DLP · Insider risk · Detection engineering
Most data loss is not an attack
It is someone emailing a spreadsheet to their personal account before a holiday, or a departing employee taking what they consider their own work. This is a practical reference for building programmes that catch that without turning the organisation into a surveillance operation.
- 42 entries
- 5 kinds
- 18 domains
- 5 stages
Where to start
If you have been told to deploy DLP and have not started, read what DLP actually does first, then data classification and building the data inventory. The tool cannot supply either, and deployments that skip them stall.
If a deployment is already generating unreviewable noise, go to the false positive problem and alert enrichment. The answer is almost never raising thresholds.
If you have no budget and no security team, read insider risk in small organisations and what you can do without a DLP product. A substantial share of real exposure is addressable with capabilities you already own.
If you are writing a business case, start with building the business case and what the regulations actually require. The compliance mandate you have been told about probably does not exist, and there are better arguments.
If someone has just done something and you are deciding what to do, read containment and triage before acting. Several of the obvious first moves destroy the case.
What this site takes as given
A few positions run through everything published here. They are stated plainly so you can disagree with them deliberately.
Most data loss is error, not malice. Someone emailing a spreadsheet home before a holiday, or sending the wrong attachment. Programmes designed around a sophisticated adversary drown in this and catch neither.
DLP is instrumentation, not a wall. It cannot stop a determined person with legitimate access, and any programme sold to executives as prevention will fail publicly at the first incident.
Access reduction outperforms detection. Reducing how many people could cause an incident is the only measure that changes the denominator. It is cheaper than monitoring, more effective, and consistently underfunded because it does not demo well.
The departure process is the highest-yield single intervention. Most real incidents involve someone leaving. It is the one scenario that comes with advance notice.
Monitoring employees is regulated. Transparency, proportionality, impact assessment and consultation are obligations in much of the world, not optional refinements. A programme that ignores them produces evidence a tribunal will not admit.
A programme that catches nothing may be blind rather than effective, and no metric distinguishes them. The honest response is to say so rather than substitute a number that implies otherwise.
What is not here
This site is written from the defender's side. It covers detection, programme design, investigation and compliance.
It does not publish material on evading data controls or moving information undetected, and it will not. That material helps one side of this problem, and it is not the side our readers are on.
Fundamentals07
What the terms mean, where data actually goes, and what has to exist before any tool helps.
- ExplainerFoundationsWhat DLP Actually Does, and What It Does NotData loss prevention is narrower than the name suggests. Understanding the boundary prevents mos
- ExplainerFoundationsThe Three Kinds of Insider RiskMalicious, negligent and compromised insiders need different detection and different responses.
- ReferenceDataData Classification: The Prerequisite Everyone SkipsYou cannot protect what has not been defined as worth protecting. Most classification schemes fa
- ReferenceDataWhere Data Actually LeavesAn honest inventory of exit routes, ranked by how much data moves through them and how well they
- ProcedureDataBuilding the Data InventoryKnowing where sensitive data lives is the prerequisite for every control that follows. Here is h
- ExplainerDataData at Rest, in Motion and in UseThe three states determine which controls are even possible. Most programmes cover one and assum
- ReferenceIdentityAccess Control as the First Insider ControlThe most effective insider risk measure is reducing how many people could cause an incident. It
Programme design09
Governance, legal constraints, staffing and the questions to settle before deployment.
- ProcedureProgrammeStanding Up an Insider Risk Programme: The First Ninety DaysThe sequence that works, and why buying the tool first is the most common way to fail.
- ReferenceLegalGovernance: Who Decides, Who Investigates, Who Sees WhatThe structural questions that determine whether a programme is trusted or resented, settled befo
- ReferenceLegalLegal and Privacy Constraints on Employee MonitoringMonitoring employees is a regulated activity in much of the world. The obligations that most com
- ProcedurePeopleWorking With HR and LegalThe relationships that determine whether findings lead to outcomes or sit in a queue.
- ReferenceAssuranceMetrics That Mean SomethingAlert counts and blocked events are the standard reporting and both are misleading. What to repo
- ReferenceIdentityPrivileged Users and AdministratorsThe smallest population, the highest consequence, and the one that can most easily obscure its o
- ReferencePeopleStaffing an Insider Risk FunctionThe roles a working programme needs, what one person can realistically cover, and where organisa
- ReferencePeopleAwareness That Actually Changes BehaviourAnnual training does not reduce incidents. The interventions that do are smaller, closer to the
- ReferenceSupply chainContractors, Third Parties and Supply Chain InsidersPeople with insider access who are outside your HR processes, your training, and usually your de
Detection and tuning11
Policy design, false positives, behavioural analytics and the major egress channels.
- ProcedureTuningPolicy Design: Start in Monitor Mode and Stay There Longer Than Feels ComfortableThe sequence from observation to enforcement, and why organisations that skip it end up enforcin
- ProcedureTuningThe False Positive ProblemEvery DLP deployment drowns at first. What causes it, how to reduce it, and why the usual respon
- ExplainerAnalyticsBehavioural Analytics: What It Can and Cannot Tell YouUser behaviour analytics is sold as detection of intent. It detects deviation from a baseline, w
- ReferenceEgressEmail and Web EgressThe most instrumented channels and still the largest source of incidents. What to watch and what
- ReferenceEndpointEndpoint and Removable MediaWhat the agent sees that the network cannot, and the controls that are worth the friction.
- ReferenceCloudCloud and SaaS Data MovementThe largest modern egress route and the least instrumented. Sharing links leave almost no trace
- ReferenceIPProtecting Source Code and Intellectual PropertyUnstructured IP is what content inspection is worst at, and frequently what matters most. What w
- ProcedureApplicationsDetecting Bulk Export From Systems of RecordThe highest-consequence movements start with someone downloading a large extract. The logs usual
- ProcedureAnalyticsAlert Enrichment: The Context That Makes Triage PossibleA raw alert is uninterpretable. The same alert with five fields of context takes thirty seconds
- ChecklistAssuranceTesting Your Own ControlsMost programmes have never verified that their detections fire. The ones that test find gaps imm
- ProcedureTuningDetection Engineering as a PracticeTreating detections as maintained artefacts rather than one-time configuration is what separates
Investigation and response06
Triage, evidence, escalation and the departing employee.
- ProcedureCaseworkTriage: Separating Mistakes From MaliceMost alerts are people doing their jobs. The triage question is which of the remainder needs a h
- ProcedureCaseworkInvestigation Practice and Evidence HandlingAn investigation that reaches the right conclusion by the wrong method is unusable. The practice
- ChecklistPeopleThe Departing EmployeeThe single highest-yield focus in insider risk, and the one with the clearest window for action.
- ProcedureCaseworkContainment: The First HourThe decisions taken before anyone understands the situation, and how to avoid the ones that dest
- ProcedureCaseworkPost-Incident ReviewThe review is where a programme learns, and it is routinely skipped because the case is closed a
- ReferenceCaseworkCommunicating an Incident InternallyWho needs to know, what they need, and the leaks that come from the response rather than the inc
Context09
Why deployments fail, what to ask vendors, and what the regulations actually require.
- AnalysisProgrammeWhy DLP Deployments FailThe failure modes are consistent enough to list. Most are decided before the product is installe
- ChecklistProcurementBuying DLP: What to Ask VendorsTwelve questions that separate a product that fits your problem from one that demonstrates well.
- ReferenceLegalWhat the Regulations Actually RequireDLP is frequently justified by compliance. What the common frameworks actually say, and what the
- AnalysisEvidenceRemote Work and Insider RiskDistributed working changed the exposure and the detection surface. What actually changed, as op
- ChecklistProgrammeInsider Risk in Small OrganisationsMost guidance assumes a security team and a budget. What to do with neither.
- AnalysisEvidenceWhy Public Insider Cases MisleadThe cases that become public are the unrepresentative ones, and building a programme around them
- ProcedureProgrammeBuilding the Business CaseThe arguments that get funded, the ones that get scrutinised, and the costs everyone omits.
- ChecklistProcurementWhat You Can Do Without a DLP ProductA substantial share of real exposure is addressable with capabilities most organisations already
- ReferenceAssuranceWhat a Mature Programme Looks LikeA description of the end state, so that intermediate stages can be judged against something othe