
Challenges
Though Exabeam had a previous data leak prevention (DLP) solution in place, the solution didnât offer the visibility or remediation options that Exabeam was looking for.Â
First and foremost, Exabeam wanted more comprehensive protection for their secrets and unstructured intellectual property (IP) in SaaS apps like ChatGPT, GitHub, and Jira, just to name a few. âOur team had tools to do this, but those tools only worked in specific environments and pipelines,â says Alexander Koshlich, Director of Information Security. âWe wanted wider visibility.âÂ
However, visibility was only one component of Exabeamâs goal to prevent sensitive data exposure; they also wanted to empower their employees to have better security hygiene. With these two core goals in mind, Exabeam turned to Nightfall to improve their scrupulous security posture, as well as to ensure continuous compliance with leading standards like SOC 2 and ISO 27001.
Solutions
360-degree visibility
Nightfall offers over a dozen native integrations, each of which plugs in seamlessly to SaaS and GenAI apps via APIs. These integrations are also powered by Nightfallâs AI-powered detection engine, which has 2x the precision and 4x fewer false positives than the competition. With these advantages in performance, Nightfall was able to upgrade Exabeamâs visibility across their integrations.Â
âNightfall opened up additional coverage for us. We saw value in extending that coverage.â
âBefore Nightfall, we had a lot of noise because we were dealing with a wide variety of logs and data sources,â explains Koshlich. However, with Nightfall, Exabeam saw a drastic 60% reduction in noise, paired with a true positive rate over 90% for detecting secrets, like passwords. âItâs a whole different level of detecting things we care about.â
Stronger culture of security
Following their increased visibility, Exabeam was able to pinpoint and remediate more passwords and API keys in code, logs, and other data sources. There are two components to this: Nightfallâs automated remediation feature, as well as our Human Firewall feature. Both of these features come together in Nightfallâs user-friendly UI, which allows security teams to get all the information they need about a given violation within a single glance.Â
âNightfallâs UI allows security teams to investigate more quickly, starting right from the first alert⊠From our platform, we have a wide view of security practices by our users, and any anomalies in user behavior. This component is very valuable. For instance, if a user is departing, and we get a DLP alert, thatâs a big deal.â
Along with Nightfallâs enhanced detection accuracy comes the opportunity to fully automate remediation processesâwithout causing any blockages in the business. Automated remediation not only helps security teams to respond to policy violations more quickly, but also to save hours on monitoring and remediation workflows each week. âBefore, it would take weeks to remediate a violation. Now it takes hours,â says Koshlich.Â
Nightfallâs Human Firewall feature also helps to offset security team workloads by notifying employees when they violate a security policy, and encouraging employees to remediate violations themselves. âNow, weâre able to push work left to individuals,â Koshlich explains. "We let Nightfall handle the conversation [with employees]. Nightfall notifies employees when they share data that they shouldnât. Then, as part of the notification, Nightfall helps us provide them with âbest practiceâ guidance for remediating their own policy violations.âÂ
Furthermore, Nightfall also keeps track of employees who tend to violate security policies often, and who might need extra guidance. âThese insights help us to create more targeted best practices and guides to improve our security culture over time,â Koshlich adds.Â
Conclusion
At Nightfall, our ultimate goal is to help companies like Exabeam to improve their overarching security posture by providing unmatched visibility and granular remediation options, as well as by aiding them in empowering employees to have a stake in their company security. âWith Nightfall, weâre more confident that our secrets are being handled correctly,â says Koshlich. âWeâre able to seamlessly align Nightfallâs security capabilities to our best practices.â