What You Can Do Without a DLP Product
- kind
- Checklist
- domain
- Procurement
- stage
- Context
- read
- 2 min
- assumes
- No prior programme in place
A substantial share of real exposure is addressable with capabilities most organisations already own and do not use.
Before committing to a platform and its operating burden, it is worth knowing how far the existing estate goes. For many organisations it is further than expected.
What you probably already have
Cloud platform audit logs. Your email and file services record external sharing, forwarding rule creation, bulk download, guest access and third-party app grants. This is the richest untapped source in most organisations, and it requires ingestion and review rather than purchase.
Mail platform controls. Alerting on external forwarding rules. Warning banners on external recipients. Restrictions on auto-forwarding entirely. All standard, all frequently unconfigured.
Sharing defaults. Changing the default from "anyone with the link" to "specific people" prevents more exposure than most detection rules catch.
Application audit logs. CRM, HR, finance and reporting platforms log exports with user, timestamp and record count. Better evidence than any content inspection, and generally uncollected.
Identity and access tooling. Access reviews, group membership reports, privileged access records. The reports exist; running and acting on them is the gap.
Endpoint management. Removable media policy, disk encryption verification, software inventory. Present in most estates.
Code platform controls. Push protection to personal repositories, restrictions on making repositories public, clone and fork audit.
The programme that uses only these
Reduce access. By data category, with a review at role change and a scheduled cycle.
Restrict sharing defaults across cloud platforms.
Alert on forwarding rules. Near-zero false positives, covers compromise and exfiltration.
Review external sharing monthly. Particularly public links, which accumulate silently.
Collect application export logs for the two systems holding your most sensitive categories, and baseline them.
Block or restrict removable media.
Run the departure process properly, including the conversation about ownership.
Verify disk encryption across the estate.
That covers a large proportion of realistic exposure. None of it requires a new product, and all of it survives a budget freeze.
What it does not cover
Being honest about the gap is what makes the argument credible:
Content awareness. You will not know a document contains customer data unless the system it came from tells you.
Endpoint activity beyond removable media. Clipboard, paste into browsers, screenshots, local file operations.
Real-time intervention. No warning at the moment of action, which is the highest-value control available and the main reason to buy something.
Unsanctioned services. Shadow IT is visible in network logs at best.
Correlation. Signals from separate systems stay separate without something joining them.
When the product becomes justified
When you have someone to operate it. Capacity first, always.
When you need the pre-send warning. This is the strongest single argument for purchase, because it prevents rather than records, and nothing in the existing estate provides it.
When content classification matters and location-based rules are insufficient.
When the volume of manual review exceeds what people can sustain, which is the honest trigger for automation.
The sequence that avoids waste
Do the free things first, for two quarters. You will learn what your actual exposure is, which channels carry it, and how much review capacity you genuinely have.
Then buy against that knowledge rather than against a vendor's framing of the problem. The requirements document written after six months of your own audit logs is a completely different document from the one written before.