Auditor's Perspective: Data Leakage Prevention (DLP)

Here at ACTIVECYBER, we work with organizations across a wide range of industries, which gives us the opportunity to assess many different technologies, business processes, and environments. We're grateful for that experience because:

  1. Our consulting expertise continuously expands, and the value we provide to our clients grows along with it.

  2. It allows us to identify common issues and emerging trends that we can carry forward into future engagements.

A common misconception we see during our engagements — especially around ISO 27001:2022 — is that effective Data Leakage Prevention (DLP) controls can be achieved solely through outbound email restrictions.

They can't.

When we assess the ISO 27001:2022 DLP control (Annex A.8.12), we often start the conversation with one simple question: If your company's most sensitive information tried to leave your environment today, would you know about it? Could you stop it?

Start With What You're Protecting

The first step isn't implementing new DLP technology — at least, not yet. It's understanding what sensitive information you're trying to protect by identifying and classifying it. Examples include:

  • Client/customer data

  • Employee PII

  • Source code

  • Financial information

  • Product designs and proprietary business information

Once that identification and classification work is done, the next step is understanding where that information is stored and how it leaves your internal boundaries. Common locations and channels include:

  • Email systems

  • Cloud storage platforms (e.g., OneDrive, SharePoint, Dropbox, Google Drive, S3)

  • HR and payroll platforms housing employee data

  • Collaboration tools (e.g., Microsoft Teams, Slack, Google Chat)

  • File shares, company-issued laptops, and removable media

Understand How It Could Be Leaked

Once you know where sensitive data lives, the next question is: How could that information be leaked?

Data leakage isn't always malicious. It can happen through personal email accounts, unauthorized access to cloud storage, a lack of removable media restrictions, VPN connections, or file transfer protocols such as SMB, SFTP/FTP, SSH, and proxy services. Less commonly, it can also occur through the improper handling or removal of physical information.

Implement the Right Technical Controls

With a clearer picture of the data you're protecting and the paths it could travel, organizations should implement technical controls to detect and prevent unauthorized disclosure. Examples of effective DLP controls include:

  • Blocking emails containing sensitive information using tools such as Microsoft Purview DLP or other secure email gateways that inspect, quarantine, or block emails containing confidential data.

  • Restricting uploads to unauthorized cloud storage through solutions like Microsoft Defender, Netskope, or Zscaler to help prevent uploads to personal or non-approved storage apps.

  • Blocking or monitoring USB and other removable media usage through endpoint management tools such as Microsoft Intune or Jamf to help prevent unauthorized copying of sensitive information.

  • Monitoring file transfers across approved and non-approved channels using next-generation firewalls, secure web gateways, or network DLP solutions.

  • Applying labels and encryption (where appropriate) using tools such as Microsoft Purview Information Protection to classify and protect sensitive information automatically.

  • Ensuring existing SIEM or UEBA tools are properly configured to alert administrators to activities such as mass downloads, excessive file sharing, or potential data exfiltration.

Don't Forget About AI

Everything above is essential when building out sufficient DLP controls — but there's another piece that's become a growing concern: What about AI?

As AI adoption in the workplace continues to grow, it's become an increasingly important part of the DLP conversation. AI tools can significantly boost productivity and are becoming more widely accepted for everyday use — but companies should still consider controls that:

  • Restrict access to unapproved AI platforms by blocking unauthorized AI websites or whitelisting approved AI platforms that users can install on their workstations.

  • Prevent sensitive information from being submitted into AI tools by configuring policies to detect and block certain data from being pasted or uploaded into AI applications.

  • Establish clear guidance on what can and cannot be shared by implementing an AI Acceptable Use Policy — or refining existing policies — and requiring employees and contractors to acknowledge these usage commitments.

The Bottom Line

At ACTIVECYBER, we believe successful DLP implementation comes down to three things:

  1. Understanding what sensitive data requires protection.

  2. Understanding how that information moves in and out of your environment.

  3. Ensuring the proper technical and administrative controls are in place to reduce the risk of unauthorized disclosure.

Next
Next

Small Steps Create Big Shifts