Skip to main content
Oyoon Altaqnya

Data Loss Prevention (DLP)

Discovery and classification of sensitive data, with controls that stop it leaving by mistake or on purpose, plus database and file monitoring.

NIST CSF 2.0 functions
Protect Detect
Relevant for
  • Banking and financial services
  • Telecommunications
  • Government and public sector
  • Oil and gas

Overview

Sensitive data spreads quickly: customer records copied into spreadsheets, reports sent to personal email, database exports left on shared drives. You cannot protect what you cannot find.

We help you locate sensitive data, decide how it should be handled and put controls in place that protect it without stopping the business.

What you get

  • Knowledge of where sensitive data is stored and who can reach it
  • Policies that stop sensitive data from leaving by mistake or on purpose
  • Monitoring of access to critical databases and files
  • Evidence for data protection and card data requirements

What we cover

  • Data discovery and classification
  • Data loss prevention for email, endpoints, web and cloud
  • Information protection and rights management
  • Database activity monitoring
  • File integrity monitoring for critical systems

Leading platforms

Established platforms in this category. We help you compare them against your requirements.

  • Microsoft
  • Forcepoint
  • Varonis
  • Proofpoint

How we work

  1. Discover

    We find and classify sensitive data across file shares, databases, email and cloud services.

  2. Define policy

    We agree classification labels and handling rules with business, legal and compliance owners.

  3. Monitor first

    We deploy controls in monitoring mode to learn real data flows without blocking business.

  4. Enforce

    We move to blocking in stages, with clear user messages and an exception process.

  5. Hand over

    We train administrators and incident handlers and document every policy.

Deliverables

  • Data inventory and classification scheme
  • Data protection policy set
  • Deployed and tuned controls
  • Incident handling procedure for data loss alerts
  • Administrator training

Questions buyers ask

Will DLP block normal work?

Not if it is introduced carefully. We start in monitoring mode, tune the rules with business owners and only then begin blocking.

Does this help with PCI DSS?

Yes. Discovery, monitoring and file integrity controls support several PCI DSS requirements for protecting cardholder data.

  • Governance, Risk and Compliance

    Security policies, risk management and compliance processes that meet regulator expectations and work in daily operations.

    NIST CSF function: Govern
  • Compliance Readiness

    Preparation for ISO/IEC 27001, PCI DSS, SWIFT CSCF and other requirements, from gap analysis to audit support.

    NIST CSF function: Govern
  • Identity & Access Management (IAM)

    Identity and access management with single sign-on, so the right people reach the right systems and access is granted and removed through a clear process.

    NIST CSF function: Protect
  • Encryption

    Encryption for data at rest and in transit, designed so that a stolen disk, database copy or network capture is of no use to an attacker.

    NIST CSF function: Protect