Sumit Dhawan, Chief Executive Officer of Proofpoint, joins us for theCUBE's live coverage of the RSA Conference 2025. In this engaging session, Dhawan shares expert insights on navigating the evolving cybersecurity landscape, highlighting key trends such as the increase in social engineering attacks and the integration of artificial intelligence in security protocols. This discussion is part of our Cyber CEO Leader series.
With over 220 customer meetings at RSAC, Dhawan emphasizes growing concerns around generative AI and its impact on cybersecurity. The conversation explores challenges faced by international markets, as well as significant differences observed from previous years. Dhawan outlines Proofpoint's strategy for enhancing data security, particularly with AI-driven solutions, to address these increasing threats—providing a unique, human-centric approach to cybersecurity challenges.
Throughout the discussion, Dhawan highlights the expansion of Proofpoint's offerings into new markets and customer segments, emphasizing their AI-powered human-centric platform as a game-changer in the industry. They reflect on the importance of partnerships and collaborations within the cybersecurity ecosystem to build integrated solutions for comprehensive threat defense. Dhawan urges businesses to adopt an architectural approach that accommodates few strategic partners, echoing the broader industry theme of change from traditional software models to AI readiness.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For RSAC Conference 2025
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for RSAC Conference 2025.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to RSAC Conference 2025
Please sign in with LinkedIn to continue to RSAC Conference 2025. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Sumit Dhawan, Proofpoint
Sumit Dhawan, Chief Executive Officer of Proofpoint, joins us for theCUBE's live coverage of the RSA Conference 2025. In this engaging session, Dhawan shares expert insights on navigating the evolving cybersecurity landscape, highlighting key trends such as the increase in social engineering attacks and the integration of artificial intelligence in security protocols. This discussion is part of our Cyber CEO Leader series.
With over 220 customer meetings at RSAC, Dhawan emphasizes growing concerns around generative AI and its impact on cybersecurity. The conversation explores challenges faced by international markets, as well as significant differences observed from previous years. Dhawan outlines Proofpoint's strategy for enhancing data security, particularly with AI-driven solutions, to address these increasing threats—providing a unique, human-centric approach to cybersecurity challenges.
Throughout the discussion, Dhawan highlights the expansion of Proofpoint's offerings into new markets and customer segments, emphasizing their AI-powered human-centric platform as a game-changer in the industry. They reflect on the importance of partnerships and collaborations within the cybersecurity ecosystem to build integrated solutions for comprehensive threat defense. Dhawan urges businesses to adopt an architectural approach that accommodates few strategic partners, echoing the broader industry theme of change from traditional software models to AI readiness.
Sumit Dhawan, CEO of Proofpoint, joins theCUBE’s Dave Vellante and John Furrier at the RSAC 2025 Conference to discuss rising concerns around generative AI and its impact on cybersecurity. The conversation highlights shifts in the threat landscape, particularly the surge in social engineering attacks and the evolving role of data protection.
Dhawan shares observations from over 220 customer meetings at RSAC, noting increased urgency around AI readiness and security architecture. He explains how Proofpoint is expanding its human-centric platform to help...Read more
exploreKeep Exploring
What event is the CEO of Proofpoint participating in as part of the Cyber CEO Leader series?add
What are some key topics of discussion at the RSA Conference?add
What is driving the increased demand for layers of defense against social engineering in enterprises, both for existing and new customers?add
What is the purpose of Prime Threat Protection and how does it tailor simulations and gaming for different types of socially engineered attacks?add
What are the key solution areas in a cyber architecture and why is there a need for solution providers to emerge?add
>> Welcome back, everyone, to
theCUBE's live coverage here in San Francisco, the RSAC in 2025. I'm John Furrier, your
host with Dave Vellante-
Dave Vellante
>> Got to get that C in
there. Got to get that C. >> I always forget, Dave,
RSAC. Sumit Dhawan's here. The CEO of Proofpoint, part of our Cyber CEO Leader series, of course. NYSE Wired community is open to everyone. It's open source and a growing
community around leaders. Bringing together the best of the best. Sumit great to have you on
theCUBE again. Good to see you. This is your show. This is
the biggest security show, because it's got the business side, all the customers are here. They have technology
tracks, so sandboxing. So they do a good job of doing that, but it can be vendor keynotes,
some feedback. But for the most part,
everyone's here. Okay-
Sumit Dhawan
>> Well, first of all, thank
you for having me but- >> Great to see you. >> But you're right, John. I mean, I think as we were
discussing, we've had, just this week alone, 220
customer meetings booked. Okay. This is not including dinners and hanging out at the
bars with customers. These are just actual
conversations in conference rooms. We've taken a big set of series of rooms and customers like it, because it's a way for them to
engage with strategic players and strategic partners. And so, that's the best use
of the RSA Conference we get- >> Yeah. What's like-
Dave Vellante
>> What's the conversation like and how has it changed in
the last couple of years?
Sumit Dhawan
>> I'd say the social
engineering is hot and more and more customers that are
coming internationally from different markets that we haven't had
experienced in the past. I met three Indian CISOs
yesterday, customers from Singapore yesterday, Japanese customers. Those customers typically
didn't think of Proofpoint as a key provider or a potential provider. And now, they are
interested because maybe... And we can only attribute
this to generative AI, because they are seeing much, much higher socially
engineered phishing attacks. So that's number one.
Secondly, data security, okay? Especially in the age of
data being everywhere. And now, with AI tooling coming in, and it's going into a
little more production, even though it's still early days. So as they go into
production, all of a sudden, data security concerns. Where the data is and our posture solution
is very important. That was less so of a conversation and we weren't quite ready. The market wasn't quite ready last year. Those are two pretty significant
differences I see from last year and there's a little bit
of this undertone of working with few strategic partners.
Dave Vellante
>> A little bit. It's starting-
- Yeah. It's starting-
Dave Vellante
>> We're starting to see. Right-
Sumit Dhawan
>> We're starting to see-There's
evidence in the data. >> Yeah.
- Whereas, last year, not so much.
Sumit Dhawan
>> It was starting, but it
was... It definitely ticked up- >> It wasn't as obvious. Yeah.
Sumit Dhawan
>> It has ticked up. It's ticked up. It's a little bit more deliberate of an architectural approach
of making it, so that few players formulate
the cyber architecture. So those are what I would consider as differences from last year. >> Yeah. The theme we're hearing
on theCUBE is obviously the architecture change, the
old way software is built to now AI readiness is a big
part of that conversation. So clearly, we're seeing
that up and down the stack. Look at Nvidia all the way to the apps and solutions around models,
apps, and infrastructure. But what you guys are
doing, I want to ask you to explain this, because
I like what you guys say. Your AI-powered, human-centric approach. Can you explain that?
Because we're hearing a lot of human in the loop, in the narratives being much more front and center here at RSAC. What does that mean? What
does AI-powered human- centric platform mean? Can you describe it?
Because I think that's going to be the theme that we'll carry
on the next year, for sure.
Sumit Dhawan
>> Yeah. Last year at this conference, and I recall when we were
talking about this last year, we introduced these new language model based
intent detection in the communications that people are having. So that intent can be
detected in the communication, whether it is real or it's something that
needs to be condemned because it's a potential threat. We have had that in production
for a year now, okay? And the amount of efficacy
we have seen in our solution has gone. While, at the same time, volume and sophistication of
threats have gone up. So we have actually used AI
to take a step ahead of it. So volume and sophistication going up. Our percentage detection,
we call it efficacy metrics, have actually grown up quarter
over quarter over quarter. Because the AI, these technology that we have in our platform,
it learns really, really well, and it gets better at a rapid pace. So we are quite proud
of how AI can be used to effectively defend against
the malicious use of AI that's happening in the threats. Same thing now. This year, we introduced agentic AI into our solution. What agentic AI is doing is it's going out and discovering all your data. Something that's manually humans can't do. Agentic AI can do that,
combine language model with automation and it becomes
agentic to some extent. It spreads out and does the
work of discovering, sampling based on the sampler... Classifying that makes
sense for your organization. And then, with one click
enabling rules for DLP. If humans were to do it, this
would take months or quarters. Now, agents can do that
within a matter of days.
Dave Vellante
>> And how's the accuracy? I
mean, more they're accurate-
Sumit Dhawan
>> Accuracy is significantly
higher than humans. Very high-
Dave Vellante
>> Yeah. Humans don't get to it.
Sumit Dhawan
>> Yeah. Humans won't get
to it, right? So to me, that is the relevance of
AI-powered human-centric, because humans are the ones
that are getting attacked. Humans are the ones that are losing data. So you couple them with AI, so that, A, you can deflect the attacks and, B, you can secure the
data through the right set of data-centric security that's
contextual to user behavior.
Dave Vellante
>> And the classification is
with gen AI, is that right?
Sumit Dhawan
>> It's all models. Yeah. It's all... There are different types.
It's like language models that can interpret code, images,
and actual human languages-
Dave Vellante
>> Because state-of-the-art
classification used to be things like support vector machines and probabilistic latent
semantic indexing, which were just not that great, you know?
Sumit Dhawan
>> It takes too long-
- throwback there.
Sumit Dhawan
>> It's too long. I mean,
many enterprises tried it and those that had to
basically just check the box on compliance is the only ones that were successful in rolling out. And then, after a quarter, they were unsuccessful because it changed. People are continually creating data. >> Sumit, the user-centric
positioning is interesting. Because one of the things we're
hearing here is that post- COVID, you have two kind
of work environments. You're in the building around the network and then you're at home, so that, obviously, from work at home. But now, you have users
being targeted everywhere. And with the models, for the
bad guys, are getting smart and highly productive too. So there's a lot of phishing, a lot of human social engineering. I think I wrote on my post,
"Social engineering is the one thing that everyone's
afraid of on both sides, the supplier side and
also the customer side. " Is this a big part of
your growth right now? Is this piece of it or is it other factors with the users being
targeted? How was that-
Sumit Dhawan
>> Yeah. We announced our quarterly summary. We share them on a quarterly basis. Most of our growth that is
coming in is predominantly because of increased risk
of just social engineering that's coming into the enterprises and existing customers want
layers and layers of defense. And new customers that
have, really in the past, not cared about it because
their location, their size, their language of doing business,
were enough of a defense against socially engineered
attacks because... And that's not the case anymore. Everyone needs the best
possible protection. It doesn't matter how big you are, doesn't matter which location you are on, doesn't matter which
language you do business in. Everyone needs it.
Dave Vellante
>> It may not be causal, but
there's some data that we have. You mentioned ETR. They
asked a question, just last week they closed the survey. 43% of the... It was an N of 500. Have increased their
cybersecurity spending, they said directly as a result of rising geopolitical tensions. >> There you go.
- But is it related to-
Sumit Dhawan
>> Geopolitical tension-
Dave Vellante
>> Because it's interesting to
hear you say Singapore, India are more interested now
in contacting Proofpoint. Do you think there's a relationship between the geopolitical tensions and-
Sumit Dhawan
>> I think there is maybe some. There is a higher degree of
correlation between advent of generative AI and crypto. I think those two together
contributed easier way to attack and easier way to extract. Okay? So to me, there is that. I think you combine that with people working from
everywhere, the consumer-like work behaviors adopted in the work styles. And so, that is, I
think, a big determinant. We always correlate what happens, when there is geopolitical? Geopolitical risk creates higher degree of attacks onto critical infrastructure. Both in terms of socially
engineered attacks... In other words, overall
volume may seem reasonable. But if you zoom into certain
industries, the volumes spike. Secondly, it creates insider risk at a much, much higher rate. You start seeing... I was talking to a CISO of
a global Fortune 50 company and said, "Listen, we analyzed the recent hires that we just made and it was
a shocking percentage of those that were North Koreans
or funded by North Korea. " So there's an increased
degree of insider risk and there is increased degree of socially engineered threats. Both human-centric problems coming in, but for certain industries-
Dave Vellante
>> And these are-
- More so in certain industries. >> Yeah.
- And these are remote employees most likely, right?
Sumit Dhawan
>> Yes. - "Send me the laptop,"
and it goes to some laptop-
Sumit Dhawan
>> Who knows when you have
this employee that's coming in to work for this enterprise, how long before they are actually going to be used as an attack vector? They're just in there at some
point in time being placed, so that they can be used to perform some form of detonation at the right time.
Dave Vellante
>> I've seen the simulations
of the interviews and these kids look... They look presentable. They're articulate. They've got a resume. You're hired.
Sumit Dhawan
>> Yeah. And they may not even know... They may not even have the intent at the time when they are getting hired- >> Right. They're recruited-
Sumit Dhawan
>> They're just recruited
in through just financial. >> Sumit, talk about the business. Since you came to Proofpoint,
what's the business outlook? Where's the growth coming from? You mentioned, before we came on camera, sovereign clouds in the
area, you mentioned those foreign locations and the regions. What new products are coming out? Can you share some of the business metrics
and what you're working on? Where's the action in that?
Sumit Dhawan
>> Yeah. I think we announced... Last year, we passed 2 billion in ARR, so we are proud of that. There are only handful of
companies that have crossed that mark in the cyber industry. And if you look at all of
those, we are the only ones that do human-centric and
that's all we focus on. In the human-centric platform,
we have two set of solutions. One is threat defense. And in threat defense,
our growth is coming in by customers saying, "I'm
not going to use piece- part solutions. I'm going to use you for
not just email, I'm going to use you for protection for any channel. Because threats may come in from WhatsApp and iMessage, just like they
are coming in from email. " They are saying, "I'm
going to use you for also making sure that if
accounts are taken over, you can correlate that back
to how the threats originated. " And then, making sure the
threat resiliency is built in. So originally, we were
selling piece-parts products. At this conference, we
announced something called Prime Threat Protection. We built integrated workflows, one for SOC and one for humans, end users. So let's say if I'm a threat actor and I'm sending you
guys two different type of socially engineered attacks, because I've said that
you are two different. You're in accounting payable and you're maybe doing an IT service desk. I'll send you a different
socially engineered attack to you than I would to you. So then, why do we have to do simulations and gaming the same way for both of you? Since we are the ones
in Proofpoint defending and detecting what type of
attack came into which user, now, we can with a click of a
button, enable customers to say, "Hey, simulate and gamify the attacks
as if they are coming in. " Of course, you're not
going to have their attacks. So that builds a human resiliency layer. So that's one thing that's driving growth. Second thing is, as I mentioned,
there are new customers, a new market segments,
geographies as well as lower size of the enterprises that typically,
Proofpoint has served in. Or even managed service
providers that have said, "We want best-in-class efficacy, but we want a product that's suited for us as is in running in my sovereign cloud. It's something managed service
providers can operate in a multi-tenant fashion. Or even if I'm a small
enterprise, I can adopt it with a simple integration
with Microsoft 365. " So we did a partnership with Microsoft. We enabled the Microsoft
365 simple API. Boom. All of our threat stack is
available to these customers who don't have security expertise and we opened up data
centers and availability and sovereign solutions all over. So it's early stage, but that's
another area of growth. But- >> So you see that as upside?
Sumit Dhawan
>> That's upside. That's upside. We are counting on it as we move forward, because it's early days. And data security, our
DLP business is on a tear. We believe we became the
market leader after Q1. End of last year, Gartner said
we are number two player with such a small difference behind Symantec. Q1 was a bumper quarter for
us, 45% year-over-year growth. We are just growing this thing so fast. So we think we tipped the scale in Q1 and we took over the leadership and that particular quarter
had more Symantec replacement. So we think it's a
two-for-one sort of a thing- >> Well, first of all, congratulations. We know you know how to scale up. And following your work at VMware, you got incredible track record. But we're in a whole
nother world now with cyber and being a cyber leader, as
part of our series, I want to ask you, what is the
cultural vibe right now? In the spirit of vibe
coding which is a hot trend, what's it take to be
a leader in cyber now? Because the market's changed, you mentioned those point products. You saw that. You pulled that together. That seems to be a trend.
Consolidation's happening. Confidence around my
partner, vendor, supplier. What is the culture of
a leader now in cyber? Is there new rules? Are there new establishments? What would
be your position on that?
Sumit Dhawan
>> I think, firstly, I would
say the first rule I still believe in is that cyber has good at innovation
and customer value. You cannot lose that in a
cyber company in the spirit of doing everything else. So I would say, you have to
preserve that, number one. Number two, I think that the
industry is highly fragmented and you do need to think about not necessarily building a bunch of tools, but building integrated solutions that you can do organically as well as bringing the right inorganic solutions. Like we acquired a
company called Normalyze. Amazing product, Gartner
Cool Vendor of the Year. We integrated into our DLP solution and it's integrated into our solution. We actually decided not to
sell it standalone like it was. We said, "Let's get this. We'll keep the momentum going with customers who are interested. " But then, it's just
someone comes in with DSPM. It's not a cul-de-sac. They can go to DLP straight
from there with one- click, touch, rules are set up- >> So data security is new with Normalyze or did you have data security before that-
Sumit Dhawan
>> We had data loss prevention, which was data security in motion, and now we have data security at rest. But from a customer point of view, coming back to your point- >> It's just one thing-
- It's one thing. It's one thing-
Sumit Dhawan
>> Yeah. It's the same data. The-
Sumit Dhawan
>> It's the same data. It's the same data. One is when it's in motion and the other is when it's at rest. So we combine that
together into a solution, but didn't force customers
that you have to buy both. So that's the second thing,
scaling part of it on how you build solutions by giving customers choices and paths. And then, I would say ecosystem. I think ecosystem is
an important dimension in cyber industry. I spend time with George at CrowdStrike. We spend time with
CyberArk. We are building deeper integrations. We have the same thing with SASE players. So formulating partnerships
with deep solutions that we can serve customers
in an integrated fashion is something new for cyber industry. >> Well, yeah. Awesome. Great.
And you know ecosystems, we covered you at VMware,
again, like I said. I want to ask you about the ecosystem. Because Dave and I, we're just
talking in our CUBE Pod this past Friday about how the role of the ecosystems are
changing in the modern era. It's not just, "Hey, I'm in the ecosystem. I resell," or, "I do some integration. " The integrations are different because if you're going to
integrate, if you're going to go bring those point
products into a platform, then you're going to
talk to another platform.
Sumit Dhawan
>> Yes.
- So there's usually an engineering discipline developing. We're seeing that clearly in
the talks and then the data. But we haven't really kind
of heard how that maps to strategy and execution because, "Okay. You're going to be in sovereign cloud. " That's essentially a region that's got its own requirements. That's going to be upside
for you and growth. But when you talk about the
ecosystem, the survey data shows that the ecosystem is
also participating... There's more spend to run things. They're not just channel partners to sell, they're running on behalf
of the customer, on behalf of the new players. So what's your view of the
ecosystem role, the relevance? Is it more engineering is-
Sumit Dhawan
>> Yeah. I think the ecosystem
partners are trending in two directions, because
cyber ecosystem started with hardware-based resellers
with a margin structure and limited services around it. That's with cyber eco. Very
different than infrastructure because infrastructure started with that, but very quickly evolved to cloud building or other sort of value providers. Cyber is behind on that
front, but it's too late now because technology moved to
the cloud and the cyber front. So what we are seeing is the
world is shifting to two parts. One is either you're becoming
managed service providers. And managed service providers
are aggregating smaller players into standardized platforms and they're running it for
more and more customers and customers at scale. That's a change. That's
never happened in the past, but there's no way a
mid-sized enterprise can get the right cyber expertise. So standardized platforms
with the right cyber expertise that can operate more customers
than even customers at bigger will happen. We are seeing that pattern- >> On the managed service
side, you see that growth- >> On the managed service side. And then, the second is the
partners are going into more solution integrations. It will happen. Because you can see, if customers have to roll out... In a cyber architecture, there are three key
solution areas, maybe four. You protect your people, you
protect your code, you detect and respond, and then you have
your zero trust perimeter. If you put out these three, four things, you've got your cyber architecture. But cyber teams are not designed to do these implementations. They are risk people, they are SOC people, and IT teams are not
designed and ready for that. So there is a clear need for
solution providers to emerge. So we see that distinction and we think that we have to
help partners on both ends and this is where alliances
need to be formulated, okay? We are not there yet. I believe the alliances need to be formulated. Because someone, if they feel like one platform
will be serving on both ends of the spectrum, it's unreal. It's impractical. It's not going to happen
for a long period of time. Maybe after five, seven years for the consolidation, but not now.
Dave Vellante
>> Well, but to your point
earlier, about we're starting to see some indications of consolidation. Your consolidation play
is through the ecosystem. It's not through being-
Sumit Dhawan
>> Yeah. I mean, we are consolidating,
like we did acquisition of Tessian and Normalyze last year. We are looking at some organic innovations that we will release this
year, which are built around our platform and we
will continue to acquire things that are human-centric, okay? But we won't go acquire XDR.
We won't go acquire SASE-
Dave Vellante
>> Partner for that. Yeah.
Sumit Dhawan
>> Those are the partnerships, okay? And we believe vice versa. Because if any of those players
acquire human-centric, then we are still the industry
leader in that space. You'd still have to partner, even if you have piece-part offer- >> It's best of breed platform, Dave.
Dave Vellante
>> Well, how does George say it? It's gone from best of breed
versus sweet to now, best of breed versus best platform-
Sumit Dhawan
>> Best platforms. I think that's sort of-
Dave Vellante
>> Yeah. Platforms- >> Well, how do you approach that platform? Is it single platform from one
brand or is it an ecosystem?
Sumit Dhawan
>> George and I, we have this
discussion all the time. Recently, on a panel. But if you think about it, it's a perfect complement solution. We are upstream preventing
bad stuff from hitting humans and making sure humans don't
make a mistake for losing data. In case something happens where something gets
through our defense, gets through humans, CrowdStrike
detects it, XDR, and responses it. So what do we do? We
send signals both ways. All of our intelligence, we share with them and they share with us. Anytime they detect something,
they can query our system to see how it happened so
that they can respond to it. So that's a classic case of how the solutions need to be built. >> Yeah. And that's the great-
Dave Vellante
>> And then for your
business, the old adage, bad human behavior trumps good
security every time. That-
Sumit Dhawan
>> 100%.
Dave Vellante
>> That's why you're in business.
Sumit Dhawan
>> That's 100% and bad human
behavior is something... In the past, we have taken
an approach of, "Listen, we are going to defend and
protect 100% of threats. " We can't ever depend on a bad human... But now, we are saying, "Listen, we're going to be the best at it. " No one will be 100% including us. So as a result, we have
to build human resiliency. Human behaviors are not
changed by making... You and I can go attend
those 30 minute sort of security awareness classes- >> Yeah. in the world-
Sumit Dhawan
>> Not going to do anything. You have to really go
through simulations, gaming, something fun, something entertaining that makes you remember what to do when you are encountered
with that situation. >> Sumit, I have to ask you,
because obviously we have the West Coast, Silicon Valley, and NYSE Studios
connections, that audience. I was talking to someone in
New York, an investor type, and they're like, "Proofpoint,
what's the upside? " They were trying to
scope and understand your vision for the company. How would you talk to that
type of investor profile in scoping the TAM for... I think human-centric is just beginning. I think it's going to explode in size. Is it a category that's
well-defined? Has it got a TAM?
Sumit Dhawan
>> I think it's starting to- >> How would you scope the
opportunity around human-centric? Because we're going to be targeted, social engineering is not going away. It's a major growth
category, in my opinion. It will change, but that is going to springboard growth.
How would you scope that?
Sumit Dhawan
>> I think there are three things that are growth vectors for us. Number one, we have this undercurrent of social engineered attacks that are happening at a growth rate that's never been seen before. We have only really captured... Even in Global 2000, we are
only there 30% of the market. Still, they are using old
network-based appliances that don't ever do any kind of protection with the sophisticated models. So there's a clear share
shift that'll change and we are in the best
position to capture it, because we've got the best
solution in there, number one. I think secondly, we've
got a growth vector on data security. Data security is a high
growth solution for us. And with the data security at rest and data security in motion, that's... Only we have it. And you know what? It's not a small business for us. It's about 30% of our business now and growing as a
percentage of the business, because it's growing even
faster than our core business. So that's the second growth vector for us. And thirdly, you have to think that when truly these new markets
of customers saying, " I need to go to a service provider," or, "I need to get to a simpler
solution that I can operate, but with the best
possible protection stack, " we haven't even played
in the market up until now. We just launched our solution.
So we are excited about it. Our partners are saying,
"This is exactly what we want. " We announced a partnership with Ingram. Anyone can go out there, get it easily. Our marketplace solution on
Azure comes alive here in the next coming weeks. So we think that opens up a completely new addressable market for us. >> What's been the results of that effort? Because I think that's a key one there. Has it been well-received? Have
you seen some early metrics?
Sumit Dhawan
>> It's early because the
solution that I'm talking about for the mid-enterprise, it's
connected to Microsoft API. It was launched 31st of March. The POCs are going great, so we feel great about the
product and the solution. There's tons of interest, but
it's too early for us to tell. >> Got it. Got it-
- It's a growth vector for us- >> All right. So the next question is customers. What are some of the new things
that you're learning from and what customers need
to know about Proofpoint? Because as you evolve with the market, you're riding the wave, you've
got good product market fit in the core business,
you've got some headroom, new initiatives that will
bear fruit, looks like. What's the new pitch?
What's the new narrative? If you had to take an Instagram photo of the new Proofpoint, what would it be?
Sumit Dhawan
>> Well, I think Proofpoint,
firstly, the human-centric part of consolidating data, security, and threat security into
an integrated solution with one human risk
management is something our existing customers love. They are like, "Why am
I using some other DLP? Why am I using some other data
security? This is integrated. This will tell me who are
my most attacked people, who are the people who have
the best worst behavior with data, and I can then train them and simulate them completely differently."
Dave Vellante
>> ROI immediate, huh? >> It's a huge ROI and a
huge visibility and control. So to me, that sort of is
the interest from customers. All 200, 220 meetings we've
had, they are like, "Oh, I love your data security. It just fits into my human risk. " That's why it's becoming
a growth vector for us. >> Yeah. Yeah. That's great. I
think you cracked the code on the human angle. Congratulations. Well, great to see you-
Sumit Dhawan
>> Great to see you. >> Congratulations.
- Great see you. Great to see you, Dave-
Dave Vellante
>> All right. >> Thank you for having me.
- Sumit, back delivering the goods on theCUBE. As always, we're theCUBE
bringing you all the data here at RSA. I'm John Furrier with Dave
Vellante. Thanks for watching.