Data Security
DLP Policy Failures
DLP tuned to vendor defaults generates thousands of false positives — and gets ignored.
What it is
Data Loss Prevention controls prevent sensitive data from leaving through email, USB, web upload, cloud sync, and print channels. When DLP policies are deployed with vendor defaults rather than calibrated to the organisation's actual data classification and business workflows, false positive rates become unmanageable. Analysts stop acting on DLP alerts. The controls remain active but provide no practical protection. Ongoing fine-tuning is not optional — it is what makes DLP function as prevention rather than logging.
Attack techniques
- Exfiltration via email attachment (T1048)
- Upload to personal cloud storage (T1567)
- USB drive data transfer (T1052.001)
- Print-to-PDF and physical exfiltration
- Web form data submission
Business impact
Effective DLP requires policies calibrated to specific classification tiers, channel risk levels, and business workflow exceptions. Generic policies provide the appearance of control without the substance.