A Global Manufacturer Takes Control of Data and AI

With Proofpoint DSPM, DLP, ITM, and AI Data Governance, a global manufacturer is gaining visibility into sensitive data, reducing data loss risk, and creating a foundation for secure AI adoption.

global manufacturer

At A Glance

For this global manufacturer with approximately 20,000 employees across more than 15 countries, protecting data is a complex undertaking. The company manufactures sensors and contactors used across a range of industries and operates major facilities around the world. Its business also includes an aerospace and defense unit with additional data protection requirements.

Products Used

  • AI Data Governance
  • Enterprise DLP
  • DSPM
  • Email Protection
  • Insider Threat Management

We didn't know where our data was going. We didn't know who was putting information on thumb drives or who was uploading sensitive data to maybe Dropbox or an external file share. Proofpoint helped us keep our data in-house.


Director of Cybersecurity

Company Size

20,000 employees 

Headquarters

Massachusetts, United States 

900 TB
data currently sized within Proofpoint
12.8K
classified files identified
33.4%
data identified as stale or abandoned
CHALLENGES
  • Lack of visibility into sensitive data and access: The company lacked a clear understanding of where sensitive data lived, who had access to it, and how it was being used. 

  • Preventing data loss across a complex global environment: The company needed to protect intellectual property—including engineering drawings, schematics, and bills of materials. At the same time, it had to navigate global privacy, regulatory, and customer-specific requirements. 

  • Securing rapid AI adoption without slowing innovation: A company-wide push to use AI created new data risks as employees adopted unsanctioned GenAI tools and began experimenting with AI agents. 

RESULTS
  • Greater visibility and control over sensitive data: Proofpoint DSPM provides a complete picture of where data resides, who owns it, and who has access to it. This visibility helps uncover excessive permissions, classify sensitive information, and prioritize remediation.  

  • Stronger prevention and investigation of data loss: With DLP deployed across the environment and ITM providing additional user context, the company can identify risky data movement, investigate user activity, and prevent data loss. 

  • A stronger foundation for secure AI adoption: The company is already using DLP to block document uploads to unauthorized GenAI tools. As Proofpoint AI security is fully deployed, the team expects greater visibility into what data is being exposed through AI and agents—enabling AI innovation while reducing the risk of sensitive data exposure. 

The Challenge

Understanding Where Sensitive Data Lives—and Where It Goes 

A global footprint creates a challenging security and compliance landscape. The company must protect modern IT environments alongside legacy operational technology (OT) systems. It also must address varying regulatory and customer requirements, including GDPR, Chinese data privacy requirements, and customer mandates to retain certain data for decades. 

At the center of the challenge is the company's most valuable information: its intellectual property, which requires strong protection from accidental exposure and emerging risks associated with generative AI. 

The company's data security journey accelerated dramatically following a ransomware incident. 

Proofpoint was already in place for email security, and the company had begun implementing Proofpoint Data Loss Prevention (DLP). However, the incident exposed a fundamental problem: the security team didn't have enough visibility into where its data resided. 

“We had the incident and we didn't know what data was where,” said the company's Director of Cybersecurity. 

That realization accelerated the company's data security roadmap. DLP deployment moved into high gear, and plans for Data Security Posture Management (DSPM) and AI governance—which had initially been considered for a later phase—were brought forward immediately. 

The company needed to answer fundamental questions: What sensitive data did it have? Where was it stored? Who could access it? How was it moving? And when employees move data to USB drives, external file-sharing services, websites or emerging AI tools, could the security team see and control those actions?  

“We didn't know where our data was going," said the Director of Cybersecurity. “We didn't know who was putting information on thumb drives or who was uploading sensitive data to maybe Dropbox or an external file share. Proofpoint helped us keep our data in-house.” 

At the same time, the team also faced rapidly developing data security challenges around AI. 

The company had launched a top-down initiative encouraging employees to do more with AI. Microsoft Copilot was its approved generative AI platform, but employees were still accessing and uploading documents to other GenAI applications, including ChatGPT and Gemini. 

The security team was concerned not only about public GenAI applications but also embedded AI capabilities and employees building their own AI agents. The organization needed visibility into how engineers, and manufacturing personnel, and other employees were using AI—and, most importantly, what corporate data those AI systems could access.  

The goal wasn't to stop AI adoption. It was to make AI adoption safer. 

“I want to enable them to do it the right way, but if I don't know what they're doing, then it's kind of tough,” said the Director of Cybersecurity.

The Solution

Securing the Data that Powers AI Innovation 

Rather than introducing another security platform and another endpoint agent, the company expanded its existing Proofpoint deployment. 

The security team already understood the Proofpoint platform. Expanding the relationship meant it would not need to deploy another vendor or learn about an entirely new environment. It also provided the opportunity to bring capabilities together into a more unified view. 

  • Proofpoint Data Security Posture Management: Finding, classifying, and reducing data risk. The security team can now identify what data exists across the organization, determine who has access to it, and understand when that data was last used. That creates opportunities to address both security risk and unnecessary data retention. DSPM also helped classify information such as new product development data and support decisions to restrict access to only the teams that require it, instead of broad access across the company.  
  • Proofpoint Data Loss Prevention: Controlling sensitive data everywhere. The company deployed DLP broadly across its environment to gain visibility of data in motion and unsanctioned GenAI tools. The security team receives alerts when significant amounts of data are being transferred and can investigate the user activity behind those events. DLP also serves as an investigative tool to understand potentially risky behavior and support response actions. DLP has also provided an immediate layer of protection against AI-related data loss. Before its broader AI security capabilities were fully deployed, the company used DLP to block users from uploading documents to unauthorized GenAI applications.  

  • Proofpoint Insider Threat Management: Adding context to risky user activity. By leveraging ITM, the security team sees visual evidence that helps investigators understand how a user attempted to move data and the actions that led to an incident. Combining DLP alerts with ITM context gives the team greater insight into what data is moving, who is moving it, and how.  

  • Proofpoint AI Data Governance: Enabling innovation without losing control of data. The company's AI journey is still evolving,. developing internal AI capabilities and agents. The company is exploring AI applications ranging from financial planning and business productivity to the possibility of highly automated manufacturing environments.  

Every new AI use case potentially creates a new path to sensitive data. 

Proofpoint's AI security and governance capabilities are built to give the security team visibility into what data is being exposed through AI and who is exposing it. Once fully deployed, the company expects to use that insight to make better-informed decisions about where restrictions are needed—without simply imposing blanket blocks that undermine productivity.  

The objective is to build security into AI adoption itself. The Director of Cybersecurity wants employees to engage security early, explain the AI projects they want to implement, and work together to find a safe path forward. 

The aim, she explained, is to make employees “forward- thinking and security- minded about AI”—not to turn every employee into an AI security expert.  

The Results

Visibility Into Data and AI 

Before implementing Proofpoint DLP, ITM, and DSPM, the company lacked a clear picture of where sensitive data resided, who could access it, and where users were sending it. Today, the cybersecurity team has significantly greater visibility into data at rest and in motion—and controls to help prevent sensitive information from leaving the organization.  

“Data security is always a continuous improvement program. It's never done," said the Director of Cybersecurity. “Now, with Proofpoint, we have a much better handle on where the data is and who owns it.” 

Key benefits include:

  • Greater visibility into sensitive data. DSPM helps the company understand what data exists across SharePoint and file servers, who can access it, who owns it, and when it was last used.  

  • Better classification and access control. The organization can identify sensitive content such as new product development information and recommend that access be restricted to appropriate teams.  

  • Stronger protection against data loss. DLP provides visibility into large data transfers and enables the company to prevent sensitive engineering files from being copied to removable storage or sent outside the organization.  

  • Deeper investigation of user risk. ITM gives investigators more context about user actions when risky data movement requires further investigation.  

  • Protection against shadow AI. DLP has already been used to stop document uploads to unauthorized GenAI applications. Proofpoint AI Data Governance is expected to provide broader visibility into data exposure through AI as deployment progresses.  

  • DSPM creates future financial benefits. The company currently has approximately 900 TB of data sized within Proofpoint and expects that identifying obsolete or unnecessary information could reduce storage costs by $300K to $400K.