Sunday, September 20, 2026

When humans and AI talk: Why Proofpoint wants to secure every interaction

Over the past two decades, Proofpoint has evolved from an email security specialist into a human‑ and agent‑centric security platform that protects inboxes, collaboration tools, and AI‑to‑AI communication inside enterprises.

During an interview with EITN, Jennifer Cheng, a cybersecurity strategist at Proofpoint, traced this shift from machine-learning classification of email aimed at spam filtering to securing complex, distributed communication behaviours across email, collaboration apps, and AI agents.

“The definition of human risk and human‑centric security is the foundation for where we started at Proofpoint, and where we’ve evolved in the past 10 years,” she said. “We’re looking at it more holistically and saying, let’s look at not only the threats that are attacking people, but also whether there are vulnerabilities in that particular person’s behaviour.”

Jennifer also admitted that a major acquisition of an insider threat management platform, ObserveIT “that we’ve built in that has grown our strategy” is Proofpoint’s first step into data security.

Proofpoint’s human-centric approach

An industry outsider may observe the various different types of cybersecurity offerings and also that the multitudes of jargons the industry collectively produces could all actually be overlapping.

We’re looking at it more holistically and saying, let’s look at not only the threats that are attacking people, but also whether there are vulnerabilities in that particular person’s behaviour.

Jennifer Cheng

Jennifer’s response is that it all boils down to the end goal and the tools of the trade to achieve it.

Data loss prevention of DLP, for example. Proofpoint positions DLP under a broader ‘data security’ approach because its focus is not only to stop data from leaving an organisation.

She opined that a lot of DLP solutions were built for compliance purposes, and on-premises context. But this has to change because the pandemic brought about a new way of working and AI has exacerbated the shift.

“It’s about how we can rethink what DLP should look like when in this world, people are working everywhere and data is everywhere – in SaaS cloud, on-premises – whatever it may be, what needs to happen for an organisation to govern that information as well as secure it?

“So, when we say we are securing email and we’re securing data, we mean it to encompass whatever that human is collaborating and communicating with, with that information we are here to understand the risks and help protect the human.”

Jennifer added that this encompasses AI that is starting to take on human workloads and processes. “Especially when it relates to any form of collaboration and communication – what does that risk look like?”

What is your strategy?

So beyond email, Proofpoint now protects collaboration and productivity platforms such as Microsoft Teams and Slack, as well as SMS and browser-based access to applications. 

Jennifer stressed that while a malicious URL may look the same in any channel, strategy must account for all the ways users communicate.

“In your strategy, then do you have coverage across all communication channels? And where is the control point in which you’re going to actually stop that threat from coming in?” she posed the theoretical question. 

“From our perspective, the control point is in all of the communication channels that the human is interacting with.” 

Underpinning the control point that Proofpoint proposes, is Nexus, its analytics and threat intelligence platform which is “a combination of a lot of our various different machine learning models as well as our threat intelligence, and how we’re correlating all that information.”

Approaching DLP

Jennifer would argue that modern security must focus on behaviour and intent, not just identity checks.

Leaving identity verification to vendors who specialise in it, what Proofpoint does instead is focused on behaviour, intent, and whether a person communicating or interacting with data is malicious. “Are they doing something they should not be doing?”

This drives Proofpoint’s view that insider threat and data loss prevention are facets of the same issue: data leaving the organisation via people who technically have access.

Jen observed that traditional DLP often fails in today’s distributed environment, and to address this, Proofpoint is using AI-driven classification to distinguish documents and then allow organisations to label and enforce handling policies.

“We can distill and look at things like product documentation versus financial reports and accounting information… Then an organisation can choose to put labels on that classification and then build policies and enforce it.”

This feeds into a “data risk map” that looks across humans, agents and generative AI applications for overly broad access, exfiltration and configuration weaknesses such as unencrypted stores.

Who’s watching your AI agents?

When it comes to AI, Jennifer broadly categorised two main risk fronts – employees experimenting with AI assistants like ChatGPT and Copilot, and the rise of enterprise agents built on protocols such as MCP or Model Context Protocol.

 With these AI assistants, there is risk of data loss due to employees giving AI access to sensitive information when they make queries.

Almost parallel to that is how an AI agent is interacting with another AI agent. 

MCP is called out specifically as the protocol to think about for enterprise agent adoption.

Jennifer shared, “As we look at how agents are communicating with other applications and other agents, then, to be able to thoroughly inspect what is happening in that communication and that interaction, that’s where we think you need to inspect on the MCP level.”

So, when humans and AI talk – to each other or to other systems – or when an agent moves large amounts of data via MCP, the organisation needs to think about MCP-level visibility to determine whether there is risk of malicious or abusive activity.

Cat Yong
Cat Yong
Cat Yong is Editor-in-Chief of Enterprise IT News, a regional news website which began in Malaysia circa 2011. A common theme in all of her work - opinions, analysis, features and more - is how technology and innovation drives business and outcomes. A career tech journalist for 22 years, her work has evolved to also encompass narratives of tech powering human potential.
Powered byspot_img

Read more

News

Powered byspot_img