Data Loss Prevention (DLP)
Discovery and classification of sensitive data, with controls that stop it leaving by mistake or on purpose, plus database and file monitoring.
- NIST CSF 2.0 functions
- Protect Detect
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Sensitive data spreads quickly: customer records copied into spreadsheets, reports sent to personal email, database exports left on shared drives. You cannot protect what you cannot find.
We help you locate sensitive data, decide how it should be handled and put controls in place that protect it without stopping the business.
What you get
- Knowledge of where sensitive data is stored and who can reach it
- Policies that stop sensitive data from leaving by mistake or on purpose
- Monitoring of access to critical databases and files
- Evidence for data protection and card data requirements
What we cover
- Data discovery and classification
- Data loss prevention for email, endpoints, web and cloud
- Information protection and rights management
- Database activity monitoring
- File integrity monitoring for critical systems
Leading platforms
Established platforms in this category. We help you compare them against your requirements.
- Microsoft
- Forcepoint
- Varonis
- Proofpoint
How we work
-
Discover
We find and classify sensitive data across file shares, databases, email and cloud services.
-
Define policy
We agree classification labels and handling rules with business, legal and compliance owners.
-
Monitor first
We deploy controls in monitoring mode to learn real data flows without blocking business.
-
Enforce
We move to blocking in stages, with clear user messages and an exception process.
-
Hand over
We train administrators and incident handlers and document every policy.
Deliverables
- Data inventory and classification scheme
- Data protection policy set
- Deployed and tuned controls
- Incident handling procedure for data loss alerts
- Administrator training
Questions buyers ask
Will DLP block normal work?
Not if it is introduced carefully. We start in monitoring mode, tune the rules with business owners and only then begin blocking.
Does this help with PCI DSS?
Yes. Discovery, monitoring and file integrity controls support several PCI DSS requirements for protecting cardholder data.
Related offerings
-
Governance, Risk and Compliance
Security policies, risk management and compliance processes that meet regulator expectations and work in daily operations.
NIST CSF function: Govern -
Compliance Readiness
Preparation for ISO/IEC 27001, PCI DSS, SWIFT CSCF and other requirements, from gap analysis to audit support.
NIST CSF function: Govern -
Identity & Access Management (IAM)
Identity and access management with single sign-on, so the right people reach the right systems and access is granted and removed through a clear process.
NIST CSF function: Protect -
Encryption
Encryption for data at rest and in transit, designed so that a stolen disk, database copy or network capture is of no use to an attacker.
NIST CSF function: Protect