A Product Built for a Different Security Question
DLP had been carefully designed around data: policies, channels, incidents, and violations. Its core capabilities — locating and tracking sensitive data across all channels, inspecting content using keyword matching, pattern detection, and machine learning, and taking immediate action when policy thresholds were crossed — ran in one direction: detect content, apply policy, respond. The system was built to catch what was moving, not to reason about who was moving it, or why.
But the security landscape shifted. After high-profile insider leaks — WikiLeaks being the most visible — enterprise customers were no longer asking only where sensitive data went. They were asking who was creating risk, whether behavior was unusual, and how to identify malicious or repeated activity amid thousands of daily incidents.
The product's architecture hadn't been designed to answer those questions. And the organization, moving through an annual waterfall release cycle, had no shared model for what investigation should look like at the identity level. The 2011–2012 product cycle was the window to change that.