Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Proofpoint integrator in Switzerland

We deploy and operate the Proofpoint solutions — email protection, domain authentication, data loss prevention and user training.

Why this vendor

The vast majority of compromises begin with a message. Not with an infrastructure flaw, not with a forgotten exposed service: with an email somebody opened because it looked like the ones they open every day. It is a banal observation, and yet most security budgets keep being spent elsewhere.

Proofpoint's approach stands out on one point: it reasons per person rather than per message. Knowing which staff are genuinely targeted — and they are targeted very unequally — changes how the effort is spent. Strengthening controls and training where the attack concentrates beats a uniform treatment that weighs on everyone without protecting anyone in particular.

The hard work is not the filtering, which works from day one. It is domain authentication: moving a domain to DMARC reject requires an inventory of every legitimate sender — the invoicing tool, the recruitment platform, the outsourcer, the agency that sends the newsletter. That inventory almost never exists, and it is what decides how long the project takes.

Our team also runs real social engineering campaigns. So we know what gets through a filter and what fools an alert user, and that feeds the configuration as directly as it feeds the training content.

Proofpoint
What we bring
  • Inventory of the domain's legitimate senders
  • Move to DMARC reject without breaking sending
  • An offensive view from our own campaigns
  • Articulation with awareness training
  • Handling of exceptions and false positives
Vendor website
Diagram

One detection engine, several controls

Proofpoint architecture: shared detection engine and four domains EmailprotectionCore Email ProtectionSecure Email RelayAuthenticationand fraudEmail Fraud DefenseAccounts andinsider threatAccount Takeover ProtectionInsider Threat ManagementData andhuman riskEnterprise DLPZenGuideProofpoint Nexusshared detection engineProofpoint Nexus
The detection engine is shared: an indicator seen on a message benefits the account and data controls.

The products we integrate

Seven products addressing the same question from different angles: what arrives, what leaves in your name, and what people do with it.

Email protection

Core Email Protection analyses inbound messages — attachments detonated, links rewritten and re-evaluated at click time, detection of business email compromise attempts that carry neither attachment nor link. Secure Email Relay handles the outbound side: centralising the mail sent by your business applications, which are almost always the blind spot of a DMARC project.

Core Email ProtectionSecure Email Relay

Domain authentication

Email Fraud Defense drives SPF, DKIM and DMARC compliance, and monitors domains that look like yours. What is at stake goes beyond security: a properly authenticated domain is delivered better. The project consists first of listing every legitimate sender, then hardening the policy in stages, from plain monitoring to reject.

Email Fraud Defense

Accounts and insider threat

Account Takeover Protection spots compromised accounts by their behaviour — a sign-in from an improbable location, a mailbox rule created to hide replies, an unusual bulk send. Insider Threat Management covers the risk from within, that of a departure taking files along as much as that of a good-faith mistake.

Account Takeover ProtectionInsider Threat Management

Data and human risk

Enterprise DLP follows data across email, the cloud and endpoints, under a single policy rather than three consoles that contradict each other. ZenGuide handles training, targeted by each person's real exposure: the most targeted staff receive more, and those who are barely targeted are not put through a programme calibrated for others.

Enterprise DLPZenGuide
What makes the difference

Proofpoint Nexus is the detection engine shared across the products. An indicator seen on an inbound message serves the account controls and the data controls, and a person's measured exposure steers their training. That circulation is what separates a platform from a set of tools bought from the same vendor.

Proofpoint Nexus
Our approach

How we proceed

Filtering works from day one. It is domain authentication that demands method, and it sets the pace of the project.

Proofpoint integration approach, from inventory to operations ScopingImplementationDuration01Domainsenders02Filteringpolicy03Pilot onone scope04DMARC inmonitoring05Move torejectOperationsor handover
Reject comes last, and only after a monitoring period: that is what avoids blocking a forgotten legitimate sender.
Related use cases

This service in practice

Frequently asked questions

Frequently asked questions

It depends entirely on the number of legitimate senders, not on the tool. An organisation that only sends from its own mail service gets there in a few weeks. One where twenty applications and providers write in its name will take several months, the time to list them all and have them sign correctly. The monitoring phase is what reveals the forgotten ones.

The two are commonly combined, and the question deserves an honest answer rather than a pre-decided one. Depending on your licence, your exposure and what you have already enabled, the answer may be to strengthen what exists rather than add a layer. We integrate both, which lets us say so without a commercial agenda.

A generic annual session, barely. A programme calibrated on real exposure and fed by campaigns that resemble the attacks you actually receive, yes — and it is measurable. We run those campaigns ourselves, which lets us tune the content to what works today rather than to a catalogue scenario.

Yes, through our support and managed service offering: handling messages reported by users, managing exceptions, tracking new senders on the domain and evolving the policies. Or through a handover to your teams.

An attack begins with a message

Describe your situation — we start by looking at who actually writes in your domain's name.