All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Forcepoint sells data security and network security software to enterprises, spanning data loss prevention, data discovery, web and cloud controls, email protection and firewalls. It is the commercial business of a company that was split in two. Francisco Partners bought Forcepoint from Raytheon Technologies in January 2021. Forcepoint sold the government and critical-infrastructure business to TPG for 2.45 billion dollars in October 2023. Everfox now sells the cross-domain and insider-threat products that business built for government agencies. Forcepoint said it had nearly 3,000 employees when that sale was announced, and it now counts more than 1,400. A buyer evaluating Forcepoint today is evaluating the commercial business Francisco Partners kept.
| Description | Forcepoint sells data security software that discovers and classifies sensitive information, then enforces one policy across cloud, web, email, endpoint, network and AI tools. | [f1] |
|---|---|---|
| Founded | 2015 | [f2] |
| HQ | Austin, Texas, United States | [f3] |
| Product | What it does |
|---|---|
| Forcepoint AI Data Security | Discovery, classification and policy enforcement at each AI interaction, covering sanctioned applications, shadow AI tools and agents running in cloud or on endpoints. |
| Forcepoint DLP | Data loss prevention that adapts to each user and watches how they handle sensitive data across cloud, web and network channels. |
| Forcepoint DSPM | Data security posture management that finds, classifies and organizes stored data using AI-powered automation. |
| Forcepoint DDR | Continuous monitoring of data activity, aimed at catching and stopping breaches while they happen. |
| Forcepoint Email Security | Inbound threat protection that supplements the security built into mainstream email platforms. |
| Forcepoint DLP for Email | Outbound mail inspection that blocks sensitive content from leaving through email. |
| Risk-Adaptive Protection | Personalized automation that varies data security enforcement rather than applying one fixed rule to every user. |
| Forcepoint Web Security | Secure web gateway controls for browsing and file downloads on managed and remote devices. |
| Forcepoint Cloud App Security | Cloud access security broker controls that protect company data held in public cloud applications. |
| Forcepoint Data Classification | Classification tooling that labels data so the rest of the portfolio knows which files are sensitive. |
| Remote Browser Isolation | Renders risky websites inside a container so the page never executes on the user's own device. |
| Advanced Malware Detection and Protection | Sandbox-style analysis aimed at advanced malware and zero-day exploits reaching users. |
| Forcepoint NGFW | Firewall appliances for the network edge, with software-defined wide area networking built into the same box. |
| Forcepoint Secure SD-WAN | Software-defined wide area networking that connects and protects offices, branches and remote sites. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Forcepoint DSPM discovers and classifies stored data, Forcepoint DLP enforces policy on how people handle it, and Forcepoint DDR watches data activity for breach behavior, alongside web, cloud application and firewall controls. These products are mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Forcepoint aims at a specific buyer, the security team that has to keep regulated information from leaving through web, email, cloud and AI channels, and it publishes a compliance document for the EU DORA rules and a product-level HIPAA document. The pain figures it cites, such as 69 percent of organizations suspecting prohibited GenAI use, are analyst notes it relays rather than independent measurement. [s1, s5, s24] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The data products carry architecture-level detail on their own pages, including the classification approach behind Forcepoint DSPM and its on-premises and cloud deployment options. The network products carry the outside evidence instead, with three Forcepoint firewall modules holding active NIST cryptographic-module validations, an independent check that reaches the firewalls rather than the data engine. [s16, s17, s19] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Forcepoint bought AI classification technology in April 2025 and launched an AI data security platform in July 2026, so it is moving with the shift it describes. The demand evidence in the reviewed sources is analyst commentary the company relays and customer stories it hosts, not independent buyer-side measurement. [s4, s11, s22, s24] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Forcepoint publishes its executive team and its board, and it promoted Ryan Windham from chief customer and strategy officer after chief executive posts at AppViewX and Cedexis plus senior positions at Imperva, F5 Networks and Websense. That record is one the company states about itself, and the reviewed sources for it are all Forcepoint pages. [s3, s10, s18] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Named references include FBD Insurance and HUBER+SUHNER, each with a named executive attached, alongside Liberty University, ERG and HDI Seguros. Forcepoint states its own current customer count, and the outside scale figure in the reviewed sources is a pre-separation one Cybersecurity Dive relayed in 2023. [s3, s12, s22, s24] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Forcepoint closed the Getvisibility purchase in April 2025 and shipped a platform launch in July 2026, which is visible output. No revenue, margin or growth figure appears in the reviewed sources, so efficiency itself is unconfirmed. [s4, s11, s12] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Forcepoint announced a Leader placement in a 2025 IDC MarketScape for data loss prevention, and the reviewed sources carry the announcement rather than the assessment. Independent security research refers to its endpoint product as DLP software without needing to explain the term. Forcepoint frames the newer AI Data Security label itself, and no outside party in the reviewed sources uses it. [s1, s21, s22] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Deployments in the cloud and on premises, together with a library of 1,800 prebuilt policy templates and classifiers, give a replacement project real work to do. Forcepoint's own DLP page offers to bolster Microsoft Purview, and Microsoft enforces data loss prevention policies across cloud apps, email, devices and AI in the Purview portal itself. [s1, s16, s17, s27] |
Forcepoint sells to the security team that has to keep regulated information from leaving through web, email, cloud applications and now AI tools. The company publishes a compliance document for the EU DORA rules and a product-level HIPAA document, which is the shape of that buyer's obligation.
Forcepoint attributes two statements about that obligation to named executives. It says Enda Kyne at FBD Insurance credits the discovery and monitoring products with letting his teams report activity to regulators, and that Christian Keller at HUBER+SUHNER lists navigating global compliance requirements among the top benefits of Forcepoint NGFW.
The framing Forcepoint now leads with is new. It launched a platform it calls AI Data Security in July 2026 and said the agent gateway and shadow-AI controls would reach customers over the following quarter. [s1, s4, s5, s24]
Forcepoint sells one set of data controls and several places to apply them. Forcepoint DLP covers cloud, web and network channels, Forcepoint DSPM finds and classifies stored data, and Forcepoint DDR watches data activity for breach behavior. Web, cloud application, email, browser isolation and malware analysis products sit alongside them.
Forcepoint DSPM runs on what the company calls AI Mesh, which Forcepoint obtained by buying Getvisibility in April 2025, after more than two years of delivering those capabilities with it. Forcepoint describes it as its own approach to data discovery, classification and tagging, and says it deploys on-premises and in public or private clouds.
Forcepoint also sells network hardware. Forcepoint NGFW and Secure SD-WAN deliver firewall and wide-area-networking capability, and the three active NIST cryptographic-module validations Forcepoint holds cover firewall hardware and a firewall cryptographic kernel, the most recent validated on 20 May 2026. Forcepoint lists the outside assessments of its data products, a SOC 2 Type 2 report and an external penetration test for Cloud DLP, on its trust center. It takes access requests there for its ISO Statement of Applicability and its SOC 2 assessments. [s2, s11, s15, s16, s17, s19]
Forcepoint names its own rivals. It publishes comparison pages against Varonis and Cyera, and its DLP page offers to bolster Microsoft Purview across the Microsoft 365 family of applications.
That Purview line measures the position well. Microsoft enforces data loss prevention policies across cloud apps, email, devices and AI from the Purview portal, and Forcepoint's own page presents its coverage as an addition to Microsoft's rather than a replacement for it.
Forcepoint also sells network hardware that its data-security framing does not lead with. Forcepoint NGFW and Forcepoint Secure SD-WAN sit outside that framing, and the outside validation in the reviewed record covers the cryptographic modules inside Forcepoint NGFW. [s2, s16, s19, s27]
Forcepoint names its references. FBD Insurance and HUBER+SUHNER each appear with a named executive attached, and Liberty University, ERG and HDI Seguros appear as customer stories.
Outside reports of scale in the reviewed sources predate the split and relay the company's own figures. Cybersecurity Dive reported in July 2023 that Forcepoint said it had nearly 3,000 employees and served more than 14,000 customers across 150 countries. The company now states more than 12,000 customers and more than 1,400 employees.
The July 2026 platform went to market through Forcepoint's partner community, with the agent gateway and shadow-AI controls scheduled over the following quarter. No adoption figure for it appears in the reviewed sources, so a buyer cannot yet check how many customers run it. [s3, s4, s12, s24]
Forcepoint publishes its executive team. Ryan Windham is chief executive officer, Matt Derdeyn chief financial officer, Bakshi Kohli chief technology officer, Guy Shamilov chief information security officer and Juha Kivikoski general manager for network security.
Windham's background is in the domain and the record for it is the company's own. Forcepoint says he was chief executive at AppViewX and at Cedexis and held senior positions at Imperva, F5 Networks and Websense, and it promoted him from chief customer and strategy officer in July 2024, succeeding Manny Rivelo.
Francisco Partners has a partner on the board. Andrew Kowal, who spoke for the firm at the 2020 purchase announcement and again at the 2024 chief executive change, is listed among Forcepoint's directors. [s10, s18, s25]
Forcepoint runs a public trust center and records there what it holds. The portal lists ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, SOC 2 Type 2, CSA STAR Level 1 and FIPS 140-3, with separate SOC 2 Type 2 reports for Forcepoint ONE, Cloud DLP, Cloud DSPM and Cloud Web.
The FIPS claim is checkable outside the vendor. NIST's list of active validated modules carries three Forcepoint certificates, numbered 5276, 4867 and 4835, covering firewall hardware and a firewall cryptographic kernel.
The endpoint client has drawn outside scrutiny twice in a year, and both reports concern software Forcepoint runs on customer endpoints to enforce policy. Triskele Labs reported a privilege escalation flaw that Forcepoint fixed in version 25.05 in May 2025, and CERT/CC published a note in January 2026 about a Python 2.5.4 runtime bundled in the Forcepoint One DLP Client, which Forcepoint resolved by removing the runtime. [s15, s19, s21, s23]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Varonis | competes with | Forcepoint publishes a comparison page against it. | |
| Cyera | competes with | Forcepoint publishes a comparison page against it. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Microsoft | competes with | Forcepoint's DLP page offers to bolster Microsoft Purview across Microsoft 365, so the two products meet in the same accounts. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Forcepoint.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Forcepoint competes on breadth and on the size of its installed base. It carries ISO 27001, SOC 2 Type 2, CSA STAR Level 1 and three active NIST cryptographic-module validations for its firewalls, all credentials a funded rival can also earn. It bought the classification technology it now leads with. Forcepoint acquired Getvisibility in April 2025, after more than two years of partnering with it to deliver those capabilities. The reviewed sources name no exclusive dataset behind that technology. The concrete form of that breadth is 1,800 prebuilt policy templates and classifiers spanning 160 regions, which a customer configures. The 12,000 customers it counts are a head start rather than a lasting lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Forcepoint delivers software the customer configures and uses, streamlining policy configuration with 1,800 classifiers and policy templates, as a cloud service or an on-premises install. Pricing goes through a sales request, and the customer's team owns the outcomes, which is the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The record documents what rung 2 names, with one policy applied across cloud, web, email, endpoint and network, deployments split between the cloud and on premises, and a library of 1,800 prebuilt policy templates and classifiers the customer configures. No qualifying rung-3 mechanism appears, no source shows the tuned baselines are non-portable, and none sizes an exit. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Forcepoint records ISO/IEC 27001:2022, SOC 2 Type 2 and CSA STAR Level 1 on its trust center, and NIST lists three active Forcepoint cryptographic-module validations. A funded competitor can obtain each of those through ordinary enterprise preparation, and no cited source shows a buyer requiring equivalent validation from a replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Inspecting AI prompts and responses inline, and classifying data with a network of task-specific AI models, is real-time and machine-learning work. Forcepoint also builds firewall appliances whose cryptographic modules passed laboratory validation, which is specialized engineering rather than configuration. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Named customers include two insurers, a manufacturer, a university and an energy company, and Forcepoint says it serves 485 of the Forbes Global 2000. Procurement and compliance functions sit between that buyer and a replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Forcepoint sells a platform that carries one policy across channels, alongside application-level products such as browser isolation. Nothing in the reviewed sources shows other applications depending on Forcepoint as infrastructure. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Forcepoint calls the AI Mesh classification architecture proprietary and its acquisition announcement described the technology as patented, but the reviewed sources give no patent identifier, name no non-public dataset and name no cross-customer asset behind it. Forcepoint bought that technology rather than building it, and no source in the record shows the models would be hard to recreate. |
Forcepoint aims at the security team responsible for keeping regulated information inside the organization. It publishes a compliance document for the EU DORA rules and a product-level HIPAA document, and it says it serves 485 of the Forbes Global 2000.
The named references show the shape of that base. FBD Insurance, HUBER+SUHNER, Liberty University, ERG and HDI Seguros span insurance, manufacturing, education and energy.
The segment is narrower than it was. Until October 2023 Forcepoint also sold to defense, intelligence and critical national infrastructure through its Global Governments and Critical Infrastructure business, and TPG now owns that business under the Everfox name. Forcepoint still names government among the sectors it serves today.
The Forcepoint name is newer than the businesses behind it. A deal Raytheon and Websense announced in 2015 formed a new company combining Websense with Raytheon Cyber Products, and the brand was unveiled in 2016.
Forcepoint applies one set of data controls across several channels. Forcepoint DLP covers cloud, web and network, Forcepoint DSPM discovers and classifies stored data, Forcepoint DDR watches data activity, and web, cloud application, email, browser isolation and malware analysis products sit alongside them.
The AI work sits on top of that. Forcepoint launched a platform it calls AI Data Security in July 2026 and says it inspects prompts and AI-generated responses inline. It said the detection and response piece, with its connectors to ChatGPT Enterprise, Microsoft Copilot, Claude Enterprise and AWS Bedrock, the agent gateway and the shadow-AI controls, would arrive on a rolling basis over the following quarter.
Forcepoint bought the classification engine underneath. It acquired Getvisibility in April 2025 after more than two years of partnership, and it now describes the resulting AI Mesh as its own approach to discovery, classification and tagging, deployable on-premises and in public or private clouds.
Forcepoint names its customers and used its partner community for the launch. It brought the July 2026 AI platform to market through that community, with the agent gateway and shadow-AI controls scheduled over the following quarter, and it lets existing customers add those features to what they already run.
Independent reporting of scale in the reviewed sources predates the split. Cybersecurity Dive wrote in July 2023 that Forcepoint said it had nearly 3,000 employees and served more than 14,000 customers across 150 countries. Forcepoint now states more than 12,000 customers and more than 1,400 employees.
The analyst signal reaches a reader through the company. Forcepoint announced a Leader placement in the IDC MarketScape for Worldwide Data Loss Prevention in March 2025, and the reviewed sources carry that announcement rather than the assessment itself, so a buyer checking the placement starts with the vendor.
Forcepoint does not publish a price on its DLP product page. That page offers a Start Today link and a Request Pricing link, which puts the number behind a sales conversation.
The company describes the commercial benefit in operating terms instead. It says customers extending protection into AI on the platform they already run reduce data security policy management by up to 90 percent and see a 31 percent drop in operating costs, both figures of its own.
Forcepoint lets the buyer choose where the controls run. Forcepoint DLP deploys in the cloud as a service or on premises, Forcepoint DSPM deploys on-premises and in public or private clouds, and the July 2026 platform is delivered from the cloud or on-premises.
Both vulnerabilities in the reviewed record concern the endpoint client. Triskele Labs found that the EndPointClassifier.exe process tried to load an OpenSSL configuration file from a path that did not exist and that any authenticated user could create, and CERT/CC recorded that code execution in the DLP client could let an attacker bypass data loss prevention enforcement, alter client behavior or disable security monitoring.
Forcepoint fixed both. It released version 25.05 with an advisory on 22 May 2025, and it removed the bundled Python runtime from endpoint builds after version 23.11.
Forcepoint runs a public trust center and records what it holds there. The portal lists ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, SOC 2 Type 2, CSA STAR Level 1 and FIPS 140-3, with separate SOC 2 Type 2 reports for Forcepoint ONE, Cloud DLP, Cloud DSPM and Cloud Web, plus dynamic application security testing and external penetration test reports in its document inventory.
One of those claims is verifiable without the vendor. NIST lists three active Forcepoint certificates in its validated cryptographic module program, numbered 5276, 4867 and 4835, covering firewall hardware and a firewall cryptographic kernel.
Forcepoint offers access requests for its ISO Statement of Applicability and its SOC 2 assessments. No independently published audit report for the data security products appears in the reviewed sources, so a buyer has to ask Forcepoint for them.
Forcepoint builds around other vendors' platforms rather than asking buyers to leave them. Its DLP page offers to bolster Microsoft Purview across the Microsoft 365 family of applications, and it says connectors to ChatGPT Enterprise, Microsoft Copilot, Claude Enterprise and AWS Bedrock will arrive with the detection and response piece over the quarter after the July 2026 launch.
That choice cuts both ways. Microsoft enforces data loss prevention policies across cloud apps, email, devices and AI from the Purview portal, so the coverage Forcepoint sells there is an addition to a control the buyer may already own.
The network products stand apart from this pattern. Forcepoint NGFW and Forcepoint Secure SD-WAN sit outside the data-security framing, and the independently published technical validation in the reviewed record covers the cryptographic modules inside Forcepoint NGFW.
Forcepoint publishes its executive team and its board. Ryan Windham is chief executive officer, Matt Derdeyn chief financial officer, Bakshi Kohli chief technology officer and head of global engineering, Guy Shamilov chief information security officer and Juha Kivikoski general manager for network security.
Forcepoint promoted Windham from inside. It moved him up from chief customer and strategy officer in July 2024, succeeding Manny Rivelo, and says he was chief executive at AppViewX and at Cedexis and held senior positions at Imperva, F5 Networks and Websense.
Francisco Partners bought Forcepoint in 2021 and said in October 2023 that it continues to own the commercial business. Andrew Kowal, the Francisco Partners partner who spoke for the firm when it agreed to the purchase in October 2020 and again when Windham was promoted, is listed among Forcepoint's directors.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Forcepoint homepage: single-policy enforcement across AI, cloud, web, email, endpoint and network | official | 2026-08-16 |
| f2 | SecurityWeek, January 11, 2021: PE Firm Completes Acquisition of Forcepoint | press | 2026-08-16 |
| f3 | Forcepoint newsroom, July 22, 2026: AI Data Security launch | official | 2026-08-16 |
| f4 | Forcepoint products page: portfolio listing across AI, data and network security | official | 2026-08-16 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.