Index / Detection and tuning

Endpoint and Removable Media

kind
Reference
domain
Endpoint
stage
Detection and tuning
read
3 min
assumes
No prior programme in place

What the agent sees that the network cannot, and the controls that are worth the friction.

Endpoint agents see activity that never touches the network: files copied to a USB drive, documents printed, content pasted between applications, screenshots taken. That visibility is the reason endpoint DLP exists, and it comes with the highest privacy cost of any deployment surface.

What the agent can see

File operations. Copy, move, rename, delete — including to removable media and to local sync folders.

Removable media. Device connection, and what is written to it.

Printing. Document, page count, printer.

Clipboard. Content copied between applications, which matters for paste into browsers.

Application activity. Which applications handle which files.

Screenshots, on some products, and this is where the privacy question sharpens considerably.

Removable media: the clearest case

The most straightforward control in the entire field, because the options are limited and the signal is unambiguous.

Three positions:

Block entirely. Simplest, and viable in more organisations than assume otherwise. Cloud storage has removed most legitimate need.

Allow only encrypted enterprise devices. Issued, encrypted, tracked. Preserves the workflow for people who genuinely need it.

Allow with logging. Weakest, and the default in many deployments. Produces a record after the fact and prevents nothing.

If you do one endpoint control, do this one. The friction is low, the exceptions are enumerable, and the alternative is an entirely unobserved exit that fits in a pocket.

Printing

Consistently under-instrumented. A printed document is outside every digital control permanently.

Volume is the signal. Someone printing 400 pages in a week, when they normally print 20, is worth a question. Content inspection at the print job adds little; the volume anomaly does most of the work.

Follow-me printing — jobs released at the device with a badge — provides better attribution and reduces abandoned printouts, which is a separate and real exposure.

Clipboard and paste

Increasingly the route that matters, because it covers paste into web applications, chat and external AI assistants.

The control is delicate: blocking paste broadly breaks ordinary work. Monitoring paste of large volumes, or of content matching sensitive patterns, into browser destinations is narrower and more defensible.

The privacy cost

Endpoint agents see everything the person does on the device, including personal activity where personal use is permitted.

This is the deployment surface where transparency, scope limitation and access control matter most:

State what the agent collects, specifically, in the employee notice.

Exclude what you do not need. Most programmes do not need screenshot capture, keystroke logging or continuous screen recording. These features exist and are sold; deploying them changes the character of the programme from data protection to surveillance, and employees will characterise it that way accurately.

Restrict who can query endpoint data, and log the queries.

Consider personal devices carefully. Installing a monitoring agent on an employee's own device is a different proposition legally and ethically from one on a corporate asset.

The performance question

Agents consume resources, and a heavy one on an older machine produces a measurable productivity cost and a substantial amount of resentment.

Test on the oldest hardware in the estate, not the newest. The complaints will come from there, and they will be legitimate.

What endpoint does not solve

The device is still under the user's physical control. A photograph of the screen defeats every control listed here.

Endpoint coverage raises the effort and increases the record. It does not close the channel, and a programme presented to executives as closing it is setting up a difficult conversation later.