Cisco CloudLock - Great DLP without the need for an entire team to support it.
Use Cases and Deployment Scope
We use Cisco CloudLock primarily to protect sensitive data from exposure in our Google Drive. Google has been able to go a long way toward replacing other forms of file sharing in our organization, but we still don't want some types of sensitive data there. With a very low false-positive rate (and certainly with no fancy regex configuration required), we can detect social security numbers and credit cards in our Google drive. Automatically notify the user, give them time to take action, and transfer the files out of their account to a secure location if they do not respond. This self-service workflow that Cisco CloudLock enables is why it can scale to such a large organization as ours. Our G Suite user count is relatively massive, but this product works well with minimal IT support. We sometimes need to flag false positives as such (usually in training documents designed to look like the data we're restricting). Cisco CloudLock also has other great features that help us manage our G Suite environment.
Pros
- Self-service workflows
- DLP detection with low false positives
- Good interface for managing incidents
- Locate and take action on any files within our G Suite implementation
Cons
- The security event notifications don't come as quickly as I would like
Return on Investment
- Audit compliance around sensitive data
- Protecting against accidental exposure
- Help IT Operations triage of other Google Drive related issues
Other Software Used
Splunk Enterprise Security (ES), Palo Alto Networks Cortex XDR






