How Varonis Improves Data Security with Automated Labeling 

Discover the power of Varonis' automated labeling and how it can be an important element in securing your sensitive data. 
Nolan Necoechea
4 min read
Last updated December 20, 2024
Varonis' Automated Labeling

Labeling files can be an effective way to protect data. Enterprises rely heavily on sensitivity labels to enforce DLP policies, apply encryption, and broadly prevent data leaks.

In practice, however, getting labels to work is difficult, especially if you rely on humans to apply sensitivity labels. Manual labeling is time-consuming and error-prone.

Automated labeling helps, but inaccurate scanning tools often leave sensitive data overexposed and unprotected. 

Let’s take an in-depth look at automated labeling and see how it can be an important element to securing your sensitive data. 

Why is automated labeling important? 

Take traditional DLP. On the surface, DLP label-driven blocking seems to create a strong safety net for your data, but in reality, your labels quickly become outdated and are rarely accurate enough to rely on for effective enforcement.

The efficacy of label-based data protection quickly degrades with the amount of data generated in the cloud, and with AI primed to generate orders of magnitude more data, the degradation will only get worse. In short, labels must be accurate and automatically updated.

Enter Varonis’ automated labeling.

Varonis uses hundreds of built-in policies to automatically scan for, pinpoint, and label sensitive and regulated data like GDPR, CCPA, and PII. Our sophisticated rule capabilities target specific data and leverage our extensive pattern repository to build even more labeling rules.

Accurate and scalable data classification 

Accurate data classification is the crucial element of labeling. Unreliable data discovery and analysis undermines everything from DLP policies to CASB functionality and threat detection and response.

According to Gartner, more than 35% of DLP projects fail because of poor data classification and discovery. DLP effectiveness depends on addressing these challenges and ensuring accurate data classification.

Varonis provides accurate and scalable data classification. Our classification engine combines sophisticated pattern matching with AI classification to reach near 99% accuracy.

We scan multi-petabyte customer environments top-to-bottom and put sensitivity in context with permissions and activity. Varonis classification results are always current because our activity auditing detects files created or changed. There is no need to re-scan every file or check the last modified date. 

Custom labeling policies  

Varonis allows you to create granular labeling policies to fit your organization’s data protection and privacy requirements for Microsoft 365, Microsoft Copilot, and on-premises. 

Blog_Labeling_InCopyImage1_202412Find, label, and protect your critical files. 

Smart labels 

Varonis automatically re-labels files when a policy changes or if the content of the file changes to no longer match the policy. If a label no longer applies, we remove it, ensuring your data protection efforts are always up to date. 

 

Blog_Labeling_InCopyImage2_202412

Smart labels change when your files change. 

Manual label clean-up  

Varonis finds files that have been misclassified by users or that aren’t labeled at all by comparing labels to our classification results. We can automatically fix labels in bulk, or you can manually reconcile them. 

 

Blog_Labeling_InCopyImage3_202412

Fill gaps in manual labeling.  

Compliance dashboard 

We have several data labeling dashboards to help you better understand your labeling efforts and fix errors. From the dashboards, you can easily drill into a report to see exactly which files are labeled and get more information on each, including: 

  • Labeled Files: See how many files are labeled in the monitored data source 
  • Labeled Files per Label: See the number of labeled files per label 
  • Labeled Files by Classification Category: View the number of classified files labeled in each category 
  • Labeled Files by Classification Rule: Provides a detailed view of labeled files according to classification rules
  • Files with Label Downgraded by User: See files with labels changed to lower priorities by users 
  • Mislabeled Files: Track incorrect labels over time 
  • Files Mislabeled Manually per Label Value: View the number of files that were labeled incorrectly by users 
  • Files Mislabeled Automatically per Label Value: Reveal files incorrectly labeled by automated systems 
  • Resolved Mislabeled Files: Showcases fixed labels across the Compliance, File Servers, SharePoint Online, and OneDrive dashboards 

 Blog_Labeling_InCopyImage4_202412
New data labeling dashboards track your labeling efforts. 

Pre-defined reports  

Unlock a massive library of reports about your labeled files, including permissions, activity, and trends, to demonstrate your labeling progress to executives, auditors, and even cyber insurers and let them see that you are continuously reducing data exposure. You can run reports on-demand or email them on a schedule. 

Label monitoring dashboard 

The new labeling monitoring dashboard provides you with a single pane of glass view into the labeling progress across your environment. It helps users understand how many files are labeled, in progress, or have failed, so you can track your labeling progress with absolute confidence.

Blog_Labeling_InCopyScreenshot_202412_V1

Monitor your labeling progress from a single page.

Microsoft Purview Information Protection integration  

By integrating with Microsoft Purview Information Protection (MPIP), customers can automatically apply classification labels and encrypt files that Varonis has automatically identified as sensitive. Users can manually tag documents, and Varonis will ingest this information and provide additional context around the data.

  • Classify a file based on its MPIP label 
  • Decrypt and scan the content of MPIP-encrypted files 
  • Automatically apply MPIP labels according to configuration, while skipping manually labeled files 
  • Automatically correct (and report on) mislabeled files 
  • Automatically perform bulk re-label when a policy is changed 
  • Enrich Varonis classification report with classification labels data 

EDR, DLP, DRM integration 

Varonis makes it easy to integrate with EDR, DLP, and DRM solutions using extended file properties. Our labels are persistent, which means that even when files leave the organization, sensitive data stays protected.

Labels can trigger encryption, obfuscation, tracking, and other DRM and DLP functions. For example, you can use labels to enforce a policy to prevent users from attaching sensitive files to external emails or copying them to USB devices. 

 

see how the integrations work

See how the integrations work.  

How Chemung Canal Trust Company is operationalizing labeling with Varonis

Like all banks, Chemung Canal Trust Company (CCTC) needed to secure sensitive personal and financial data, comply with regulations like SOX and GLBA, and audit data access continuously.

Josiah Bennet, the Security Analyst at CCTC, knew the power of Varonis from previous institution and that he wanted to bring the industry-leading platform to CCTC. CCTC had Microsoft Purview but hadn’t considered embarking on a labeling project.

Our labeling project came up during our Varonis deployment. Our Varonis deployment engineer did a tremendous job outlining the different benefits and brought us up to speed.

Josiah Bennet, CCTC Security Analyst

 

Now that they have Varonis and Microsoft Purview, CCTC is doing what most companies can only dream of — they are in the process of labeling all their information across their data estate, saving time to prepare for audits, and easily pulling reports from Varonis with all the information they need. Read the full case study here. 

See Varonis’ automated labeling in action. 

Knowing where your sensitive data exists, who can access it, and what users are doing with it are all critical questions that need answers to protect it from cyberattacks. Varonis uniquely combines these key security aspects in one unified solution. 

At Varonis, we’re on a mission to deliver automated security outcomes with a holistic approach to data security. Our unified Data Security Platform installs in just minutes and protects your sensitive data wherever it resides, including cloud, SaaS, and data center.

Are you curious to see what risks may exist in your environment? Schedule a demo to get started today. 

What should I do now?

Below are three ways you can continue your journey to reduce data risk at your company:

1

Schedule a demo with us to see Varonis in action. We'll personalize the session to your org's data security needs and answer any questions.

2

See a sample of our Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation.

3

Follow us on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

what’s-new-in-varonis:-jan-2024
What’s new in Varonis: Jan 2024
This month brings you a fresh set of updates designed to improve your cybersecurity journey.
data-classification-labels:-integrating-with-microsoft-information-protection-(mip)
Data Classification Labels: Integrating with Microsoft Information Protection (MIP)
We’re thrilled to announce the beta release of Data Classification Labels: integrating with Microsoft Information Protection (MIP) to enable users to better track and secure sensitive files across enterprise data...
cloud-security-essentials:-the-case-for-automated-dspm
Cloud Security Essentials: The Case for Automated DSPM
Data security posture management (DSPM) has emerged as a standard for securing sensitive data in the cloud and other environments. However, without automation, DSPM doesn’t stand a chance. Automation is crucial to overcoming the challenges of securing data in the cloud.
how-to-prevent-your-first-ai-data-breach
How to Prevent Your First AI Data Breach
Learn how the broad use of gen AI copilots will inevitably increase data breaches, which Varonis' Matt Radolec shared in an RSA Conference 2024 Keynote session.