Nightfall
[🎙 Live webinar on June 26th. Build vs Buy: Designing an Effective DLP Program in the AI Era with Confluent CISO Chris Sandulow\ \ Save your seat\ \
Articles written by
Emily Heaslip
\ \ Blog\ \ What is DevSecOps: A Comprehensive Guide \ \ The rise of cloud, containers, and microservices has shifted the way software developers work for good. Whereas traditionally, software developers would release a new version of an application every few months, today’s platforms allow teams to work faster and more streamlined. These advancements have led to the rise of “software, safer, sooner” — also known as DevSecOps.\ \ \ \ Added\ \ November 30, 2022](/content/blog/what-is-devsecops-a-comprehensive-guide/index.html)
\ \ Blog\ \ 5 Stages of the Vulnerability Management Process \ \ The threat landscape in IT is ever-evolving, with new risks arising practically daily. Trying to anticipate the next type of threat can feel a little like playing whack-a-mole. Instead, IT teams are focusing on vulnerability management: reducing the opportunities for hackers and other bad actors to find a weakness in cyber defenses.\ \ \ \ Added\ \ October 27, 2022](/content/blog/5-stages-of-the-vulnerability-management-process/index.html)
\ \ Blog\ \ Understanding Sensitive Data Discovery: Classification and Tools \ \ In its 2022 Cost of a Data Breach report, IBM notes that for 83% of companies, it’s not if a data breach will happen — but when. The sheer volume of data, as well as the difficulty in monitoring shadow IT and the shift to remote work, means that IT security teams face a persistent and ever-changing risk landscape that makes it extremely difficult to keep information secure.\ \ \ \ Added\ \ October 17, 2022](/content/blog/understanding-sensitive-data-discovery-classification-and-tools/index.html)
\ \ Blog\ \ Establish an Efficient DLP Policy With These 5 Best Practices \ \ Strong data loss prevention requires two things: a strong policy that guides user actions and permissions, and the tools to monitor and manage data security. Many organizations know they need to invest in software, platforms, and other security settings to create secure networks, endpoints, and cloud settings. But not every organization has a strong DLP policy to guide these tools.\ \ \ \ Added\ \ October 4, 2022](/content/blog/establish-an-efficient-dlp-policy-with-these-5-best-practices/index.html)
\ \ Blog\ \ How To Create A Cloud Security Policy [+ FREE Template] \ \ By one estimate, 60% of all corporate data is stored in the cloud. Businesses rely on cloud platforms like Slack, Google Drive, GitHub and Confluence to store data, share information, and run smoothly.\ \ \ \ Added\ \ September 28, 2022](/content/blog/how-to-create-a-cloud-security-policy/index.html)
\ \ Blog\ \ The Importance of Email DLP for Remote Organizations \ \ Email is a popular channel for hackers: phishing attacks and malware usually originate from email. In 2022, Verizon found that 82% of breaches involved the human element: phishing emails and ransomware delivered via email continue to plague organizations of all sizes.\ \ \ \ Added\ \ September 27, 2022](/content/blog/the-importance-of-email-dlp-for-remote-organizations/index.html)
\ \ Blog\ \ How Does Data Visibility Help With Data Loss Prevention? \ \ Data loss prevention starts with data visibility. Without a clear idea of what data an organization has, where it lives, and how it’s used, data loss prevention (DLP) is essentially an exercise in futility.\ \ \ \ Added\ \ September 22, 2022](/content/blog/how-does-data-visibility-help-with-data-loss-prevention/index.html)
\ \ Blog\ \ What Is Cloud DLP And Why Do You Need It For Remote Work? \ \ Remote work is not going away. Depending on who you ask, experts believe 35% - 65% of the US workforce will continue to work remotely, permanently. Remote work was a trend that began well before the pandemic and will continue to be the preferred way to work for companies and employees alike.\ \ \ \ Added\ \ September 20, 2022](/content/blog/what-is-cloud-dlp-and-why-you-need-it-for-remote-work/index.html)
\ \ Blog\ \ Data Loss Prevention: Fundamentals and Best Practices \ \ Ransomware and other cyber attacks are getting more expensive every year. IBM’s recent report found that the average cost of a breach increased 2.6% from $4.24 million in 2021 to $4.35 million in 2022 — and the year isn’t over yet.\ \ \ \ Added\ \ August 30, 2022](/content/blog/data-loss-prevention-fundamentals-and-best-practices-nightfall/index.html)
\ \ Blog\ \ How To Integrate Endpoint DLP Into Your Company's Security Policy \ \ Even before the pandemic, many companies had a relaxed approach to the devices employees brought to work. In fact, many businesses had BYOD (bring your own device) policies that allowed team members to work on personal laptops or cell phones. By one account, 75% of employees use their personal cell phones for work.\ \ \ \ Added\ \ August 30, 2022](/content/blog/how-to-integrate-endpoint-dlp-into-your-companys-security-policy/index.html)
\ \ Blog\ \ What is Data Hygiene and Why Is It Important \ \ Data errors and inconsistencies cost companies millions of dollars a year. Businesses that aren’t able to implement the tools, strategies, and training required often find big data to be more of an obstacle than an advantage. Until business leaders invest in strong data hygiene practices, big data’s promise will continue to remain elusive.\ \ \ \ Added\ \ August 18, 2022](/content/blog/what-is-data-hygiene-and-why-is-it-important/index.html)
\ \ Blog\ \ Cyber Hygiene Key Principles and Best Practices \ \ Ransomware and other cyber attacks are getting more expensive every year. IBM’s recent report found that the average cost of a breach increased 2.6% from $4.24 million in 2021 to $4.35 million in 2022 — and the year isn’t over yet.\ \ \ \ Added\ \ August 12, 2022](/content/blog/cyber-hygiene-key-principles-and-best-practices/index.html)
\ \ Blog\ \ Nightfall vs. Aware: Looking for an alternative to Aware? \ \ Most companies are determined to make remote work feasible for the future. To do so, they need the right tools to maintain data security while their employees work here, there, and everywhere.\ \ \ \ Added\ \ July 27, 2022](/content/blog/nightfall-vs-aware/index.html)
\ \ Blog\ \ Nightfall vs. BetterCloud: Looking for a BetterCloud alternative? \ \ By one estimate, the average company has a whopping 254 SaaS apps (with enterprises averaging 364 apps). Employees may not be using all 250+ SaaS platforms regularly; this leaves dozens of apps with unchecked access to the business’ IT environment — a big security risk.\ \ \ \ Added\ \ July 23, 2022](/content/blog/nightfall-vs-bettercloud/index.html)
\ \ Blog\ \ Nightfall vs. Prisma Cloud: Looking for a Prisma Cloud Alternative? \ \ There are many types of solutions available to organizations that seek to secure their data in the cloud. From cloud DLP to Cloud Access Security Brokers (CASBs) to Cloud Workload Protection Platforms (CWPPs). But, how can you tell which approach to cloud security is right for your business?\ \ \ \ Added\ \ July 22, 2022](/content/blog/nightfall-vs-prisma-cloud/index.html)
\ \ Blog\ \ What is PII? Guide To Personally Identifiable Information\ \ “PII” stands for personally identifiable information. Hackers often target personally identifiable information for a variety of reasons: to steal a customer’s identity, take over an account, launch a phishing attack, or damage an organization. As a result, there is a multitude of regulations concerning PII protection.\ \ \ \ Added\ \ July 20, 2022](/content/blog/what-is-pii-guide/index.html)
\ \ Blog\ \ Nightfall vs. Netskope: Looking for a Netskope Alternative? \ \ Ransomware, phishing, and malware are persistent and ever-evolving threats that today’s remote workspaces need to consider. The shift to a remote-first office, which for many has become permanent, has meant that companies need to be better equipped to protect their data in the cloud.\ \ \ \ Added\ \ July 20, 2022](/content/blog/nightfall-vs-netskope/index.html)
\ \ Blog\ \ What is ePHI? A Guide to electronic Protected Health Information (ePHI) \ \ ePHI stands for electronic protected health information. Electronic protected health information is protected under the Health Insurance Portability and Accountability Act of 1996, commonly known as HIPAA.\ \ \ \ Added\ \ May 26, 2022](/content/blog/what-is-ephi-a-guide-to-electronic-protected-health-information/index.html)
\ \ Blog\ \ What is the HIPAA Security Rule? \ \ Title II of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) has two key provisions: the Privacy Rule and the HIPAA Security Rule.\ \ \ \ Added\ \ May 24, 2022](/content/blog/what-is-the-hipaa-security-rule/index.html)
\ \ Blog\ \ A Quick Guide To Information Security Programs \ \ Broadly speaking, an information security program is a set of activities and initiatives that support a company’s information technology while protecting the security of business data and enabling the company to accomplish its business objectives. An information security program safeguards the proprietary information of the business and its customers.\ \ \ \ Added\ \ May 10, 2022](/content/blog/a-quick-guide-to-information-security-programs/index.html)
\ \ Blog\ \ Understanding the GLBA Safeguards Rule \ \ The Gramm-Leach-Bliley Act (GLBA) aims to protect consumer financial privacy with three provisions: the Financial Privacy Rule, the Safeguards Rule, and the Pretexting Provisions.\ \ \ \ Added\ \ May 6, 2022](/content/blog/understanding-the-glba-safeguards-rule/index.html)
\ \ Blog\ \ Network Segmentation: What Is It and How Does It Affect PCI Scope? \ \ Network segmentation is a practice that can dramatically lower the time, effort and cost of a PCI DSS assessment. Not only is it an industry best practice for security cardholder data, but it’s also an effective way of controlling the annual commitment of meeting your PCI compliance requirements.\ \ \ \ Added\ \ April 11, 2022](/content/blog/network-segmentation-what-is-it-and-how-does-it-affect-pci-scope/index.html)
\ \ Blog\ \ PCI Compliance for Small Business \ \ PCI compliance applies to businesses of all sizes: In fact, the PCI Council sets compliance standards according to how many card-based transactions a business handles each year.\ \ \ \ Added\ \ April 11, 2022](/content/blog/pci-compliance-for-small-business/index.html)
\ \ Blog\ \ What are PCI Security Standards? \ \ PCI DSS stands for Payment Card Industry Data Security Standard. This standard is set forth by the PCI Security Standards Council, an organization founded in 2006 by American Express, Discover, JCB International, Mastercard and Visa Inc.\ \ \ \ Added\ \ April 11, 2022](/content/blog/what-are-pci-security-standards/index.html)
\ \ Blog\ \ How to Test for PCI Compliance \ \ PCI compliance is a complicated matter. There are a number of different steps to meet and validate your achievement of the PCI DSS standard. In this guide, we’ll break down the steps in PCI compliance testing, the different types of PCI compliance tests, and how much it costs to complete this process.\ \ \ \ Added\ \ April 11, 2022](/content/blog/how-to-test-for-pci-compliance/index.html)
\ \ Blog\ \ Understanding The HIPAA Breach Notification Rule \ \ Some PHI breaches, however, are out of the organization’s control. Determined hackers can expose PHI, and employees can make mistakes — they’re only human, Despite training, rigorous security protocols, and constant monitoring, data breaches can happen.\ \ \ \ Added\ \ March 16, 2022](/content/blog/understanding-the-hipaa-breach-notification-rule/index.html)
\ \ Blog\ \ What Are Covered Entities Under HIPAA? \ \ HIPAA’s regulations refer to two parties: a covered entity and a business associate. These groups are required to achieve PHI compliance. Specifically, this means these groups are liable for protecting the confidentiality, integrity, and availability of personal health information.\ \ \ \ Added\ \ March 11, 2022](/content/blog/what-are-covered-entities-under-hipaa/index.html)
\ \ Blog\ \ HIPAA Compliance Checklist: A Quick Guide \ \ HIPAA compliance requires covered entities and business associates to secure protected health information. Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, and names of patients, relatives, or employers all must be secured from unauthorized access.\ \ \ \ Added\ \ March 11, 2022](/content/blog/hipaa-compliance-checklist-a-quick-guide/index.html)
\ \ Blog\ \ 5 Most Common HIPAA Violations and Their Penalties \ \ Those who work in the healthcare industry know: HIPAA compliance is often fiercely enforced by the Department of Health and Human Services, and penalties can be steep.\ \ \ \ Added\ \ March 11, 2022](/content/blog/5-most-common-hipaa-violations-and-their-penalties/index.html)
\ \ Blog\ \ Understanding The Gramm-Leach-Bliley Act (GLBA) Privacy Rule \ \ The Gramm-Leach-Bliley Act, known as the GLBA, was passed in 1999 under President Clinton. The goal of the GLBA was to update and modernize the financial industry. Today, it’s primarily used to protect customer and consumer information, with steep penalties for financial institutions that violate its privacy rules. Here’s what you need to know about the GLBA and its regulations.\ \ \ \ Added\ \ February 27, 2022](/content/blog/understanding-the-gramm-leach-bliley-act-glba-privacy-rule/index.html)
\ \ Blog\ \ NIST vs ISO Compliance: What's the Difference? \ \ As businesses and health organizations seek to strengthen cybersecurity, they’re turning frequently to compliance frameworks to help prioritize, guide, and improve decision-making and implementation. Two of the more popular compliance frameworks are the NIST CSF and the ISO 27001.\ \ \ \ Added\ \ February 16, 2022](/content/blog/nist-vs-iso-compliance-whats-the-difference/index.html)
\ \ Blog\ \ What is Data Exfiltration? \ \ Data exfiltration, quite simply, is the risk of your data ending up somewhere it doesn’t belong. Though this definition might seem simple, understanding this risk is quite complicated — especially as companies migrate their data into the cloud. Companies that work remotely using cloud platforms like Google Drive, AWS, or Jira often struggle to maintain the visibility needed to ensure their data remains secure. This increases the risk of data exfiltration, which can often go undetected for weeks, if not longer.\ \ \ \ Added\ \ February 10, 2022](/content/blog/what-is-data-exfiltration/index.html)
\ \ Blog\ \ What is Unstructured Data? \ \ Unstructured data is data that cannot be processed and analyzed using conventional data tools and methods: qualitative data, such as customer feedback or social media posts are considered unstructured data.\ \ \ \ Added\ \ February 2, 2022](/content/blog/what-is-unstructured-data/index.html)
\ \ Blog\ \ 4 Data Governance Best Practices \ \ Data governance is the principled approach to managing data during its life cycle — from the moment you generate or collect data to its disposal. Good data governance ensures that data is kept private, accurate, usable, and most of all: secure.\ \ \ \ Added\ \ January 27, 2022](/content/blog/4-data-governance-best-practices/index.html)
\ \ Blog\ \ How Penetration Testing Helps Cloud DLP \ \ The market for penetration testing is expected to reach $3.1 billion by 2027, rising at a market growth of 12% CAGR during this time. Fueled by the rising number of mega-breaches and more sophisticated attacks, IT teams are taking a more proactive approach, using penetration testing to validate and improve their security configurations.\ \ \ \ Added\ \ January 19, 2022](/content/blog/how-penetration-testing-helps-cloud-dlp/index.html)
\ \ Blog\ \ How To Protect and Store Sensitive Data in SaaS Platforms with Cloud DLP \ \ Mega-breaches, or reported breach incidents that impact more than one million records, have increased dramatically. Our analysis shows that, on average, mega-breaches increased 36% year over year since 2016.\ \ \ \ Added\ \ January 14, 2022](/content/blog/how-to-protect-and-store-sensitive-data-in-saas-platforms-with-cloud-dlp/index.html)
\ \ Blog\ \ How To Manage The Hidden Impacts of Data Leak With Cloud DLP \ \ Data leaks are a type of data loss threat that often fly under the radar — making them potentially more damaging than a malware or ransomware attack. Compared to data breaches, data leaks put customer information at risk accidentally. Data leaks can lead to credit card fraud, extortion, stolen IP, and further attacks by cybercriminals who seek to take advantage of security misconfigurations.\ \ \ \ Added\ \ January 11, 2022](/content/blog/how-to-manage-the-hidden-impacts-of-data-leak-with-cloud-dlp/index.html)
\ \ Blog\ \ Database Security: How Cloud DLP Can Help Protect Sensitive Data \ \ Databases are great targets for hackers and cybercriminals. There’s a wealth of information that can be gained by infiltrating a database, from proprietary intellectual property to customer data to financial records. One of the reasons why database security is so difficult is known as “Anderson’s rule” — that the more useable and more accessible the database, the more vulnerable it is to security threats.\ \ \ \ Added\ \ December 17, 2021](/content/blog/database-security-how-cloud-dlp-can-help-protect-sensitive-data/index.html)
\ \ Blog\ \ Data Masking Techniques and Best Practices for Data Security \ \ The risks of a data leak have never been higher. Over the last year, data breach costs rose from $3.86 million to $4.24 million, a record high. Data exfiltration, sophisticated hacker attacks, and even insider threats are forcing organizations across the board to take a more sophisticated, multi-layered approach to data security.\ \ \ \ Added\ \ December 9, 2021](/content/blog/data-masking-techniques-and-best-practices-for-data-security/index.html)
\ \ Blog\ \ How To Protect Sensitive Data with Cloud DLP \ \ A recent report from IBM found that data breach costs rose from $3.86 million to $4.24 million in 2021. This year’s estimate is the highest average total cost in the 17-year history of the IBM Cost of a Data Breach Report.\ \ \ \ Added\ \ November 30, 2021](/content/blog/how-to-protect-sensitive-data-with-cloud-dlp/index.html)
\ \ Blog\ \ 6 Cloud Data Loss Prevention Best Practices & Strategies \ \ Data loss prevention (DLP) refers to a category of tools and technologies that classify, detect, and protect information (data) in three states: data in use, data at rest, and data in motion. The purpose of DLP is to enforce corporate data security policies that govern where data does — and doesn’t — belong.\ \ \ \ Added\ \ November 22, 2021](/content/blog/data-loss-prevention-best-practices-strategies/index.html)
\ \ Blog\ \ PCI Data Discovery Tools: Keeping Sensitive Data Protected Within Your Organization \ \ The rules set forth by PCI-DSS can seem complicated. Four levels, 12 requirements, multiple credit card brands: it’s easy to get lost in the details of PCI-DSS requirements.\ \ \ \ Added\ \ November 19, 2021](/content/blog/pci-data-discovery-tools-keeping-sensitive-data-protected-within-your-organization/index.html)
\ \ Blog\ \ A Definitive List of Different Cloud Compliance Standards \ \ Cloud security is not only good for consumers — but it’s also a requirement for businesses in many industries. Understanding compliance regulations (like GDPR) and security frameworks (like NIST) can help IT teams create strong, layered privacy and security controls and data loss prevention using a range of platforms and integrations\ \ \ \ Added\ \ November 14, 2021](/content/blog/a-definitive-list-of-different-cloud-compliance-standards/index.html)
\ \ Blog\ \ A Definitive Guide to Security Analytics \ \ Security analytics has become an increasingly popular field as more and more organizations take a different tact to cybersecurity. Historically, IT teams focused on prevention and protection, but today’s priority is detection.\ \ \ \ Added\ \ October 29, 2021](/content/blog/a-definitive-guide-to-security-analytics/index.html)
\ \ Blog\ \ Slack Security: FERPA and HIPAA Compliance \ \ During the pandemic, healthcare and education providers scrambled to adapt to providing services remotely, using tools like Slack, Google Drive, and Zoom to continue connecting with patients and students.\ \ \ \ Added\ \ September 29, 2021](/content/blog/slack-security-ferpa-and-hipaa-compliance/index.html)
\ \ Blog\ \ The Essential Guide to Content Moderation \ \ According to a recent CNBC report, Google has seen a rise in posts flagged for racism or abuse on its message boards. This has caused the company to ask its employees to take a more active role in moderating internal message boards.\ \ \ \ Added\ \ September 13, 2021](/content/blog/the-essential-guide-to-content-moderation/index.html)
\ \ Blog\ \ What is Data Loss Prevention (DLP) And How Does It Work \ \ Data loss prevention solutions have evolved significantly in recent years, with cloud DLP providing a cutting-edge solution to protecting sensitive data many companies share over SaaS, IaaS, and PaaS platforms. Here’s what you need to know about data loss prevention and how to implement strict controls in your business.\ \ \ \ Added\ \ September 9, 2021](/content/blog/what-is-data-loss-prevention-dlp-and-how-does-it-work/index.html)
\ \ Blog\ \ Vulnerability Management Lifecycle, Process, and Best Practices \ \ The vulnerability management lifecycle reflects the fact that cyber defense is a full-time occupation. Vulnerability management should be iterative, with constant monitoring, documentation, and review of your organization's security protocols and defense. From updating your software to recording new patches, vulnerability management is a constant process that benefits from automated tools like Nightfall.\ \ \ \ Added\ \ August 24, 2021](/content/blog/vulnerability-management-lifecycle-process-and-best-practices/index.html)
\ \ Blog\ \ 5 Types of Social Engineering Attacks and How to Mitigate Them \ \ Social engineering is a type of cyber attack that targets people to gain access to buildings, systems, or data. Social engineering attacks exploit human vulnerabilities to get inside a company’s IT system, for instance, and access its valuable information.\ \ \ \ Added\ \ August 17, 2021](/content/blog/5-types-of-social-engineering-attacks-and-how-to-mitigate-them/index.html)
\ \ Blog\ \ 7 Indicators of Compromise: The Essential List for Breach Detection \ \ Indicators of compromise are the red flags of the information security world. These helpful warnings allow trained professionals to recognize when a system may be under attack or if the attack has already taken place, providing a way to respond to protect information from extraction.\ \ \ \ Added\ \ August 17, 2021](/content/blog/7-indicators-of-compromise-the-essential-list-for-breach-detection/index.html)
\ \ Blog\ \ How to Comply with Facebook’s New Data Protection Assessment \ \ Recently, Facebook announced a new initiative aimed at protecting how its users’ data is managed across its platforms: the Data Protection Assessment. The assessment consists of a questionnaire for apps that access advanced permissions and specifically focuses on how developers protect, share and use platform data.\ \ \ \ Added\ \ August 9, 2021](/content/blog/how-to-comply-with-facebooks-new-data-protection-assessment/index.html)
\ \ Blog\ \ Developing Secure Web Applications: 6 Best Practices \ \ When businesses think about maintaining cybersecurity, the first thing that comes to mind is often endpoint and network security. However, web application security is becoming increasingly important. There have been numerous high-profile attacks on web applications in recent years; in 2020, for instance, the Twitter accounts of famous people were compromised as part of a bitcoin scam.\ \ \ \ Added\ \ August 4, 2021](/content/blog/developing-secure-web-applications-6-best-practices/index.html)
\ \ Blog\ \ The NIST Cybersecurity Framework: Security Checklist And Best Practices \ \ The National Institute of Standards and Technology (NIST) is part of the US Department of Commerce and was founded in 1901. NIST was originally established to help the U.S. industry become more competitive with economic rivals and peers, such as the UK and Germany. NIST prioritizes developing measurements, metrics, and standards for technology used in different industries.\ \ \ \ Added\ \ July 16, 2021](/content/blog/the-nist-cybersecurity-framework-security-checklist-and-best-practices/index.html)
\ \ Blog\ \ GLBA Compliance Checklist: Keeping Financial Data Safe And Secure \ \ GLBA compliance isn’t something to take lightly. These measures are strictly enforced by the Federal Trade Commission (FTC). In 2018, for instance, Venmo and its parent company PayPal reached a settlement after complaints about the company’s handling of privacy disclosures.\ \ \ \ Added\ \ July 13, 2021](/content/blog/glba-compliance-checklist-keeping-financial-data-safe-and-secure/index.html)
\ \ Blog\ \ The Basics of PCI Compliance: Merchant Levels and Requirements \ \ PCI compliance isn’t just good for customers; it’s also good for business. Merchants that fall short of PCI compliance standards not only put their customer data at risk but also may face hefty fines. The PCI Compliance Guide reports that fines and penalties can range from $5,000 to $100,000 per month for the merchant.\ \ \ \ Added\ \ June 29, 2021](/content/blog/the-basics-of-pci-compliance-merchant-levels-and-requirements/index.html)
\ \ Blog\ \ What Is PII Compliance? Requirements, Checklist & Best Practices \ \ Research from Gartner suggests that, by 2023, more than 60% of the world’s population will be covered by some form of personal data protection legislation. From GDPR to CalPRA, privacy regulations are on the rise.\ \ \ \ Added\ \ June 22, 2021](/content/blog/pii-compliance-checklist-best-practices/index.html)
\ \ Blog\ \ PHI Compliance: What It Is and How To Achieve It \ \ For organizations that work in or partner with the healthcare industry, HIPAA compliance is of paramount importance. Keeping a patient’s medical records and personal information safe isn’t just a matter of avoiding penalties. It’s also key to building trust with patients and, ultimately, providing great patient care.\ \ \ \ Added\ \ June 18, 2021](/content/blog/phi-compliance-what-it-is-and-how-to-achieve-it/index.html)
\ \ Blog\ \ Is Slack Secure? Vulnerabilities and Solutions \ \ Slack has become one of the most integral platforms for businesses over the last decade, with more than 12 million users currently active. Despite its popularity, however, there are some Slack security concerns that linger from the platform’s 2015 security breach.\ \ \ \ Added\ \ June 14, 2021](/content/blog/is-slack-secure-vulnerabilities-and-solutions/index.html)
\ \ Guides\ \ Cloud Security Architecture: 5 Best Practices \ \ Cloud programs like Slack and Google Drive allow businesses to work collaboratively and efficiently, often at a low cost. However, these cloud platforms open a business up to new levels of risk: sharing information via cloud programs can put customer data at risk.\ \ \ \ Added\ \ June 8, 2021](/content/blog/cloud-security-architecture-5-best-practices/index.html)
\ \ Blog\ \ How To Implement DevSecOps \ \ Security, previously an afterthought in the product development lifecycle, is now becoming an integral part of the process. New methodologies, like DevSecOps and shift left, offer clear advantages to companies seeking to protect valuable data while still moving quickly.\ \ \ \ Added\ \ June 8, 2021](/content/blog/what-is-devsecops-and-how-to-implement-it/index.html)
\ \ Blog\ \ An Introduction To Cloud Security Posture Management (CSPM) \ \ Many organizations are equipped to handle insider threat and external, common well-known challenges (like malware, for instance). These so-called “intentional” threats can be addressed through proactive security measures and best practices.\ \ \ \ Added\ \ May 29, 2021](/content/blog/an-introduction-to-cloud-security-posture-management-cspm/index.html)
\ \ Guides\ \ Shift-Left Testing: What It Is and How It Works \ \ If your development team isn’t yet using shift-left testing, you could be wasting time, money, and energy.\ \ \ \ Added\ \ May 28, 2021](/content/blog/shift-left-testing-what-it-is-and-how-it-works/index.html)
\ \ Guides\ \ How Micro Services Impact Your App Security \ \ Microservices have many uses, and security is one area where micro services can both help — and harm. Learn how micro services provide flexibility, scalability, and both security advantages and disadvantages to app developers and their end-users. \ \ \ \ Added\ \ April 29, 2021](/content/blog/how-micro-services-impact-your-app-security/index.html)
\ \ Guides\ \ 5 Basic Data Security Protocols Developers Must Know \ \ This guide will break down some of the basic data security protocols developers must know to protect the integrity of their app and, inevitably, the data of the end-user. \ \ \ \ Added\ \ April 27, 2021](/content/blog/5-basic-data-security-protocols-developers-must-know/index.html)
\ \ Guides\ \ How to Future Proof Your System Against a Zero Day Exploit \ \ Zero days are an IT security professional’s worst nightmare: but, there are steps you can take to minimize the risk of a zero day and recover as quickly as possible. \ \ \ \ Added\ \ April 26, 2021](/content/blog/how-to-future-proof-your-system-against-a-zero-day-exploit/index.html)
\ \ Guides\ \ How To Conduct A Website Security Check \ \ Follow this website security checklist to make sure you have all your bases covered when it comes to securing your business site. \ \ \ \ Added\ \ March 31, 2021](/content/blog/how-to-do-a-website-security-check/index.html)
\ \ Guides\ \ Identity and Access Management vs Password Managers: What's the Difference? \ \ Identity and access management best practices dictate that an organization provides one digital identity per individual. That identity can be maintained, monitored, and modified as needed while the user works on different projects and in different roles.\ \ \ \ Added\ \ March 22, 2021](/content/blog/identity-and-access-management-vs-password-managers-whats-the-difference/index.html)
\ \ Guides\ \ 9 BYOD Security Risks and Challenges \ \ BYOD — whether instituted as a formal policy or as an adaptation to the pandemic — opens a company’s systems and platforms up to hacking, data loss, and insider threat. IT teams need to be aware of these critical BYOD security concerns, as well as implement best practices to mitigate the risks associated with shadow IT.\ \ \ \ Added\ \ March 16, 2021](/content/blog/9-byod-security-risks-and-challenges/index.html)
\ \ Guides\ \ Quick Guide to the Difference Between a Public and a Private Cloud \ \ Cloud security. Cloud architecture. Cloud storage. As you start scaling your business, you know “the cloud” is an important element of your IT capabilities. But, it can be a little confusing to understand the ins and outs of “the cloud” — especially when it comes to using cloud-based tools for your company to work remotely. \ \ \ \ Added\ \ March 15, 2021](/content/blog/quick-guide-to-the-difference-between-a-public-and-a-private-cloud/index.html)
\ \ Guides\ \ What is Social Engineering? \ \ As phishing attacks grow, its important to understand social engineering and how it manifests.\ \ \ \ Added\ \ March 1, 2021](/content/blog/what-is-social-engineering/index.html)
\ \ Guides\ \ A Guide to VPN Security \ \ VPN is an important component of your company’s remote work security features. Learn how to get the most out of one.\ \ \ \ Added\ \ February 24, 2021](/content/blog/a-guide-to-vpn-security/index.html)
\ \ Guides\ \ 6 Identity and Access Management Best Practices \ \ Stolen credentials are among the biggest threats to data security across industries, accounting for around 80% of data breaches. In 2022 alone, nearly half of breaches during the first six months involved the theft of passwords and user accounts.\ \ \ \ Added\ \ February 23, 2021](/content/blog/6-identity-and-access-management-best-practices/index.html)
\ \ Guides\ \ Business Continuity: How to Plan for the Worst \ \ If the last year has taught us anything, “hope for the best and plan for the worst” should be the new mantra of business owners and IT professionals. No one could have predicted the global pandemic that wreaked havoc on industries and businesses around the world; yet, those companies with a business continuity plan were far better off than those without one.\ \ \ \ Added\ \ February 15, 2021](/content/blog/business-continuity-how-to-plan-for-the-worst/index.html)
\ \ Guides\ \ Cloud DLP and Regulatory Compliance: 3 Things You Must Know \ \ Compliance regimes may seem burdensome, but the goal of these policies is to prevent a devastating data breach that can bankrupt a business and cause myriad problems for consumers. It’s important to understand the differences between compliance and security, as well as how data loss prevention (DLP) allows your organization to accomplish both objectives efficiently and affordably.\ \ \ \ Added\ \ February 3, 2021](/content/blog/cloud-dlp-and-regulatory-compliance-3-things-you-must-know/index.html)
\ \ Guides\ \ How to Create a Cloud Security Framework \ \ Strong data loss prevention (DLP) requires a multifaceted process that requires layering tools, policies, and approaches. In addition to having a range of network, endpoint, and cloud DLP solutions in place, businesses need a strong foundation of policies, guiding principles, and rules underpinning the approach to data security.\ \ \ \ Added\ \ February 1, 2021](/content/blog/how-to-create-a-cloud-security-framework/index.html)
\ \ Guides\ \ The Economics of Data Loss Prevention \ \ Every business needs to enforce strong data policies — backed by data loss prevention tools –– and dedicate an investment in time, money, and effort.\ \ \ \ Added\ \ January 28, 2021](/content/blog/the-economics-of-data-loss-prevention/index.html)
\ \ Guides\ \ 6 Updates to Make to Your Cloud Security Policy \ \ In a recent survey, 84% of organizations reported finding it difficult to maintain security configurations across their cloud services. Organizations across industries are struggling to protect their valuable information, in part because they don’t understand the extent of security measures built-in to cloud platforms. As a result, Gartner predicts that 95% of all cloud security failures (through 2020) will be primarily the customer’s fault.\ \ \ \ Added\ \ January 27, 2021](/content/blog/6-updates-to-make-to-your-cloud-security-policy-in-2021/index.html)
\ \ Guides\ \ 3 Permanent Security Risks in a Post-Pandemic World \ \ We predict three security risks will become persistent threats to businesses of all sizes going forward.\ \ \ \ Added\ \ January 14, 2021](/content/blog/3-permanent-security-risks-in-a-post-pandemic-world/index.html)
\ \ Guides\ \ Network, Endpoint, and Cloud DLP: A Quick Guide \ \ In this guide we distinguish between network, endpoint, and cloud DLP so you can operationalize each effectively.\ \ \ \ Added\ \ January 13, 2021](/content/blog/network-endpoint-and-cloud-dlp-a-quick-guide-2/index.html)
\ \ Guides\ \ How is Data Stored in Confluence? \ \ When it comes to safeguarding confidential information, Atlassian relies on third-party apps, like Nightfall AI.\ \ \ \ Added\ \ January 12, 2021](/content/blog/how-is-data-stored-in-confluence/index.html)
\ \ Guides\ \ Why Third-Party Risk on Google Drive Should Be a #1 Concern \ \ Google Drive is one of the more vulnerable content service platforms to third-party risks. Learn how to identify this risk.\ \ \ \ Added\ \ December 15, 2020](/content/blog/why-third-party-risk-on-google-drive-should-be-a-1-concern-2/index.html)
\ \ Guides\ \ Threat Alert: Protect Your Files from New Google Drive Security Risks \ \ Learn 4 best practices for addressing security risks in Google Drive.\ \ \ \ Added\ \ December 7, 2020](/content/blog/threat-alert-protect-your-files-from-new-google-drive-security-risks/index.html)
\ \ Guides\ \ How Understanding User Privacy Can Improve Your Cybersecurity \ \ Learn how DLP tools can improve privacy and security while saving time\ \ \ \ Added\ \ November 30, 2020](/content/blog/how-understanding-user-privacy-can-improve-your-cybersecurity-4/index.html)
\ \ Guides\ \ Best Tools for Building Your DLP Tech Stack \ \ Learn the best tools to add to your DLP stack – and why you should consider a multi-faceted approach.\ \ \ \ Added\ \ November 25, 2020](/content/blog/best-tools-for-building-your-dlp-tech-stack/index.html)
\ \ Guides\ \ Which DLP Tasks to Automate – and Which to Do Manually \ \ Save time by learning which aspects of data protection can be automated\ \ \ \ Added\ \ November 18, 2020](/content/blog/which-dlp-tasks-to-automate-and-which-to-do-manually/index.html)
\ \ Guides\ \ 5 Best Tools for Secure Data Transfer \ \ Learn what to look for in a solid data transfer tool.\ \ \ \ Added\ \ November 6, 2020](/content/blog/5-best-tools-for-secure-data-transfer/index.html)
\ \ Guides\ \ The Fintech Sector is Under Cyber Attack – Here's How Companies Are Protecting their Data \ \ Here’s how hackers are targeting fintech companies –and what your fintech company can do to better protect itself.\ \ \ \ Added\ \ October 30, 2020](/content/blog/the-fintech-sector-is-under-cyber-attack-heres-how-companies-are-protecting-their-data/index.html)
\ \ Guides\ \ 5 Tips for Training Non-IT Employees on Cybersecurity \ \ \ \ Added\ \ October 23, 2020](/content/blog/5-tips-for-training-non-it-employees-on-cybersecurity/index.html)
\ \ Guides\ \ 5 Most Common Types of Cybersecurity Threats \ \ Building a strong defense starts with understanding what it is you’re up against. Beware of these four common types of cyber threats – and learn what you can do to prevent them. \ \ \ \ Added\ \ October 16, 2020](/content/blog/5-most-common-types-of-cybersecurity-threats/index.html)
\ \ Guides\ \ What Is A CASB And 4 Ways It Differs From Cloud DLP \ \ A CASB may not be the right solution for every business; CASBs have a few shortcomings that are important to recognize. \ \ \ \ Added\ \ October 9, 2020](/content/blog/what-is-a-casb-and-4-ways-it-differs-from-cloud-dlp/index.html)
\ \ Guides\ \ Industry Watch: How the Pandemic is Changing Cybersecurity \ \ Here’s how the pandemic has changed cybersecurity, and what your business can do differently to protect your data as the situation evolves.\ \ \ \ Added\ \ October 2, 2020](/content/blog/industry-watch-how-the-pandemic-is-changing-cybersecurity/index.html)
\ \ Guides\ \ A DLP Security Checklist for IT Professionals \ \ Nightfall works with many customers, including healthcare organizations, to improve DLP security and implement HIPAA-compliant measures to protect patient data. Here’s a checklist of best practices our experts use when approaching DL\ \ \ \ Added\ \ September 25, 2020](/content/blog/a-dlp-security-checklist-for-it-professionals/index.html)
\ \ Guides\ \ Data security vs. network security: What should your business prioritize? \ \ Here’s how to understand how working from home impacts your data security – as well as some steps to take to make sure you are prioritizing the right things.\ \ \ \ Added\ \ September 18, 2020](/content/blog/data-security-vs-network-security-what-should-your-business-prioritize/index.html)
\ \ Guides\ \ 4 Things to Know about Sharing Data Over Slack \ \ Slack security is achievable: take these steps to protect your company’s PII and data while using Slack. \ \ \ \ Added\ \ September 9, 2020](/content/blog/4-things-newly-remote-companies-need-to-know-about-sharing-data-over-slack/index.html)
Products
solutions
Products
Platform Overview Data Exfiltration Prevention Data Detection & Response Data Discovery & Classification
Solutions
Use cases
Stop data exfiltration anywhere Eliminate sensitive data exposure Revoke inappropriate data sharing Prevent data leakage to Shadow AI
industries
Technology Healthcare Financial Services Legal Manufacturing
integrations
Endpoints & Browsers AI Apps Slack Google Drive Gmail Jira Confluence More +
integrations
Salesforce Microsoft Teams Microsoft OneDrive Microsoft Exchange Online Microsoft SharePoint Online Notion Zendesk
Products
Resources
Company
Get Started
Products
Data Exfiltration Prevention Data Detection & Response Data Discovery & Classification Nyx - Autonomous DLP Analyst
Resources
Case studies Blog AI Security 101 Reports and Research Webinars Compare Nightfall Guides Pricing ROI Calculator
Company
About us Partners Careers Trust center Press
Company
© 2026 Nightfall AI. All rights reserved.