Service · IT security

Data loss prevention (DLP)

Information seldom leaves a business through hacking. Far more often it slips out along ordinary routes: an attachment forwarded to a private Gmail account for weekend work, a OneDrive link set to “anyone with the link” that never expires, a USB stick left on a train seat, or the departing sales rep who quickly exports the customer list on his last Friday. Take an engineering consultancy in Innsbruck: drawings, expert reports and bills of quantities for clients are its real capital, and they travel daily by email to specialist planners and contractors. Preventing leaks does not mean stopping that collaboration. It means knowing which information genuinely deserves protection, and then watching the exits for exactly that material. We build this with tools that are usually already part of Microsoft 365 or Google Workspace, and we always start by observing before anything gets blocked.

3 to 4 levels
from “public” to “strictly confidential”
Observe first
for at least four weeks before any block
Purview
or Google DLP, often already licensed
Warn, not block
wherever a warning is enough

Everything this covers

DLP only works when the rules match how people actually work. Rules that are too strict push staff towards workarounds, and those are far harder to control than the original situation.

Settle the details with an engineer

Classification scheme

A handful of clearly named confidentiality levels, illustrated with examples from your own day-to-day: an internal plan, a confidential cost calculation, strictly confidential material such as health records or salary lists.

Sensitivity labels

Labels in Microsoft Purview that mark documents, encrypt them and limit forwarding. Where possible they are suggested automatically, for example when a file contains social security numbers or IBANs.

Mail rules

A warning or a block when confidential content heads to private addresses or to an unusually large number of outside recipients, with the option for users to confirm a justified exception themselves.

Cloud sharing

Restricting anonymous links, expiry dates on external shares and regular reports on which files are shared outside. Partners you work with regularly get managed guest access.

Endpoints and removable media

USB sticks read-only or encrypted-only, blocking uploads of confidential files to personal cloud storage, spotting copies into unapproved apps. Delivered through Intune and Defender for Windows and macOS.

Departures

Unusual downloads and forwarding in the weeks before someone leaves become visible. Reviews follow rules agreed with the works council and your data protection lead.

Our working method

DLP is introduced in three phases so that no workflow breaks without warning.

01

Define the levels

A workshop with management and departments: which information is truly critical, where it lives and whom it is routinely shared with.

02

Watching phase

Rules run in logging mode only. After a few weeks we can see which content goes where and which rules would trigger too many false alarms.

03

Tips, then blocks

First, policy tips that explain the reason to users; blocks only for clear-cut cases. Staff are introduced in a short video session.

04

Monthly review

A monthly report on incidents and overrides, with rules adjusted whenever working habits change.

Most data leaks are not sabotage but convenience. A prompt at the right moment, such as “This file contains salary data. Do you really want to send it to a private address?”, prevents more than any hard block. That is why we lead with prompts and block only where the case is unambiguous.

Frequently asked questions

Automated matching against content patterns is possible in principle, but it needs a proper basis: staff must be informed, in Austria there is often a works agreement where a works council exists, and a data protection assessment is required. We configure the technology so that reviews are purpose-bound and logged. The legal side is for your lawyer to settle.

Basic DLP policies for Exchange, SharePoint and OneDrive are currently part of Business Premium. Automatic labelling and endpoint DLP need higher plans or add-ons depending on scope; Microsoft's current licensing overview is what counts. We look at what you own and work out what is worth paying for.

Not if it is introduced properly. Regular partners get guest access or approved domains, and rules only bite on the genuinely confidential levels.

Only to a very limited extent. DLP governs digital routes, not cameras. For strictly confidential data, watermarks, restricted viewing and clear rules help as well. Complete protection does not exist, and we say so plainly.

Keep confidential material from walking out unnoticed

Describe which information is most sensitive for you and which platform you use. We will propose a classification scheme and a realistic starting point.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.