Data Loss Prevention (DLP)
Data Loss Prevention (DLP) detects and prevents confidential data from leaving an organisation without authorisation.
Data Loss Prevention (DLP) detects and prevents the unwanted exfiltration of confidential data. It monitors where sensitive information is stored, used and transferred.
How it works
DLP solutions identify sensitive data using patterns, keywords, and classifications. They also use fingerprints from specific documents. Common examples are credit card numbers, AHV numbers (Swiss social security numbers), and files labelled 'confidential'. Rules then define what happens: a warning, a block, or an alert. DLP works on endpoints, in emails, cloud services, and web traffic.
A practical example
An employee tries sending a client list to a private email. They want to work on it during the weekend. A DLP rule detects the file and blocks the email from being sent. The employee receives a notification on how to work via the company laptop. A security incident is thus avoided.
What to look out for
- Classify your data before you define any rules.
- Start in a monitoring-only mode to understand false alarms.
- Involve business departments. They know which data is sensitive.
- Cover cloud services and chat tools, not just email.
- Define who is responsible for handling DLP alerts.
Switzerland and regulation
DLP can help meet data security duties under the revFADP (revised Federal Act on Data Protection). At the same time, it evaluates employee-generated content. Its purpose and scope must follow employment and data protection law. Employees must also be informed about this monitoring. For banks, client data protection is relevant under banking secrecy rules.
Limitations
DLP primarily prevents accidental data leakage. A determined attacker with admin rights can bypass controls or encrypt data. To counter such attacks, you also need NDR, EDR, and cloud monitoring.
Typical mistakes
A common mistake is activating too many rules at once. The resulting flood of alerts means no one processes them. Another error is blocking actions without offering a permitted alternative. This often encourages users to find workarounds.
How we implement it
We integrate relevant DLP alerts into our SOC and correlate them with signals from identity and endpoints. This allows us to detect if an attack is behind a data exfiltration event.