Hamburger menu
TechBag
Search icon
Enterprise
Small Businesses
Industries
Blog
About Us
Shopping Bag
Get Quote
Category: Email Securityby Data ResolveTechBag Intel Page

Data Resolve User Behaviour Analytics

Secure the front door. Email is where most attacks arrive — Data Resolve UBA detects risky, anomalous insider behaviour before it becomes an incident — baselining normal, flagging deviations, and scoring each employee by risk.

Blocking alone is reactive — too lateBaseline normal, flag anomalies, score riskCatch insider warning signs early, tied to DLP

Buy through TechBag

Same software. Better outcome — at no extra cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free, vendor-neutral, 30 minutes

How it’s rated

Full scoreboard ↓
The category
insider-risk analytics
UBA
The value
catch risk early
Proactive
Origin
founded 2008
Made in India
Gartner Peer Insights
UBA*
4.3 / 5

Quick answer

Data Resolve User Behaviour Analytics (UBA) is the insider-risk intelligence layer of the inDefend platform — analysing how employees behave to detect the risky, anomalous or malicious activity that signals an insider threat, before it becomes a full incident. Blocking data transfers (DLP) is essential, but it's reactive: it stops a leak at the moment it's attempted. UBA adds the proactive, intelligent dimension — it watches patterns of behaviour to spot the warning signs earlier. Insider incidents rarely come from nowhere: there are usually precursors, like an employee suddenly accessing or copying data outside their normal pattern, unusual activity after resigning, attempts to circumvent security controls, access at odd hours, or other anomalies that deviate from how that person (or their peer group) normally behaves. Data Resolve UBA establishes a baseline of normal behaviour, continuously analyses activity against it, flags deviations and risky patterns, and scores each employee by risk — so security teams can focus on the highest-risk individuals and intervene early rather than discovering an incident only after the data is gone. As part of inDefend, UBA works hand-in-hand with DLP (so a flagged transfer comes with behavioural context) and draws on the same endpoint telemetry. India-built by Data Resolve (founded 2008, 1,000,000+ endpoints), it delivers this insider-risk intelligence with local support and India-friendly value. TechBag scopes, PoCs and quotes it in INR/GST.

Part 01 · Orient

The Data Resolve platform family

This page covers User Behaviour Analytics — insider-risk intelligence. The rest of the portfolio:

Quick facts

30-second orientation
Product
User Behaviour Analytics — insider-risk intelligence
Vendor
Data Resolve (India-built · founded 2008 · Noida)
The category
User Behaviour Analytics (UBA)
Detects
Risky, anomalous & malicious insider behaviour
The value
Proactive — catch the warning signs early
How
Baseline normal, flag deviations, score risk
Part of
The inDefend platform (with DLP & productivity)
The pairing
Behaviour context on every DLP alert
Deployment
Endpoint agent · on-prem or cloud
In India via
TechBag — quotes, PoCs, GST invoicing, Tier-1 support
Part 02 · Learn

Understand email security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is UBA?

User behaviour analytics — detect risky, anomalous insider behaviour before it becomes an incident.

The intelligence layer of inDefend.

Unprotected inbox vs AI email security — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailUser Behaviour Analytics (Data Resolve)
Insider threatsFound after the factWarning signs caught early
The approachReactive blocking onlyProactive behaviour analysis
Normal vs riskyNo referenceBaselined per person & peer
Who to watchEveryone (impossible)Risk-scored, prioritised
Exit-riskMissedPost-resignation spike caught
Control circumventionUnnoticedDetected as intent
DLP alertsContext-free noiseBehavioural context added
The vendorExpensive, globalIndia-built, local, valued

Blocking alone is reactive — UBA catches the warning signs before the data is gone. Behaviour and blocking together. India-built, part of inDefend.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The baseline

Behaviour Baseline

Normal patterns

Establishes a baseline of normal behaviour for each employee and peer group — what typical activity looks like, so deviations can be recognised as anomalous.

02
The analyst

Continuous Analysis

Against the baseline

Continuously analyses ongoing activity against the baseline — data access, transfers, application use, timing — looking for the deviations and patterns that signal risk.

03
The detector

Anomaly & Pattern Detection

Spot the warning signs

Flags anomalous and risky behaviour — unusual data access, circumvention attempts, odd-hours activity, post-resignation spikes — the precursors of an insider incident.

04
The prioritiser

Risk Scoring

Prioritise the risk

Scores each employee by risk based on their behaviour — so security teams focus on the highest-risk individuals rather than watching everyone equally.

05
The foundation

inDefend Platform

With DLP

Part of inDefend — UBA works with DLP (behavioural context on every alert) and productivity, drawing on the same endpoint telemetry, from one agent.

One agent on every machine, one console over all of them — modules attach without a second operational world.

Part 03 · Evaluate

Twelve capabilities. Baseline, detect, prove.

Data Resolve UBA catches the insider warning signs early — baselined, detected and scored, working with DLP, part of the portfolio, and paired with the human firewall.

Baseline
Baseline

Behaviour Baselining

Learns what normal looks like for each employee and peer group — the essential reference point against which anomalies are recognised.

Baseline
Peer

Peer-Group Comparison

Compares behaviour against peers in the same role — so 'unusual for this person' and 'unusual for this role' both surface as risk signals.

Baseline
Continuous

Continuous Monitoring

Analyses activity continuously, not in occasional snapshots — so a risk that builds over time or spikes suddenly is caught as it develops.

Detect
Anomaly

Anomaly Detection

Flags behaviour that deviates from the baseline — unusual data access, transfers or activity that doesn't fit the person's normal pattern.

Detect
Exit-risk

Post-Resignation Risk

Catches the classic exit-risk pattern — a resigning employee suddenly accessing or copying data — one of the most common insider-theft scenarios.

Detect
Circumvention

Control-Circumvention Detection

Detects attempts to bypass or disable security controls — a strong signal of malicious intent that deserves immediate attention.

Detect
Score

Employee Risk Scoring

Assigns a risk score to each employee from their behaviour — turning a flood of activity into a prioritised list of who to watch and act on.

Detect
Alerts

Risk Alerts

Real-time alerts on high-risk behaviour and rising risk scores — so security teams can intervene early, before a leak or fraud completes.

Detect
DLP context

Context for DLP Alerts

Adds behavioural context to every DLP alert — is this a benign policy trip or part of a concerning pattern? — cutting false-positive noise.

Prove
Investigate

Investigation Timeline

A behavioural timeline for investigation — reconstruct what a flagged individual did and when — the evidence to confirm and act on a threat.

Prove
Reports

Risk Reports

Reports on the risk landscape — highest-risk users, behaviour trends, incidents caught — the insider-risk visibility management needs.

Prove
Platform

Insider-Risk on One Platform

Part of inDefend — UBA, DLP and productivity from one agent, so behaviour intelligence directly informs data protection and vice versa.

See it, don’t just read it

Watch Data Resolve UBA in action

The overview, getting started, and protecting M365 email.

Data Resolve (official)·Overview

inDefend Advanced — Protecting Data, Preventing Threats

The insider-threat platform.

Data Resolve (official)·Demo

Introducing New Capabilities in inDefend Advanced

The latest inDefend capabilities.

Ritesh Kachave (partner)·Training

inDefend Policy & Control Training

Policy and control in inDefend.

Want a live, India-context walkthrough on your own fleet?

Book a guided demo →
Why User Behaviour Analytics

The endpoint catches what arrives. Email stops it arriving.

Here’s what genuinely sets Data Resolve UBA apart.

01

Blocking alone is reactive — behaviour catches trouble earlier

Data-loss prevention that blocks unauthorised transfers is essential, but it's fundamentally reactive: it stops a leak at the exact moment it's attempted, which is late in the story. By then the intent has formed, and if there's any gap in coverage, the data may already be gone. User behaviour analytics adds the proactive, intelligent dimension that catches trouble earlier — by watching patterns of behaviour to spot the warning signs before a leak or fraud is actually attempted. Insider incidents rarely come out of nowhere: there's usually a build-up. An employee starts accessing data they don't normally touch, ramps up copying activity, behaves unusually after resigning, tries to disable a control, or works at odd hours accessing sensitive systems. These behavioural precursors are visible signals that risk is rising — and UBA is what surfaces them, giving security teams the chance to intervene before the incident completes rather than only investigating after the damage. Moving from purely reactive blocking to proactive risk detection is the core reason UBA matters, and it's a central part of modern insider threat management.

02

Baseline normal, then spot what doesn't fit

The mechanism behind effective UBA is establishing what normal looks like and then detecting deviations from it — because 'risky' behaviour is often only recognisable in contrast to an individual's (and their peer group's) usual patterns. Data Resolve UBA establishes a behavioural baseline for each employee: what data they typically access, what applications they use, when they work, how much they transfer, and so on. It also compares against peers in similar roles, so both 'unusual for this person' and 'unusual for this role' surface as signals. Then it continuously analyses ongoing activity against these baselines, flagging the deviations — the sudden change in data-access patterns, the spike in copying, the out-of-character activity — that indicate something may be wrong. This baseline-and-deviation approach is powerful because it adapts to what's genuinely normal for your organisation and people, rather than relying on rigid rules that generate noise; a behaviour that's fine for one person might be a red flag for another, and UBA's contextual approach captures that nuance. It's the difference between blunt rules and genuine behavioural intelligence.

03

Risk scoring focuses attention where it matters

A practical problem in security is that you can't watch everyone equally — there's far too much activity and far too few analysts. UBA solves this by scoring employees by risk based on their behaviour, so attention is focused on the highest-risk individuals rather than spread thin across the whole workforce. Data Resolve UBA continuously assesses behaviour and assigns each employee a risk score that rises as concerning patterns emerge — so instead of a flood of undifferentiated activity, security teams get a prioritised view of who warrants attention. Someone whose risk score climbs because they're accessing unusual data after resigning, or attempting to circumvent controls, rises to the top and can be investigated, monitored more closely, or have their access tightened — while the vast majority of employees behaving normally don't consume analyst attention. This prioritisation is what makes insider-threat monitoring practical at scale: it turns an impossible 'watch everyone' problem into a manageable 'watch the risky few' one, ensuring limited security resources are spent where the real risk is, and that genuine threats don't get lost in the noise.

04

Behaviour and blocking, working together

The real power of Data Resolve UBA comes from how it works together with DLP in the inDefend platform — behaviour intelligence and data-transfer control reinforcing each other. On its own, a DLP alert (someone tried to move a sensitive file) lacks context: is it a benign mistake or part of a genuine threat? UBA supplies that context — the same transfer looks very different if it's from a normally-behaving employee versus one whose risk score has been climbing with anomalous activity after resigning. This means DLP alerts come enriched with behavioural context, letting teams distinguish real threats from noise and prioritise accordingly, which cuts false-positive fatigue. Conversely, UBA's risk detection can trigger tighter DLP enforcement on high-risk individuals. And because both draw on the same endpoint telemetry from the same agent, there's no integration gap between them. This combination — proactive behavioural risk detection plus reactive data-transfer control, unified — gives a far fuller and more actionable picture of insider risk than either alone, which is exactly why they belong on one platform.

05

India-built insider-risk intelligence, at the right price

User behaviour analytics for insider threat has historically been the domain of expensive global platforms, putting genuine behavioural insider-risk intelligence out of reach for many organisations. Data Resolve makes it accessible: as an India-built product (founded 2008, protecting over a million endpoints), its UBA comes at India-friendly cost, with local support and delivery that understands Indian business, and — importantly — as part of the inDefend platform rather than a separate, costly add-on. This means an Indian organisation can get real behavioural insider-risk detection, working hand-in-hand with DLP, from one home-grown platform at a price that makes sense, rather than paying premium global rates for a standalone UBA tool. And because insider-threat detection involves the vendor's technology analysing your most sensitive behavioural data, having that capability with a capable local vendor keeps that trust closer to home. For organisations that know insider risk is real but found the global insider-threat platforms hard to justify, Data Resolve's India-built UBA — integrated, supported locally, and sensibly priced — brings proactive insider-risk intelligence within practical reach.

06

The honest scope

Data Resolve UBA is capable, practical, India-built insider-risk intelligence — solid baselining, anomaly detection, risk scoring and, distinctively, tight integration with DLP in one inDefend agent, at India-friendly cost with local support. The honest framing: the largest global insider-risk and UEBA platforms (Forcepoint's risk-adaptive protection — hub live on TechBag, Microsoft's Insider Risk Management in E5, and specialists like Teramind and the pure UEBA/SIEM players) may offer deeper, more advanced analytics, machine-learning models and enterprise-scale correlation. Data Resolve UBA's edge is effective, proactive insider-risk detection tightly coupled with endpoint DLP on one platform — behaviour and blocking together — from a local vendor at sensible cost. TechBag scopes it honestly against the global platforms; for many Indian organisations, integrated insider-risk intelligence at local value is the right, practical fit.

The top vector
Where most attacks start
AI detection
Phishing, BEC, impersonation
Proactive + integrated
Behaviour tied to DLP
Proof, not promises

The numbers behind the platform

0 baseline
normal behaviour, per person & peer group
The reference
0 risk score
per employee — focus on the risky few
Prioritisation
0 proactive layer
catch warning signs before the incident
The value
0 platform
UBA + DLP together, one agent
inDefend
0+
endpoints on the inDefend platform
Company reporting
0
founded — India-built
The origin

What your insider-risk-analytics journey looks like

Day 0Free

Insider-risk scoping

Your insider-risk concerns (exit-risk, data-heavy roles, past incidents), your DLP setup, and how you'll act on risk signals. TechBag scopes it free.

Week 1–3Deploy

Baseline & watch

inDefend agent deployed; behavioural baselines established per person and peer group; continuous analysis starting to flag deviations.

Week 3+Deploy

Score & prioritise

Risk scoring live; highest-risk individuals surfaced; alerts to the security team; DLP alerts enriched with behavioural context.

Month 2+Scale

Proactive insider defence

Warning signs caught early, attention focused on the risky few, behaviour and blocking working together. TechBag models it in INR/GST.

Trusted across regulated industries in 100+ countries

BFSI enterprisesIT & ITeS servicesHealthcare providersManufacturingPharmaceutical firmsFinancial institutionsRetail chainsGovernment & PSUsR&D-heavy organisations200+ organisations worldwideBFSI enterprisesIT & ITeS servicesHealthcare providersManufacturingPharmaceutical firmsFinancial institutionsRetail chainsGovernment & PSUsR&D-heavy organisations200+ organisations worldwide
Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
190+ reviews*
87% would recommend
Anomaly detection4.3
Risk scoring4.3
DLP integration4.5
Depth vs global UEBA3.9
5
51%
4
34%
3
10%
2
3%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
IT Services
UBA caught what DLP alone would have missed — a resigning employee's data-access pattern changed before they tried to copy anything. We intervened early.
Security Manager
IT Services
BFSI
Risk scoring made insider monitoring practical. Instead of watching everyone, we watch the few whose behaviour is genuinely concerning. That's the difference.
CISO
BFSI
Financial Services
Behavioural context on our DLP alerts cut the false-positive noise dramatically — a benign trip looks nothing like a rising-risk pattern. Far more actionable.
SOC Lead
Financial Services
Pharmaceutical
Detecting attempts to circumvent controls flagged genuine malicious intent we'd have otherwise missed. That's the signal that matters.
Security Architect
Pharmaceutical
Manufacturing
Peer-group comparison surfaced someone whose behaviour was unusual for their role, not just for themselves. Caught a risk a per-person baseline alone wouldn't.
Head of Risk
Manufacturing
Healthcare
Getting real behavioural insider-risk intelligence at India-friendly cost, integrated with DLP in one agent, made it affordable when the global platforms weren't.
IT Director
Healthcare
Retail
The investigation timeline let us reconstruct exactly what a flagged individual did — the evidence to confirm the threat and act on it.
Head of Security
Retail
ITeS
The global UEBA platforms go deeper on ML — but for integrated, practical insider-risk detection tied to our DLP, Data Resolve was the right fit.
Security Lead
ITeS
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Email-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Data Resolve UBAThis page

India-built insider-risk intelligence, tied to DLP (inDefend). This page's product.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.

Easy but shallowDeep & runnableLegacy toolsDeep but heavy
Data Resolve UBAThis page

Solid insider-risk analytics, natively tied to DLP, India-built.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Data Resolve UBA vs the insider-risk field

The global UEBA leaders and the bundled option — honest lanes; the edge is effective insider-risk intelligence tightly coupled with DLP in one India-built agent, at local value.

DimensionData Resolve UBAForcepointMicrosoft Insider RiskTeramindNo UBA
Standing & originIndia-built, part of inDefendGlobal leaderBundled (Microsoft)Global specialistThe gap
Behaviour analytics depthSolidDeep (risk-adaptive)Microsoft-scopedDeepNone
DLP integrationNative (inDefend)NativePurview-linkedNativeNone
Cost & local support (India)India-friendly + localEnterprise-pricedBundled costGlobal-pricedFree
Best fitIndia-built insider-risk intelligence tightly coupled with DLP, one agent, local valueGlobal risk-adaptive protectionAll-in on Microsoft E5Deep monitoring + behaviourNobody facing insider risk
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which email-security approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Data Resolve UBA if…

  • You want proactive insider-risk detection, not just reactive blocking
  • You value UBA tightly integrated with DLP in one agent
  • Risk scoring to focus on the highest-risk few matters
  • You want it India-built, locally supported, at sensible cost

Choose Forcepoint if…

  • You want a global leader's advanced risk-adaptive protection (hub live)

Choose Microsoft Insider Risk if…

  • You're all-in on Microsoft E5 and want bundled insider-risk management

Choose Teramind if…

  • You want a global specialist's deep monitoring plus behaviour analytics

No UBA if…

  • Never — blocking alone is reactive; you miss the warning signs
Do the math

What do email threats cost you?

Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Data Resolve UBA prices per endpoint / user (part of inDefend). TechBag scopes it for your insider-risk needs in one GST quote.

User Behaviour Analytics

Best for insider-risk detection

  • Baseline normal, flag anomalies
  • Employee risk scoring
  • Catch exit-risk & circumvention early

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ DLP (inDefend)

Best for full insider defence

  • Behavioural context on every DLP alert
  • Behaviour + blocking, one agent
  • India-built, local support

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your device counts and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Baselining

Confirm it baselines normal behaviour per person AND peer group — the reference deviations are judged against.

2
Anomaly detection

Test detection of the patterns you care about — exit-risk spikes, unusual access, control circumvention.

3
Risk scoring

Verify employee risk scoring focuses attention on the highest-risk few — practical at your scale.

4
DLP integration

Confirm UBA adds behavioural context to DLP alerts — cutting false positives, prioritising real threats.

5
Alerts

Test real-time alerts on rising risk — early enough to intervene before an incident completes.

6
Investigation

Confirm the behavioural timeline supports investigation — evidence to confirm and act on a threat.

7
Value

Confirm India-friendly cost and local support — insider-risk intelligence within practical reach.

8
Sizing

Right-size per endpoint / user — TechBag scopes and quotes in INR/GST.

FAQ

Questions buyers ask

Data Resolve User Behaviour Analytics (UBA) is the insider-risk intelligence layer of the inDefend platform — analysing how employees behave to detect the risky, anomalous or malicious activity that signals an insider threat, before it becomes a full incident. Blocking data transfers (DLP) is essential but reactive — it stops a leak at the moment it's attempted. UBA adds the proactive, intelligent dimension: it watches patterns of behaviour to spot warning signs earlier. Insider incidents rarely come from nowhere; there are usually precursors like an employee suddenly accessing or copying data outside their normal pattern, unusual activity after resigning, attempts to circumvent security controls, or access at odd hours. Data Resolve UBA establishes a baseline of normal behaviour, continuously analyses activity against it, flags deviations and risky patterns, and scores each employee by risk — so security teams focus on the highest-risk individuals and intervene early rather than discovering an incident only after the data is gone. As part of inDefend, UBA works hand-in-hand with DLP (so a flagged transfer comes with behavioural context) and draws on the same endpoint telemetry. India-built by Data Resolve (founded 2008, 1,000,000+ endpoints), it delivers this with local support and India-friendly value.

Ready to catch insider threats early?

Scope a UBA PoC (baseline behaviour, flag anomalies, score risk) — working with DLP in the same agent — or let a TechBag advisor plan your proactive insider defence.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.