602-725-2818AZ Licensed & InsuredSchedule a Consultation
Call 602-725-2818Consultation

Honeybadger Solutions LLC

Most data loss is not theft, and why DLP deployments fail

The majority of data leaves an organisation through ordinary work, not malice — which is exactly why so many DLP rollouts get switched off.

Most data loss is not theft

The picture people have of data loss is a departing employee copying a client list to a USB stick. That happens, and it is not the common case. The common case is ordinary: an email sent to the wrong Sarah, a spreadsheet attached with the hidden columns still in it, a sharing link set to “anyone with the link” because that was the fastest way to get somebody unblocked on a Friday, a document uploaded to a personal cloud account so it could be finished at home, a chat message with a customer record pasted into it.

That distinction decides how a programme should be built. Controls designed to catch a determined thief are hostile, expensive and easy to route around. Controls designed to catch a rushed person about to make a mistake are cheap, well received, and prevent most of what actually goes wrong — while still catching a good deal of the deliberate activity, because deliberate exfiltration usually uses the same routes.

Why DLP deployments fail

This technology has a poor reputation and it is largely earned. Three failure patterns account for most of it.

Deployed before anyone knows what the data is. A tool configured against generic patterns in an organisation that has never inventoried its sensitive information will generate enormous volumes of noise, because it is guessing. Discovery and classification come first, and they are the unglamorous part everybody wants to skip.

Switched to blocking too early. A policy that blocks legitimate work on day one teaches the entire workforce that the security tool is an obstacle, and they will find the route around it within a week — usually a personal device or a personal account, which is worse than what you were preventing.

Nobody owns the alerts. A policy that fires into an unwatched queue is not a control, it is a log. And a queue full of false positives will be ignored even when it is watched, which means the real event arrives into a noise floor.

The sequence that works is unexciting and reliable: discover, classify, monitor in audit mode, tune against reality, warn users, and only then block the narrow set of things worth blocking.

What Honeybadger Solutions provides

Honeybadger Solutions is an Arizona-licensed security guard and private investigations agency — Guard 1759798, PI 1759795 — with investigations, digital forensics and cyber work delivered nationwide. This article is background on the problem. For what we actually provide, see Data Loss Prevention, or book a confidential consultation.