Cloud Armor IT Consultancy logo

Forcepoint DLP for Defence Manufacturing: Protecting Design IP at Kalyani Rafael Advanced Systems (KRAS)

Defence Manufacturing · Kalyani Rafael Advanced Systems (KRAS)

Forcepoint DLP for Defence Manufacturing: Protecting Design IP at Kalyani Rafael Advanced Systems (KRAS)
At a glance
Client Kalyani Rafael Advanced Systems (KRAS) — a Kalyani Group & Rafael Advanced Defense Systems joint venture
Industry Defence manufacturing, Hyderabad, India
Solution Forcepoint enterprise Data Loss Prevention (DLP)
Delivered by Cloud Armor IT Consultancy Pvt. Ltd.
Scope Endpoint, email and removable-media data protection across the engineering and programme environment

The challenge

A defence joint venture handles some of the most sensitive commercial data that exists in Indian industry: weapon-system design files, programme documentation, supplier drawings and export-controlled technical data. For KRAS, the risk model is unforgiving — a single uncontrolled copy of a design file leaving the environment is not an IT incident, it is a programme and compliance event.

The security team needed data-level control that would satisfy both Indian defence-sector expectations and the governance standards of an international OEM partner — without slowing down the engineers who use CAD, PLM and simulation data all day.

What Cloud Armor delivered

The four layers of a DLP program that holds

  • Discovery and classification first. We mapped where design and programme data actually lived — engineering workstations, file shares, project folders — and built classification around the programme structure KRAS already used, so labels made sense to engineers.
  • Forcepoint DLP policy engineering. Fingerprinting of design-document families, strict removable-media control, print and clipboard governance, and channel policies for email and web — tuned to distinguish a legitimate supplier exchange from an exfiltration path.
  • OS-level validation. As with every Cloud Armor DLP rollout, policies were validated against real Windows workstation behaviour — clipboard, print spooling, browser process interaction — not just against the policy console. This is the layer where most DLP rollouts quietly fail.
  • Phased enforcement. Monitor-only first, then enforcement expanded group by group as false positives were engineered out — so blocking mode arrived without a single day of engineering downtime.

The outcome

  • Defence-grade design and programme data governed by enforcing DLP policies across endpoints, email and removable media
  • Data-handling controls that stand up to both Indian defence-sector review and international partner governance
  • A policy set engineers do not fight, because it was built around how they actually work

Why Forcepoint for this environment

For high-security, on-premises-heavy estates like defence manufacturing, Forcepoint's depth — document fingerprinting, granular endpoint channel control, and mature network integration — is exactly what the risk model demands. For cloud-first organisations we often recommend a different model entirely; see our Safetica cloud-native DLP deployment for Vedanta Power.


Handling data your business cannot afford to lose? Cloud Armor designs, deploys and operates DLP for defence, BFSI and pharma environments across India, UAE and the US. Talk to our engineers.

Facing something similar?

Talk to the engineers who delivered this one — we'll tell you honestly whether your problem looks the same or different.