Proofpoint integrator in Switzerland
We deploy and operate the Proofpoint solutions — email protection, domain authentication, data loss prevention and user training.
Why this vendor
The vast majority of compromises begin with a message. Not with an infrastructure flaw, not with a forgotten exposed service: with an email somebody opened because it looked like the ones they open every day. It is a banal observation, and yet most security budgets keep being spent elsewhere.
Proofpoint's approach stands out on one point: it reasons per person rather than per message. Knowing which staff are genuinely targeted — and they are targeted very unequally — changes how the effort is spent. Strengthening controls and training where the attack concentrates beats a uniform treatment that weighs on everyone without protecting anyone in particular.
The hard work is not the filtering, which works from day one. It is domain authentication: moving a domain to DMARC reject requires an inventory of every legitimate sender — the invoicing tool, the recruitment platform, the outsourcer, the agency that sends the newsletter. That inventory almost never exists, and it is what decides how long the project takes.
Our team also runs real social engineering campaigns. So we know what gets through a filter and what fools an alert user, and that feeds the configuration as directly as it feeds the training content.
- Inventory of the domain's legitimate senders
- Move to DMARC reject without breaking sending
- An offensive view from our own campaigns
- Articulation with awareness training
- Handling of exceptions and false positives
One detection engine, several controls
The products we integrate
Seven products addressing the same question from different angles: what arrives, what leaves in your name, and what people do with it.
Email protection
Core Email Protection analyses inbound messages — attachments detonated, links rewritten and re-evaluated at click time, detection of business email compromise attempts that carry neither attachment nor link. Secure Email Relay handles the outbound side: centralising the mail sent by your business applications, which are almost always the blind spot of a DMARC project.
Domain authentication
Email Fraud Defense drives SPF, DKIM and DMARC compliance, and monitors domains that look like yours. What is at stake goes beyond security: a properly authenticated domain is delivered better. The project consists first of listing every legitimate sender, then hardening the policy in stages, from plain monitoring to reject.
Accounts and insider threat
Account Takeover Protection spots compromised accounts by their behaviour — a sign-in from an improbable location, a mailbox rule created to hide replies, an unusual bulk send. Insider Threat Management covers the risk from within, that of a departure taking files along as much as that of a good-faith mistake.
Data and human risk
Enterprise DLP follows data across email, the cloud and endpoints, under a single policy rather than three consoles that contradict each other. ZenGuide handles training, targeted by each person's real exposure: the most targeted staff receive more, and those who are barely targeted are not put through a programme calibrated for others.
Proofpoint Nexus is the detection engine shared across the products. An indicator seen on an inbound message serves the account controls and the data controls, and a person's measured exposure steers their training. That circulation is what separates a platform from a set of tools bought from the same vendor.
How we proceed
Filtering works from day one. It is domain authentication that demands method, and it sets the pace of the project.
This service in practice
Frequently asked questions
An attack begins with a message
Describe your situation — we start by looking at who actually writes in your domain's name.