How DLP prevents leaks: real cases from practice

Overview of typical data leakage scenarios and how the DLP system prevents them.

What is DLP?

Data Loss Prevention (DLP) is a set of technologies designed to prevent the unauthorized transfer of confidential information outside the organization. More than 60% of data leaks in Kazakhstan occur due to employee negligence.

Typical leak scenarios
Sending to a personal email

An employee sent a customer database to Gmail. DLP detected the file containing the IIN and banking details, blocked the sending, and notified the information security department.

USB drive

The departing manager tried to copy the customer database onto a USB drive. The DLP agent blocked the writing of files with confidentiality labels.

Cloud storage

The marketer uploaded the internal strategy to Google Drive. DLP suspended the transfer of the “For Official Use Only” document until approval.

Control channels

Network: email, web traffic, messengers, cloud services, FTP.

End points: USB, printers, clipboard, screenshots

Storage: file servers, databases, SharePoint.

The implementation of DLP in a large state-owned enterprise revealed more than 340 potential incidents in the first quarter, 12 of which were critical.

Implementation stages

1. Data audit — we identify confidential data and transmission channels.

2. Classification — marking documents according to levels.

3. Policies — rules for each level and channel.

4. Training — rules for working with confidential data.

5. Operation — monitoring, investigation, adjustment.

Другие статьи