Data Security

DLP Policy Failures

DLP tuned to vendor defaults generates thousands of false positives — and gets ignored.

What it is

Data Loss Prevention controls prevent sensitive data from leaving through email, USB, web upload, cloud sync, and print channels. When DLP policies are deployed with vendor defaults rather than calibrated to the organisation's actual data classification and business workflows, false positive rates become unmanageable. Analysts stop acting on DLP alerts. The controls remain active but provide no practical protection. Ongoing fine-tuning is not optional — it is what makes DLP function as prevention rather than logging.

Attack techniques

  • Exfiltration via email attachment (T1048)
  • Upload to personal cloud storage (T1567)
  • USB drive data transfer (T1052.001)
  • Print-to-PDF and physical exfiltration
  • Web form data submission

Business impact

Effective DLP requires policies calibrated to specific classification tiers, channel risk levels, and business workflow exceptions. Generic policies provide the appearance of control without the substance.