Presumably everyone has heard of the wonderful solution that stands guard over the flow of information from the Organisation. Unfortunately, many people believe that implementing a DLP (Data leak prevention) system will protect their business from the loss of important information and allow them to safely exchange sensitive information. This is not entirely true – or more accurately, not true at all – as with any partial truth.
DLP systems prevent the accidental leakage of classified information. This is the correct definition for DLP systems.
As you can see, the difference in definition is just two words, but the sense changes almost completely.
The thing is that for the DLP protection to work, the system has to detect specific security triggers it’s been set up to look for. Firstly, there’s information classification. The classic classification – Unclassified, Official, Restricted, Confidential, Secret, Top Secret – can be expanded. Another type of trigger could be a specific set of information that it’s known to be forbidden to transmit outside the organization. For example, this could be a set of information including surname and bank account or card number. Or the presence of the words “Agreement + BTR4 + Delivery Date” in a document. This creates two key problems for effective implementation of DLP systems – every user creating a document must classify it and must specify in the document text which class it belongs to. At the same time, the Information Security department must clearly understand which arbitrary set of words will trigger the DLP system and specify it in the settings before an incident occurs.
The problems start with the classification, as it’s incredibly difficult to train all users to properly classify documents. The simplest solution for quick classification may be to ask the author of the document to himself: “What damage could the release of information from this document cause?” However, most employees can’t imagine the full potential threat or real circumstances, so they usually make mistakes – significantly over- or underestimating, and with it the classification. The problems of creating triggers by an arbitrary set of words are even more interesting, as it’s necessary to describe all possible variations of such sets of words beforehand, which is usually impossible and leads to either a very selective operation of the DLP system or to constant errors, which in turn leads to a decrease in the attention of security departments. For example, if a trigger is set for “Agreement + BTR4 + Delivery Date,” an email with the words “Tomorrow we will unload two and four fourths at base 1234” will not trigger the DLP system, even more, in a large organization.
And that’s not all the nuances of information protection 😊
Modern systems haven’t learned to block user memory at the end of the workday yet, so if an employee simply reads the agreement with the delivery dates of the BTR4 and informs outside through their personal phone (even if it was left in the safe before entering the company), then no DLP system will help. Thus, DLP (Data leak prevention) systems prevent accidental leaks of classified information.
It is important to note that we are talking about “classic” DLP systems (let’s not list them to avoid court cases😊). At the same time, there are quite powerful User and Entity Behavioral Analytics (UBA/UEBA) systems (especially in authoritarian countries) that can quite cynically violate employees’ rights to privacy, but already provide the opportunity to investigate an incident and close in on suspected individuals involved in leaking or spreading.
