Home/Data Security & Privacy

Every other control protects a place. This one protects the data after it has left all of them.

The endpoint, the network, the identity and the backup each guard a boundary. Data does not stay inside one: it is copied to a laptop, synced to a personal drive, attached to an email, pasted into an AI assistant and restored into a test environment — and every one of those is outside the control that was bought to protect it.

Almost no organisation can answer where its sensitive data is. Every product on this page begins by telling them — discovery is the first deliverable of all three routes, and it is the step buyers consistently underestimate. Three routes below, organised by where the control sits: at the exit, at rest, or on the file itself.

3 guides

Three routes, by where the control sits. Open the one that matches your situation.

DLP & Insider Risk

Data is leaving and you need to see it, stop it, and prove who did it.

18 productsOpen the guide →
Often confused with DSPM & Data Discovery. The difference: one watches data move; the other finds data sitting still. Most buyers who say DLP have a discovery problem. DSPM & Data Discovery

DSPM & Data Discovery

You do not know where your sensitive data is, or who can reach it.

15 productsOpen the guide →
Often confused with Encryption & Rights Management. The difference: finding and classifying the file, versus protecting the file once it is found. Encryption & Rights Management

Encryption & Rights Management

The file will leave your control. It needs to stay protected anyway.

6 productsOpen the guide →
Often confused with DLP & Insider Risk. The difference: DLP decides whether a file may leave; rights management decides what happens to it after it has. DLP & Insider Risk
Second entry axis

Something just happened?

Events and audits send people here more often than job descriptions do. If one of these is your week, it already names your route.

A departing employee copied files to a personal drive

DLP & Insider Risk

Someone pasted customer data into a public AI assistant

DLP & Insider Risk

Nobody can answer where personal data is held

DSPM & Data Discovery

DPDP readiness work started and the data map does not exist

DSPM & Data Discovery

A public bucket was found holding customer records

DSPM & Data Discovery

A confidential file was forwarded outside and cannot be recalled

Encryption & Rights Management

The overlaps

Why people pick the wrong door

Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:

DLPvsDSPM

Do you need to watch data move, or find out where it already is?

Buy DLP when you needed DSPM and you write policies against a definition of “sensitive” that nobody in the organisation has agreed — the console fills with false positives on invoices and the rules quietly revert to monitor. Buy DSPM when you needed DLP and you have an excellent map of where the data sits while it continues to leave by email every afternoon.

DSPMvsCSPM

Are you securing the cloud account, or what is inside it?

CSPM tells you the bucket is public. DSPM tells you the public bucket holds customer PAN numbers. Buy CSPM expecting data classification and every finding is a configuration, not a consequence — the report says “public S3 bucket” with no way to know whether it matters. That route lives on the Security category and is cross-linked, not repeated here.

Encryption & RightsvsDLP

Does the file need to be stopped, or protected after it leaves?

Buy DLP for a problem that ends with a file legitimately going to an external auditor, and the only options are block it or let it go unprotected. Buy rights management expecting egress control and files still leave freely — protected, but leaving. One is a gate; the other is a wrapper that travels.

DLPvsInsider risk

Is the question what left, or who is behaving differently?

Rule-based DLP catches the policy violation and misses the resignation-shaped pattern of behaviour that preceded it by three weeks. Behavioural insider-risk tooling flags the pattern and cannot tell you which file was taken. Estates that buy one and describe the other in the requirement get a working product answering an unasked question.

Compare any two terms

vs
DLPDLP & Insider Risk

Inspects content in motion or at an exit point and enforces a policy on it.

The DLP & Insider Risk boundary section →
DSPMDSPM & Data Discovery

Finds data at rest across stores, classifies it and maps who can reach it.

The DSPM & Data Discovery boundary section →

The difference

DSPM finds data sitting still and maps who can reach it. DLP watches data move and decides whether it may. Most buyers who arrive saying “we need DLP” actually cannot answer where their sensitive data is — which is a discovery problem, and writing DLP policy before answering it produces rules against a definition nobody has agreed.

The vocabulary — one line each

Sixteen terms, one line each. The depth lives in each route’s guide.

These are adjacent controls at different points in the data’s life, not tiers. A product that classifies perfectly may block nothing. A product that blocks at the endpoint may never see the cloud copy. Each route’s guide resolves only the four terms its buyer actually confuses.

  • DLP (Data Loss Prevention)inspects content in motion or at an exit point and enforces a policy on it
  • Insider riskbehavioural: scores what a person is doing over time, not what one file contains
  • UEBA (User and Entity Behaviour Analytics)the analytics engine underneath — baselines normal, flags deviation, names no policy
  • Endpoint DLP (Data Loss Prevention)an agent on the device: USB, print, screenshot, clipboard, local file operations
  • Network DLP (Data Loss Prevention)inspects traffic in flight — blind to anything encrypted it cannot terminate
  • Cloud DLP (Data Loss Prevention)reads SaaS applications through APIs; sees sanctioned tenants, rarely unsanctioned ones
  • DSPM (Data Security Posture Management)finds data at rest across stores, classifies it and maps who can reach it
  • Data discoverythe scan itself — what exists and where, before anything is judged about it
  • Classificationdeciding what a file is: regex and keyword, machine learning, or fingerprinting
  • Cataloguingan inventory for governance and analytics use, not a security control
  • Access-path analysiswho can actually reach this data through every group, role and share — effective, not nominal
  • DDR (Data Detection and Response)data detection and response: alerting on access to data at rest, not on a configuration
  • Encryption at restthe disk or the store is encrypted; anyone with a valid session reads plaintext
  • Encryption in transitTLS between two points; protects the wire, not the file at either end
  • EDRM / IRM (Enterprise Digital Rights Management / Information Rights Management)the protection travels inside the file — policy enforced wherever the file goes
  • Revocationwithdrawing access to a file already delivered — the whole point of rights management
Ground truths

What holds whichever route you take

Most of what signs in is not a person

Service accounts, API consumers, pipeline credentials, workload identities and now AI agents authenticate constantly, unattended, and outnumber human identities in most estates by a wide margin. No manager owns them, no HR event ends them, and no certification campaign reviews them. Every route on this page was designed for people first — ask each vendor what it does for the other population, and expect a thinner answer than the brochure implies.

You already own an identity provider

Microsoft Entra ID P1 (roughly $6–7 per user per month, already inside Microsoft 365 E3) gives SSO and full conditional access; P2 (about $9–10, inside E5) adds Privileged Identity Management. Google’s Cloud Identity Premium is around $6. The useful question is never “which identity provider” but “where does the one on my invoice stop” — usually at legacy protocols, non-Microsoft depth, or governance evidence.

The factor matters more than the acronym

“Supports MFA” covers both a push notification a tired person taps at midnight under a fatigue attack and a FIDO2 security key an attacker cannot phish at all. Push fatigue is a live technique, not a theoretical one. Every guide here records documented FIDO2 and passkey support per product — and marks it unknown where vendor documentation does not establish it, rather than assuming.

India names the control, not the product

The RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023, in force 1 April 2024) requires need-based access and multi-factor authentication for privileged users; SEBI’s CSCRF (August 2024) sets least-privilege and privileged-access requirements; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require privileged access management and periodic access reviews. Each names a control and an evidence expectation — not a product category. Read the circular before the brochure.

The licence is the small number. Onboarding, implementation and the population nobody governs are the purchase.
TechBag
Where it's heading

The seams are moving

SASE vendors are absorbing DLP, because inline inspection is already where the traffic flows — Zscaler and Netskope both sell data protection as a platform module rather than a product. Backup vendors are adding DSPM from the other side (Rubrik), on the logic that they already hold a copy of everything worth classifying. DSPM is absorbing standalone classification. And Microsoft Purview is setting the floor: what E5 includes is what an SMB compares every quote against. Buying two of these today often means buying one thing twice — or buying a module you already own.

What you used to buyWhat you buy now
DLP & insider risk
at the exit
DSPM & discovery
at rest
Encryption & rights
on the file
One direction
Microsoft absorbing the floor
Purview inside E5 sets the baseline every quote is compared against
Microsoft
One direction
The platforms that already hold the data
SASE inspects where traffic flows; backup and cloud platforms classify the copy they keep
ZscalerNetskopeRubrikWiz

Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.

Check what you already own

Almost every buyer in this category already holds part of what they are about to purchase — usually the sign-in half, occasionally the governance half, almost never the machine half.

  • Microsoft Entra ID P1 SSO, full conditional access and hybrid identity at roughly $6–7 per user per month — and already inside Microsoft 365 E3. Stops at governance evidence and non-Microsoft depth.
  • Microsoft Entra ID P2 adds Privileged Identity Management (eligible rather than permanent roles, with approval and expiry) and risk-based sign-in, about $9–10 per user per month, inside E5. It governs Microsoft's own roles; it vaults no server or network credential.
  • Entra ID Governance add-on access reviews, entitlement management and lifecycle workflows for roughly $4–7 per user per month on top of P1 or P2. Real governance for the Microsoft estate; thin for third-party applications.
  • Google Cloud Identity Premium around $6 per user per month for SSO, device management and security controls in a Google-centric estate. Thin for legacy protocols and non-Google SaaS.
  • On-premises Active Directory Kerberos, LDAP and group policy for the domain — and nothing for SaaS. It is what most estates federate from, not to.
  • MFA inside a product you already run your VPN, firewall, UEM or endpoint vendor may already include multi-factor authentication. Check which factors — if it is push and one-time codes only, the phishing-resistant gap is still open.

If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.

Budget shape

What it costs, roughly

Three meters live in this category, and a fourth number under all of them: the project. Which meter you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.

DLP & Insider Risk
Per user · per endpoint
Safetica publishes about $72–144 per user / yr (about ₹5,976–₹11,952); Forcepoint from about $52 per user / yr (about ₹4,316). Seclore, Data Resolve and Seqrite quote in INR directly. The platform modules (Zscaler, Netskope, CrowdStrike, Coro) are priced inside a subscription you may already hold.
DSPM & Data Discovery
Per data store · per scanned volume
Quote-led across Varonis, Cyera and Securiti, metered on stores, accounts or scanned volume rather than headcount — which is why an estate with few users and large object stores can cost more than a large workforce. Wiz and Rubrik price theirs inside the platform.
Encryption & Rights Management
Per protected user · per file volume
Seclore quotes per protected user in INR; Trellix and Seqrite price encryption per endpoint, Seqrite in INR. The external-recipient experience — whether they need your software — moves adoption more than the licence line does.
All three routes
The line nobody quotes
Classification and policy tuning. In year one it commonly exceeds the licence: someone has to decide what “sensitive” means in your organisation, and no vendor can do that for you.
Appendix — every vendor in the category, tagged by route
  • VaronisThe access-path specialist: DSPM, DDR, DLP, Data Access Governance, MDDR and Athena AI — the deepest answer to “who can actually reach this” across file shares, Microsoft 365 and cloud storesDLPDSPM
  • ForcepointDLP (from about $52 per user / yr), Risk-Adaptive Protection, DSPM, DDR, Data Classification and CASB — the broadest single-vendor span of the three routes on this pageDLPDSPMEncryption
  • TrellixDLP Endpoint, DLP Network, DLP Discover, Data Encryption, Database Security and AI Data Security — these TechBag pages are the data-security line, not the endpoint oneDLPEncryption
  • SecloreIndia-built (Mumbai): ARMOR EDRM — protection that travels inside the file with post-distribution revocation — plus Data Classification, DSPM and AI-DLPEncryptionDSPMDLP
  • CyeraAI-native DSPM, Data Access Governance, Omni DLP and AI Security — agentless cloud-first discovery and classificationDSPMDLP
  • SecuritiData Command Center: discovery, DSPM, governance, privacy automation and Gencore AI — the privacy-operations depth here; acquired by Veeam (about $1.725B, closed December 2025) and continuing under its own brandDSPM
  • SafeticaPublished per-user list (about $72–144 per user / yr): the Platform and an on-premises edition — DLP and insider risk sized for the mid-marketDLP
  • Data ResolveIndia-built: inDefend DLP, user behaviour analytics, employee productivity and MobSec — INR pricing and on-premises as a first-class optionDLP
  • SeqriteIndia-built (Quick Heal): DLP, Data Privacy for DPDP work and full-disk Encryption — quoted in INR, on-premises capableDLPDSPMEncryption
  • ProofpointDLP & Insider Risk — people-centric, strongest where the exit is email and the signal is behaviouralDLP
  • MimecastIncydr — insider risk built on file-movement telemetry rather than content rulesDLP
  • ZscalerData Protection inline in the Zero Trust Exchange — a module of the SASE platform, not a standalone purchaseDLP
  • NetskopeData Protection and SkopeAI — CASB and DLP in the platform's DNA; eight Indian data centres with a Mumbai management planeDLP
  • CrowdStrikeFalcon Data Protection — data controls on the endpoint agent you already run, not a full DLP suiteDLP
  • CoroCloud & Data Governance inside the Coro modular platform — SMB-shaped, bought as a moduleDLP
  • WizDSPM on the Wiz security graph — cloud-native, and strongest when the estate is already WizDSPM
  • RubrikDSPM over data the backup platform already holds — discovery without a second scan of productionDSPM
  • MicrosoftPurview is the dominant “already own” answer, not a carded product here: E3 carries manual and basic labelling, E5 adds automatic classification, endpoint DLP and insider risk management; standalone SKUs sit betweenDLPDSPM

Five vendors span all three routes; every product on the guides is mapped by SKU, not by vendor. SailPoint, Saviynt, Ping Identity, Delinea and JumpCloud are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked. Microsoft appears in the index and in every “already own” section, but its identity SKUs are not carded on the guides.

Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.

Talk to an advisor

Vendor-neutral · no gated content

Last reviewed