us great all right we're gonna end everybody thanks so much have a great week thanks

View original source

https://www.youtube.com/watch?v=xGlO3aXB-8Y