DLP · Insider risk · Detection engineering
Most data loss is not an attack
It is someone emailing a spreadsheet to their personal account before a holiday, or a departing employee taking what they consider their own work. This is a practical reference for building programmes that catch that without turning the organisation into a surveillance operation.
- 42 entries
- 5 kinds
- 18 domains
- 5 stages
Everything published here, grouped by where it fits in a programme. Written for the people who have to build and run this, not for a buyer audience.
Fundamentals07
What the terms mean, where data actually goes, and what has to exist before any tool helps.
- ExplainerFoundationsWhat DLP Actually Does, and What It Does NotData loss prevention is narrower than the name suggests. Understanding the boundary prevents mos
- ExplainerFoundationsThe Three Kinds of Insider RiskMalicious, negligent and compromised insiders need different detection and different responses.
- ReferenceDataData Classification: The Prerequisite Everyone SkipsYou cannot protect what has not been defined as worth protecting. Most classification schemes fa
- ReferenceDataWhere Data Actually LeavesAn honest inventory of exit routes, ranked by how much data moves through them and how well they
- ProcedureDataBuilding the Data InventoryKnowing where sensitive data lives is the prerequisite for every control that follows. Here is h
- ExplainerDataData at Rest, in Motion and in UseThe three states determine which controls are even possible. Most programmes cover one and assum
- ReferenceIdentityAccess Control as the First Insider ControlThe most effective insider risk measure is reducing how many people could cause an incident. It
Programme design09
Governance, legal constraints, staffing and the questions to settle before deployment.
- ProcedureProgrammeStanding Up an Insider Risk Programme: The First Ninety DaysThe sequence that works, and why buying the tool first is the most common way to fail.
- ReferenceLegalGovernance: Who Decides, Who Investigates, Who Sees WhatThe structural questions that determine whether a programme is trusted or resented, settled befo
- ReferenceLegalLegal and Privacy Constraints on Employee MonitoringMonitoring employees is a regulated activity in much of the world. The obligations that most com
- ProcedurePeopleWorking With HR and LegalThe relationships that determine whether findings lead to outcomes or sit in a queue.
- ReferenceAssuranceMetrics That Mean SomethingAlert counts and blocked events are the standard reporting and both are misleading. What to repo
- ReferenceIdentityPrivileged Users and AdministratorsThe smallest population, the highest consequence, and the one that can most easily obscure its o
- ReferencePeopleStaffing an Insider Risk FunctionThe roles a working programme needs, what one person can realistically cover, and where organisa
- ReferencePeopleAwareness That Actually Changes BehaviourAnnual training does not reduce incidents. The interventions that do are smaller, closer to the
- ReferenceSupply chainContractors, Third Parties and Supply Chain InsidersPeople with insider access who are outside your HR processes, your training, and usually your de
Detection and tuning11
Policy design, false positives, behavioural analytics and the major egress channels.
- ProcedureTuningPolicy Design: Start in Monitor Mode and Stay There Longer Than Feels ComfortableThe sequence from observation to enforcement, and why organisations that skip it end up enforcin
- ProcedureTuningThe False Positive ProblemEvery DLP deployment drowns at first. What causes it, how to reduce it, and why the usual respon
- ExplainerAnalyticsBehavioural Analytics: What It Can and Cannot Tell YouUser behaviour analytics is sold as detection of intent. It detects deviation from a baseline, w
- ReferenceEgressEmail and Web EgressThe most instrumented channels and still the largest source of incidents. What to watch and what
- ReferenceEndpointEndpoint and Removable MediaWhat the agent sees that the network cannot, and the controls that are worth the friction.
- ReferenceCloudCloud and SaaS Data MovementThe largest modern egress route and the least instrumented. Sharing links leave almost no trace
- ReferenceIPProtecting Source Code and Intellectual PropertyUnstructured IP is what content inspection is worst at, and frequently what matters most. What w
- ProcedureApplicationsDetecting Bulk Export From Systems of RecordThe highest-consequence movements start with someone downloading a large extract. The logs usual
- ProcedureAnalyticsAlert Enrichment: The Context That Makes Triage PossibleA raw alert is uninterpretable. The same alert with five fields of context takes thirty seconds
- ChecklistAssuranceTesting Your Own ControlsMost programmes have never verified that their detections fire. The ones that test find gaps imm
- ProcedureTuningDetection Engineering as a PracticeTreating detections as maintained artefacts rather than one-time configuration is what separates
Investigation and response06
Triage, evidence, escalation and the departing employee.
- ProcedureCaseworkTriage: Separating Mistakes From MaliceMost alerts are people doing their jobs. The triage question is which of the remainder needs a h
- ProcedureCaseworkInvestigation Practice and Evidence HandlingAn investigation that reaches the right conclusion by the wrong method is unusable. The practice
- ChecklistPeopleThe Departing EmployeeThe single highest-yield focus in insider risk, and the one with the clearest window for action.
- ProcedureCaseworkContainment: The First HourThe decisions taken before anyone understands the situation, and how to avoid the ones that dest
- ProcedureCaseworkPost-Incident ReviewThe review is where a programme learns, and it is routinely skipped because the case is closed a
- ReferenceCaseworkCommunicating an Incident InternallyWho needs to know, what they need, and the leaks that come from the response rather than the inc
Context09
Why deployments fail, what to ask vendors, and what the regulations actually require.
- AnalysisProgrammeWhy DLP Deployments FailThe failure modes are consistent enough to list. Most are decided before the product is installe
- ChecklistProcurementBuying DLP: What to Ask VendorsTwelve questions that separate a product that fits your problem from one that demonstrates well.
- ReferenceLegalWhat the Regulations Actually RequireDLP is frequently justified by compliance. What the common frameworks actually say, and what the
- AnalysisEvidenceRemote Work and Insider RiskDistributed working changed the exposure and the detection surface. What actually changed, as op
- ChecklistProgrammeInsider Risk in Small OrganisationsMost guidance assumes a security team and a budget. What to do with neither.
- AnalysisEvidenceWhy Public Insider Cases MisleadThe cases that become public are the unrepresentative ones, and building a programme around them
- ProcedureProgrammeBuilding the Business CaseThe arguments that get funded, the ones that get scrutinised, and the costs everyone omits.
- ChecklistProcurementWhat You Can Do Without a DLP ProductA substantial share of real exposure is addressable with capabilities most organisations already
- ReferenceAssuranceWhat a Mature Programme Looks LikeA description of the end state, so that intermediate stages can be judged against something othe