Data Loss Prevention
Data loss prevention (DLP) detects and prevents sensitive information from leaving an organization through unauthorized channels. It uses content inspection, context-aware policies, and enforcement actions to stop accidental or malicious exposure of confidential data.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Data Loss Prevention
Data loss prevention, mercifully shortened to DLP, is the set of controls that find sensitive data and govern how people and systems use or send it. Despite the name, it has nothing to do with backups or disaster recovery. It is about confidentiality: keeping a readable copy from reaching someone who should not have one.
The problem it exists for is annoying precisely because it has no clean solution. Sensitive data has to stay available for real work, and that same access is what lets it leak. Someone picks the wrong email recipient. A compromised account downloads records. A departing employee copies files to a USB stick. A laptop is left on a train. Before DLP, the answer was mostly "write a policy and hope"; DLP adds a system that actually watches the handling points and can act.
Three ideas carry the rest. First, a DLP decision is really five questions: what data is this, where is it, who is acting, what are they doing, and what should happen. Second, data lives in three states, and coverage should span all of them: at rest in storage, in motion across a network or email, and in use on an endpoint while it is copied, pasted, or printed. Third, enforcement is a spectrum, from silently recording an event, through warning the user or asking for a justification, up to blocking or quarantining. You start at the quiet end, in audit or simulation mode, and tighten only once you understand what real work you are about to break.
The thing that surprises people: the classifier does not make the decision. A payment-card number sitting in an approved finance system is fine. The exact same number pasted into a public upload is not. Content without context is just noise, and a rule that ignores context generates a great deal of it. The related trap, covered in Field Notes, is treating DLP as a product you install rather than an operation you staff. If nobody reviews the alerts and tunes the detectors every week, the tool quietly becomes an expensive log that no one reads.
Where to go next. The intro builds the full model and the program sequence. The cheatsheet is the decision table, the enforcement ladder, and the tuning signals in dense form. The slides are the same map, drawn. Field Notes covers what teams reliably get wrong. The practice reference and exercise walk you through building a tiny detector and policy engine on synthetic data, which is the fastest way to feel why precision and recall matter here. The quiz checks that it stuck.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/glossary/term/data_loss_prevention
Supports
- DLP identifies, monitors, and protects data at rest, in motion, and in use
- DLP uses content inspection and transaction context to prevent unauthorized use and transmission
- https://www.nccoe.nist.gov/publication/1800-28/VolA/index.html
Supports
- Data confidentiality means preventing unauthorized disclosure during storage, processing, and transit
- Breaches can cause operational, financial, and reputational impacts
- Identification and protection complement detection, response, and recovery
- https://www.nccoe.nist.gov/publication/1800-28/VolB/index.html
Supports
- Data inventory, protection, access control, policy enforcement, logging, and network protection work together
- Accidental email, lost device, compromised credentials, malware exfiltration, and privilege misuse are confidentiality scenarios
- Digital confidentiality loss cannot be reliably undone after an unauthorized party receives the data
- Technical means cannot completely stop every determined malicious insider
- Security monitoring and protection can create privacy risks that require data-flow awareness, minimization, access control, and lifecycle management
- https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
Supports
- DLP policies combine content analysis, locations, activities, and protective actions
- Detection can use keywords, regular expressions, validation, proximity, and machine learning
- Actions can warn, allow justified override, block, quarantine, log, and alert
- Simulation, testing, tuning, user training, and business-process input precede restrictive deployment
- DLP reporting and alerts support investigation and policy tuning
- Microsoft Purview DLP enforces policy across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and the Edge browser
- https://learn.microsoft.com/en-us/purview/dlp-overview-plan-for-dlp
Supports
- Planning starts with stakeholders, sensitive information categories, business processes, goals, and strategy
- https://learn.microsoft.com/en-us/purview/dlp-create-deploy-policy
Supports
- Policy implementation covers intent, scope, conditions, actions, notifications, simulation, tuning, and production use
- https://dealroom.co/companies/vontu
Supports
- Vontu was founded in 2001 in San Francisco by Joseph Ansanelli and Michael Wolfe
- Vontu built policy-based software to address internal data leakage across data at rest, in motion, and in use
- https://www.techmonitor.ai/technology/symantec_to_acquire_vontu_for_350m
Supports
- Symantec announced the acquisition of Vontu for 350 million dollars in November 2007
- Vontu's product was described as the first to combine endpoint and network technology to discover, monitor, and protect data
- https://www.commsbusiness.co.uk/content/news/symantec-completes-acquisition-of-vontu
Supports
- Symantec completed its acquisition of Vontu at the end of November 2007
- https://securosis.com/blog/dlp-acquisitions-the-good-the-bad-and-the-whatever/
Supports
- The 2006 to 2008 period saw DLP vendors acquired by larger security companies including McAfee, Websense, EMC, and Symantec
- Websense acquired PortAuthority and EMC acquired Tablus during the consolidation wave
- https://www.helpnetsecurity.com/2008/08/15/mcafee-completes-acquisition-of-reconnex/
Supports
- McAfee completed its 46 million dollar acquisition of Reconnex on 15 August 2008
- Reconnex technology was planned for integration into McAfee ePolicy Orchestrator
- https://securosis.com/blog/understanding-and-selecting-a-dlp-solution-part-2-content-awareness/
Supports
- Content awareness is the single most important technology in a DLP solution
- Rules and regular expressions have high false positive rates and little protection for unstructured content
- Database fingerprinting and exact data matching achieve near-zero false positives but depend on a current authoritative extract of the real data
- Partial document matching and statistical analysis need a maintained corpus of source content
- https://learn.microsoft.com/en-us/exchange/data-loss-prevention-exchange-2013-help
Supports
- Exchange Server 2013 introduced built-in DLP policy templates, transport-rule conditions, and policy tips
- https://www.microsoft.com/en-us/microsoft-365/blog/2015/04/21/evolving-data-loss-prevention-in-sharepoint-onlineonedrive-for-business-and-office-applications/
Supports
- Microsoft began previewing DLP for SharePoint Online and OneDrive for Business in April 2015
- https://www.microsoft.com/en-us/microsoft-365/blog/2015/09/30/data-loss-prevention-in-onedrive-for-business-sharepoint-online-and-office-2016-is-rolling-out/
Supports
- Microsoft began the general rollout of DLP across OneDrive for Business, SharePoint Online, and Office 2016 in September 2015
- https://www.endpointprotector.com/blog/the-story-of-the-missing-gartner-magic-quadrant-for-enterprise-dlp/
Supports
- Gartner published its last Magic Quadrant for Enterprise Data Loss Prevention in 2017
- Gartner retired the Magic Quadrant in 2018 and replaced it with a Market Guide for Data Loss Prevention
- Gartner's shift reflected DLP increasingly delivered as an integrated feature of other security products
- https://www.gartner.com/en/documents/6342779
Supports
- Gartner publishes a Market Guide for Data Loss Prevention in place of a Magic Quadrant
- https://www.broadcom.com/company/news/financial-releases/52706
Supports
- Broadcom completed its acquisition of Symantec's enterprise security business, including Symantec DLP, in November 2019
- https://www.meritalk.com/articles/broadcom-completes-acquisition-of-symantecs-enterprise-security-division/
Supports
- Broadcom acquired Symantec's enterprise security division for 10.7 billion dollars and the former parent became NortonLifeLock
- https://alberthoitingh.com/2020/09/23/announcements-from-ignite-2020-information-protection/
Supports
- Microsoft announced Endpoint DLP for Windows 10 at Ignite in September 2020
- Endpoint DLP covers USB copy, network shares, cloud uploads, printing, and clipboard monitoring
- https://learn.microsoft.com/en-us/purview/endpoint-dlp-learn-about
Supports
- Endpoint DLP extends Microsoft 365 DLP policy evaluation and protective actions to managed devices
- https://www.prnewswire.com/news-releases/helpsystems-acquires-enterprise-data-loss-prevention-leader-digital-guardian-301409820.html
Supports
- HelpSystems announced the acquisition of Digital Guardian in October 2021
- Digital Guardian provides enterprise DLP with a managed service that runs alert triage for customers
- https://www.fortra.com/resources/press-releases/helpsystems-welcomes-digital-guardian
Supports
- HelpSystems, later renamed Fortra, integrated Digital Guardian into its data-security portfolio
- https://consilien.com/news/data-loss-prevention-best-practices
Supports
- A rule for nine-digit numbers matches purchase orders, part numbers, and tracking codes as well as Social Security numbers
- The reviewed false-positive rate should fall every month for the first six months, and a flat rate indicates no one is tuning
- Someone must own the alert review queue or a DLP deployment produces false confidence rather than reduced risk
- Data discovery and classification must precede enforcement
- https://www.forcepoint.com/blog/insights/data-loss-prevention-best-practices
Supports
- Running DLP in audit mode first shows the real-world effect of policies before they touch user workflows
- Treating every incident as a critical breach causes alert fatigue and a team that stops trusting its own tools
- A file blocked from email can still leave through personal cloud storage, chat, an unmanaged device, or a generative AI prompt
- A mature DLP deployment becomes less burdensome over time as policies are tuned to the real data environment
- https://www.cyera.com/blog/the-rise-fall-and-rebirth-of-data-loss-prevention
Supports
- Early DLP was built for on-premises networks, storage, and endpoints and did not adapt well to cloud adoption
- DLP is more effective on structured data than on unstructured data shared across email, cloud storage, and collaboration tools
- Cloud DLP and CASB-integrated DLP emerged as partial, fragmented responses to the cloud shift
- https://www.forcepoint.com/blog/insights/radicati-data-loss-prevention-dlp-market-quadrant-2024-top-player
Supports
- Forcepoint was named a Top Player in the Radicati Group Data Loss Prevention Market Quadrant 2024
- https://www.fortra.com/blog/top-10-enterprise-data-loss-prevention-dlp-vendors-2026
Supports
- The enterprise DLP market splits between on-premises-rooted suites and cloud-native or security-service-edge platforms
- Microsoft, Broadcom (Symantec), Forcepoint, Trellix, Fortra Digital Guardian, and GTB Technologies are recognized enterprise DLP vendors
- https://www.gartner.com/reviews/market/data-loss-prevention
Supports
- Data Loss Prevention is an established software market with multiple competing enterprise and platform-native products
- https://cloud.google.com/security/products/sensitive-data-protection
Supports
- Google Sensitive Data Protection discovers, classifies, and de-identifies sensitive data in storage, BigQuery, and content streams
- https://microsoft.github.io/presidio/
Supports
- Microsoft Presidio is an open-source library for detecting and anonymizing personal data in text and images using NER, regex, and checksum validators
