proofpoint-signing-collective-cyber-defense-blog

Proofpoint Invests in FedRAMP High Authorization for Data Security & Insider Threat Management

Share with your network!

Extending Proofpoint Data Security and Insider Threat Management to Federal Agencies 

Federal agencies are transforming how they use, share, and protect data. Cloud, AI, and collaboration platforms are creating new opportunities to advance the mission, but also new ways for sensitive information to be exposed and trusted users to create risk –intentionally or unintentionally. 

Under FedRAMP's Consolidated Rules for 2026, the government raised the bar for what 'High' means. The old impact levels are now Certification Classes A through D, and FedRAMP High is Class D — reserved for systems where a compromise would cause severe or catastrophic harm to national security, law enforcement, or critical infrastructure. It's a higher, more rigorously tested bar than the label it replaces. 

That’s why Proofpoint is pursuing FedRAMP High (Class D) authorization for Proofpoint Data Security and Insider Threat Management, with completion targeted for 2027 — building on the Proofpoint Agentic Data & AI Security System we introduced last week, and on our experience. 

The planned scope includes Data Security Posture Management (DSPM), Multi-Channel Data Loss Prevention (DLP), and Insider Threat Management (ITM) – building on our experience meeting FedRAMP Moderate for Email Protection, Targeted Attack Protection (TAP) and Enterprise Archive solutions. 

Insider Risk Is a Mandate, not a Best Practice 

For federal agencies and cleared contractors, managing insider risk isn’t optional. Executive Order 13587 created a government-wide program for deterring, detecting and mitigating insider threats. Cleared contractors operate under similar requirements through the National Industrial Security Program Operating Manual (NISPOM), with the Defense Counterintelligence and Security Agency (DCSA) assessing implementation through recurring security reviews. 

CISA's newly updated Insider Threat Mitigation Guide: 2026 Edition, released this September, sharpens that mandate further — adding guidance specifically on how AI is changing insider risk, alongside the exposure created by hybrid and remote work. The stakes extend well beyond compliance. Insiders may have legitimate access to classified information, Controlled Unclassified Information (CUI), sensitive systems, and other national security resources. Misuse of that access—malicious or unintentional—can lead to unauthorized disclosure, espionage, fraud, sabotage or degradation of critical capabilities. To further protect CUI the Defense Industrial Base must use FedRAMP Moderate or High SaaS solutions according to DFARS 252.204-7012. For customers handling ITAR- and EAR-controlled data, FedRAMP High is also critical to ensuring data remains in U.S.-based data centers with support access limited to U.S. personnel. 

Meeting the mandate requires more than monitoring user activity – it also requires distinguishing routine work from meaningful risk and building enough evidence to act before harm is done. 

Proofpoint goes beyond traditional user activity monitoring by combining deep visibility into user behavior with data context and communications-derived insights into motive. It connects related behaviors and events over time to reveal risks individual signals may miss and explain not just what a user is doing, but why it matters. When further investigation is warranted, teams can progressively gather stronger evidence—including enhanced monitoring and screen capture—to intervene before concerning behavior becomes data loss, fraud, sabotage, espionage or other harm. 

Data Security Has to Keep Pace with AI — and with Insiders 

The definition of 'insider' is expanding. Federal directives and security guidance increasingly treat misconfigured AI systems, synthetic identities, and shadow AI usage as insider threats in their own right — capable of leaking sensitive data at machine speed, without any malicious human actor in the loop. (We wrote more on this shift in How AI Is Becoming the Next Insider Threat.) 

Federal agencies are also generating more sensitive data, in more places, faster than most can inventory it — unmanaged SharePoint sites, Teams channels, and cloud stores that grow without a corresponding update to who can access them. OMB's Zero Trust Strategy (M-22-09) treats this as a first-order problem, requiring agencies to know where sensitive data lives, who can access it, and how that access is controlled — not just secure the network and identities around it. 

Federal agencies and defense contractors must also protect sensitive information—including CUI, Personally Identifiable Information (PII), acquisition and mission data—across on-premises systems, cloud services, collaboration environments, endpoints and mission partners. As AI expands how that information is accessed, shared and used — including by AI agents and assistants acting on users' behalf — security teams need confidence that access stays appropriate as it happens. Excessive access, misconfigurations, or inappropriate sharing create exposure that traditional controls were never built to catch.  

For federal organizations, these aren't just security priorities—they're compliance requirements. The Federal Information Security Modernization Act (FISMA), NIST Special Publication 800-53 and the federal Zero Trust Strategy reinforce a data-centric approach built around identifying sensitive information, controlling access and continuously managing risk. Cybersecurity Maturity Model Certification (CMMC) similarly requires Defense Industrial Base organizations to safeguard CUI. Meeting these requirements also means demonstrating that protections remain effective as conditions change. 

Proofpoint connects discovery, access governance and prevention in a closed loop. AI-generated classification identifies sensitive information agencies didn't know to look for, while effective access analysis shows who and what can actually reach it. Agencies can reduce exposure through bulk or delegated access remediation, while the same understanding of sensitive data from DSPM can be directly protected through DLP across email, cloud, endpoints, collaboration, and AI. 

Data Security and Insider Risk Are Stronger Together 

Data Security and Insider Threat Management become more powerful when they operate from the same understanding of risk. 

Data Security provides insight into the information itself—what is sensitive, where it resides, who and what can reach it, while Insider Threat Management connects behavior, activity, context and motive to determine what represents meaningful risk and why. 

That combination is what we brought together last week in the Proofpoint Agentic Data & AI Security System, and it becomes even more important as AI assistants retrieve sensitive information on users' behalf, and AI agents act across enterprise systems. As these interactions grow in volume and speed, agencies need to evaluate data, identity, access and behavior together—not in isolation. This approach also aligns with CISA's Zero Trust Maturity Model, which describes more mature security operations as correlating information across multiple sources and using context to automate orchestration and response. 

Looking Ahead 

Federal agencies should not have to choose between accelerating AI adoption and maintaining control of their most sensitive information. Our goal is to help them protect that information, understand and reduce the insider risk surrounding it — including the risk introduced by AI itself — and securely embrace the technologies changing how government works. 

Pursuing FedRAMP High (Class D) is our next step toward delivering on that goal, building on our FedRAMP Moderate experience. We'll share updates as the authorization process moves forward. To learn more about our roadmap and how Proofpoint supports the security and compliance requirements of federal agencies and Defense Industrial Base (DIB) organizations, contact your Proofpoint account team.