Cyber Services
Data Loss Prevention
Strategy and technology preventing unauthorized access, transmission or loss of the information your business runs on.
Most data does not get stolen. It gets sent.
The dramatic version of data loss is an intruder exfiltrating a database. The common version is an employee attaching the wrong file, forwarding a client list to a personal address on their last week, or syncing a folder to unmanaged storage. Controls that only watch the perimeter never see any of it.
Data loss prevention starts by establishing what actually matters and where it lives, then applies policy and technology to how it moves. Where a loss has already happened, our investigations and forensics capability can establish what left, when, and by whose hand.
What is included
Data Discovery & Classification
What sensitive information exists, where it lives, and who currently holds access to it.
Policy & Controls
Governance, controls and compliance programs aligned to your business and regulatory requirements.
Egress Monitoring
Transmission of sensitive information monitored across mail, storage and endpoint channels.
Post-Incident Investigation
Where data has already gone, forensic examination establishes what left and the chain behind it.
What the work involves
Discovery. Finding where sensitive data actually is, which is never only where the policy says. File shares, mailboxes, cloud storage, collaboration platforms, endpoints, databases, and the departmental spreadsheet that has quietly become a system of record.
Classification. Deciding what matters and labelling it — regulated personal data, health or card data, source code, contracts, pricing, designs, customer lists. The labels have to be few and meaningful. A five-tier scheme nobody understands is a scheme nobody applies.
Policy design. Rules tied to real risk rather than to everything a tool can detect, with different treatment for internal movement, external sharing and personal accounts. The organisation’s own regulatory obligations shape this — HIPAA, PCI DSS, CMMC and contractual confidentiality commitments each imply different controls.
Channel coverage. Email, cloud storage and collaboration platforms, endpoint activity including removable media and printing, and web uploads. Coverage gaps are where the traffic moves to.
User experience. Warnings that explain rather than simply refuse, a route to proceed with justification where the business genuinely needs it, and a reporting path. A control people understand is a control people comply with.
Monitoring and response. Someone reviewing what fires, a defined escalation for the serious events, and a process for the insider risk cases where the pattern rather than the single event is the signal — which connects to monitoring and response and, where a person is the concern, to threat management.
The departure window
If an organisation does one thing beyond the basics, it should be this. The overwhelming majority of deliberate data theft happens in the final weeks of employment, and it is visible: unusual volumes of file access, downloads from systems the person rarely touched, sharing to a personal address, connecting removable media for the first time in a year, printing at volume.
A defined departure protocol — heightened monitoring from the point of notice, a documented review of the preceding period, and a preservation step before the device is reissued — catches most of it and preserves the evidence for the cases that matter. The preservation part is the one most often skipped, and it is the one that determines whether anything can be done afterwards. See digital forensics for what that involves and why reissuing the laptop first is the expensive mistake.
Privacy, and being straight with employees
Monitoring employee activity is lawful in most workplace contexts and it carries obligations, expectations and consequences for trust. Our position with clients is consistent: tell people what is monitored, in writing, in a policy they have actually seen. Scope it to business systems and business data. Do not extend it into personal devices and personal accounts without a properly considered basis. Handle what monitoring reveals proportionately, and remember that DLP will surface personal information about employees incidentally — how that is handled says more about an organisation than the policy document does.
Covert monitoring is a different decision with a different justification, appropriate to a specific investigation with proper authority rather than as a standing posture — see covert operations for how that is scoped, including the legal boundaries around employee protected activity.
How it is priced
Assessment and programme design are quoted per engagement from environment size, number of platforms and the state of any existing classification. Implementation support is quoted per phase. Ongoing monitoring and alert review runs monthly alongside managed detection.
Included: discovery, classification scheme design, policy design, phased rollout plan and user communication material. Quoted separately: tooling licences, implementation engineering, ongoing alert review, departure-window monitoring programmes, and forensic investigation where an incident occurs.
Frequently asked questions
We bought a DLP tool and it just makes noise. What went wrong?
Almost always that it was switched on before anyone established what the sensitive data actually is and where it lives. Discovery and classification first, then audit mode, then tuning, then enforcement. Skipping to enforcement is the standard failure and it is fixable.
Should we block or just monitor?
Monitor first, always. Blocking on day one teaches people the tool is an obstacle and they will route around it, usually onto a personal device — which is worse than what you were preventing. Block a narrow set of genuinely serious actions once the policy reflects how the business actually works.
What is the single highest-value control?
A departure protocol. Most deliberate data theft happens in the final weeks of employment and it is visible in access, download, sharing and removable media patterns. Heightened monitoring from notice, plus preservation before the device is reissued.
Can we monitor employees legally?
In most workplace contexts, yes, with obligations. Tell people in writing what is monitored, scope it to business systems and data, and handle what it reveals proportionately. Extending it into personal devices and accounts needs a properly considered basis, not an assumption.
Someone has already taken data. Is DLP the answer?
Not for that event — it is a control, not an investigation. What you need now is preservation and forensic examination to establish what left and by which route. Then DLP to stop the next one, informed by exactly how this one happened.
We are small. Is this overkill?
The tooling might be; the practice is not. For a smaller organisation, knowing where sensitive data lives, restricting external sharing defaults, and running a departure protocol delivers most of the benefit without a licence spend.
Who this is for
- Law firms
- Healthcare
- Financial services
- Corporate HR
- Departing-employee matters
- Regulated industries
- Government contractors
Scope your requirement
A short call establishes what information matters most, your regulatory obligations, and whether you are preventing a future loss or investigating one that has already occurred.
Background reading: Most data loss is not theft, and why DLP deployments fail