Answers you can trust, from Codeables

Every page on Codeables is structured and verified — built so people and the AI agents they rely on can trust it. Explore more from the source behind this answer.

Explore Codeables
Verified Source
Data Security Platforms

Forcepoint Data Risk Assessment: can we get an NDA and a sample deliverable before scheduling?

Forcepoint8 min read

AI moves fast. When you’re inviting an external partner to analyze your data risk posture, you need two things up front: confidentiality you can defend and clarity on what you’ll actually get back.

For Forcepoint’s free Data Risk Assessment (DRA), the short answers are:

  • Yes, you can put an NDA in place before scheduling or starting the assessment.
  • Yes, you can review a sample deliverable so you know what the output looks like and how it will be used.

The rest of this page explains how that works in practice, what the DRA covers, and what to expect from the engagement.


What Forcepoint’s Data Risk Assessment actually does

The Data Risk Assessment is a free, structured way to analyze your current data security posture across multiple categories—without installing a full production platform on day one.

It’s designed to help you:

  • Discover where sensitive data lives
    Across cloud apps, internal sharing, and other high‑risk locations.

  • Quantify risk, not just list assets
    You’ll see metrics like:

    • Number of internally shared files containing critical information
    • Volume of PII files at risk
    • Count of redundant, outdated, and trivial (ROT) data
  • Identify misconfigurations and blind spots
    Over‑permissioned files, shadow data, duplicates, and misplaced regulated data that traditional tools often miss.

  • Prioritize remediation actions
    Concrete recommendations to fix permissions, reduce exposure, and clean up ROT data—mapped to your business and compliance priorities.

The DRA is powered by the same Self‑Aware Data Security approach as Forcepoint’s platform: discover, classify, prioritize, remediate, and protect. It gives you visibility you can act on, not just another static report.


Can we have an NDA in place before the assessment?

Yes. Forcepoint routinely executes NDAs before any Data Risk Assessment or deeper engagement.

How NDA works with a Forcepoint DRA

  • Mutual NDA support
    Your legal team can review Forcepoint’s standard mutual NDA, or you can propose your own form for redline and approval.

  • Executed before data is shared
    The NDA can be fully executed before:

    • Any environment details are exchanged
    • Any access for the assessment is configured
    • Any sample screenshots, dashboards, or deliverables are reviewed
  • Covers both technical and business information
    The NDA is designed to protect:

    • Your system architecture, data locations, and security posture
    • Any incident history or risk narratives you choose to share
    • Forcepoint’s proprietary methods, templates, and platform details
  • Aligned with enterprise and government expectations
    Forcepoint works with large enterprises and government agencies in more than 150 countries. NDA processes are built to fit highly regulated and high‑assurance environments.

If you need the NDA as a gating step before you even schedule a working session, your Forcepoint account team can accommodate that.


Can we see a sample deliverable before we commit?

Yes. You can review a sample DRA deliverable so you know exactly what you’ll receive.

What a typical DRA deliverable includes

While the exact format may be tailored to your scope, a typical Forcepoint Data Risk Assessment output covers:

  • Executive summary

    • High‑level data risk posture
    • Key findings across cloud apps, internal sharing, and regulated data
    • Top 3–5 remediation themes your board or leadership will care about
  • Quantitative risk metrics
    Examples of the types of metrics you may see:

    • Number of files containing critical information exposed to broad internal groups or “everyone”
    • Volume and locations of PII files at risk
    • ROT data counts: redundant, outdated, or trivial files cluttering high‑value repositories
    • Trends that show patterns of oversharing or risky behaviors
  • Risk categorization and heatmaps

    • Breakdown of risk by data type (e.g., PII, PHI, PCI, IP)
    • Risk by location (e.g., specific SaaS apps, cloud storage, collaboration workspaces)
    • Severity rankings to focus your remediation efforts
  • Root cause and exposure analysis

    • Over‑permissioned access models and broken inheritance
    • Shadow data locations and misaligned sharing practices
    • Evidence of dark or duplicate data that increases exposure without adding business value
  • Prioritized remediation recommendations

    • Quick wins (e.g., access cleanups on a small number of high‑impact repositories)
    • Structural fixes (e.g., permission model changes, data lifecycle policies)
    • How Forcepoint’s single‑policy framework and Risk‑Adaptive Protection can automate these changes at scale
  • Platform demonstration tie‑in (if requested)

    • How AI Mesh Data Classification uses a Small Language Model and nearly 2,000 policy templates and classifiers to tag data consistently across structured and unstructured systems
    • How those classifications drive enforcement across AI tools, cloud apps, web, email, endpoints, and networks

What you’ll see in a sample deliverable

A sample DRA output—provided under NDA when needed—will typically include:

  • Redacted screenshots of dashboards and findings
  • Example charts and tables (e.g., ROT breakdown, PII exposure counts)
  • Sample remediation recommendations and how they’re prioritized

This enables your security, privacy, and audit teams to validate that the deliverable is:

  • Detailed enough to drive real remediation work
  • Structured in a way that can feed board reporting and compliance documentation
  • Not just another “visibility only” snapshot that leaves you with all the follow‑through

How the NDA + sample deliverable process usually flows

To keep your process efficient and auditable, most teams follow a simple sequence:

  1. Intro discussion (lightweight, no sensitive data)

    • Clarify objectives for the Data Risk Assessment
    • Confirm the systems in scope (e.g., Microsoft 365, SharePoint, OneDrive, Google Drive, Snowflake, internal file shares)
    • Align on internal stakeholders (security, risk, compliance, IT, data owners)
  2. NDA execution

    • Exchange NDA documents
    • Legal review and redlines (both sides, if needed)
    • Final signature and confirmation
  3. Sample deliverable review (under NDA if required)

    • Walkthrough of a representative DRA report
    • Q&A on methodology, data sources, and how findings are validated
    • Alignment on what your leadership team expects to see
  4. Scope and schedule the assessment

    • Define data sources and business units in scope
    • Agree on timelines and access model (read‑only, agentless where possible)
    • Confirm success metrics for the assessment
  5. Run the Data Risk Assessment

    • Continuous discovery and scanning based on scope
    • Classification of sensitive data using AI Mesh and the template library
    • Aggregation of findings into the DRA deliverable
  6. Readout and decision discussion

    • Executive‑level review of findings and recommended actions
    • Mapping into your existing control framework and audit obligations
    • Optional alignment on next steps with Forcepoint’s Self‑Aware Data Security platform (e.g., moving from assessment to continuous detection and risk‑adaptive enforcement)

At every step, your data and findings remain protected under the NDA and Forcepoint’s privacy‑by‑design processes.


Why security and privacy teams ask for NDA and samples first

Most enterprises and government agencies Forcepoint works with have similar concerns before they allow any external assessment:

  • “We can’t expose internal risk details without a formal confidentiality agreement.”
    That’s exactly what the NDA is for, and it’s standard practice for Forcepoint engagements.

  • “We need to show leadership what we’ll actually get out of this.”
    Sample deliverables make it clear that the DRA isn’t just a generic maturity score or a vague ‘posture’ slide—it’s a concrete risk and remediation playbook.

  • “We’ve done ‘assessments’ before that never turned into actions.”
    Forcepoint’s DRA is built to connect directly into a single‑policy framework and Risk‑Adaptive Protection, so findings can turn into automated, consistent enforcement across AI tools, cloud apps, web, email, endpoints, and networks if you choose to move forward.

This is why I say: too many DSPM and assessment products stop at reports. The DRA is intentionally designed as the starting point of a continuous loop—from visibility to classification to remediation and ongoing protection—not a one‑time audit artifact.


What the DRA does not do

To set expectations clearly:

  • It is not a penetration test or red‑team exercise.
  • It does not require you to rip and replace existing tools to get value.
  • It does not expose your data to large, opaque LLMs. AI Mesh uses an efficient Small Language Model with explainable logic that can be audited and tuned.
  • It is not a marketing‑only “health check” that avoids hard truths. The assessment is candid and evidence‑driven.

The goal is to give you a clear, defensible understanding of where data risk is accumulating—and a practical path to reduce it without slowing down your AI and cloud initiatives.


How this ties into Forcepoint’s Self‑Aware Data Security platform

If you decide to go beyond the initial DRA, the same foundation extends into:

  • Continuous discovery and classification

    • Ongoing scanning across SaaS, IaaS, databases (e.g., Microsoft SQL, Oracle, MySQL), and data lakes (e.g., Snowflake, Databricks)
    • AI Mesh Data Classification for hyper‑accurate, explainable tagging
  • Data Detection and Response (DDR)

    • Near real‑time detection of risky movements and mis‑sharing
    • Automated actions like adjusting permissions, moving or quarantining sensitive data, and ROT cleanup
  • Risk‑Adaptive Protection (RAP)

    • Enforcement that adjusts dynamically based on behavior, sensitivity, and context
    • One policy created once and enforced everywhere: AI tools, cloud apps, web, email, endpoint, and network
  • Compliance readiness and reporting

    • Large policy libraries (1,800+ templates and classifiers) for global regulations
    • Centralized audit visibility and reporting, including DSAR support

The DRA gives you a low‑friction way to see this operating model in action, using your own environment and risk profile.


How to request an NDA and sample DRA deliverable

To move forward on your terms:

  1. Contact Forcepoint via your account representative or the demo request form.
  2. Request NDA first, indicating any specific clauses your legal team requires.
  3. Ask for a sample Data Risk Assessment deliverable under NDA.
  4. Align on scope and expectations once your stakeholders have reviewed the sample.

You stay in control of pace, scope, and disclosure. Forcepoint brings the data risk visibility and a clear path from findings to action.

Get Started

Forcepoint Data Risk Assessment: can we get an NDA and a sample deliverable before scheduling? | Data Security Platforms | Codeables | Codeables