Service · Cybersecurity

Data leak prevention (DLP)

The first decision is not which product to buy, it is the answer to a plain question: what exactly are we protecting? Without it, any tool will bury your administrator in alerts that nobody opens after the first month. So we begin with a short list, often a single page, of the information that genuinely matters: drawings and calculations from an engineering office, the pricing grid, the client file, personnel records. Rules for mail, sharing, removable media and printing come afterwards.

3 to 4
classification levels, not ten
Monitoring
several weeks before blocking
Rules
written for your own documents
USB
approved devices only

Where this service reaches

The sequence never varies: find the information, narrow the access, close the exits, then watch for breaches. Skipping the first step drains the meaning out of everything that follows.

Put your scope to an engineer

Classification

Information is sorted by value: public, internal, confidential, strictly confidential. Without that sorting everything is guarded the same way, which in practice means nothing is guarded well.

Device encryption

BitLocker on laptops and encrypted memory sticks. An encrypted laptop left on a train is a lost asset; the same laptop unencrypted is a breach to assess and possibly to report.

Removable media

A list of permitted devices, a record of what was plugged in, and a full block in the departments that handle sensitive material such as payroll or a medical reception desk.

Mail and sharing

Rules for attachments going outside, a lifetime for OneDrive and SharePoint sharing links, and automatic encryption of messages carrying bank details or social security numbers.

Protection rules

Sensitivity labels and policies in Microsoft Purview or an equivalent, written around your classification rather than copied from the generic template that ships with the product.

Handling alerts

A routine for what happens after something is caught, and a periodic report: what was stopped, by whom, and how each case was closed out.

The way an engagement runs

Blocking is only switched on once we understand how information really moves. Otherwise what we would mostly stop is ordinary work.

01

The crown jewels

We name the few per cent of data that truly matters: drawings and calculations, commercial terms, personnel records, health information.

02

Cheap measures

Laptop encryption, USB limits in the key departments, and a clear-out of sharing links opened three years ago and never revoked.

03

Monitor mode

Rules run without blocking for an agreed period, which shows where information actually travels, including routes nobody had pictured.

04

Enforcement

Blocking goes live once false alerts are rare enough that a real person can look at each one the same day.

A leak rarely looks like theft. More often it is a sales rep emailing the client list to a private mailbox a fortnight before resigning, or a payroll officer sending a salary table through a consumer messaging app because it was quicker. Well-built rules catch those moves before they turn into a case file.

Questions and answers

No, if they are written properly and have been through the monitoring phase. An ordinary invoice triggers nothing. We aim at genuinely sensitive patterns, such as a file holding dozens of social security numbers, not at every document carrying a company name.

Often partly. Several plans include information protection features and sensitivity labels, but how far they reach depends on the plan. We use what you already pay for first, and only raise the question of an extra tool for information of very high value.

Most of it is decided before that day: no copying to personal media, logging of bulk exports from the CRM, and prompt removal of access. If something has gone, the logs are evidence for your lawyer; the legal reading is entirely theirs.

Yes. The labour code requires people to be informed in advance and, in some cases, employee representatives to be consulted; the processing also belongs in your register. The tool looks for patterns rather than reading correspondence, but the wording and form of that notice should be settled with HR or your counsel. We describe the technical side.

The simple measures, encryption and removable media, take a few days. Content rules need the monitoring phase, often four to six weeks, so that blocking does not land in the middle of a perfectly legitimate delivery.

Keep your information where it belongs

Tell us which information matters most to you and what tools your teams work with. We will suggest the first steps.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.