Service · Cybersecurity

Data leak prevention (DLP)

Buying a DLP licence is not where this starts. The first job is agreeing what deserves protection, because without that decision any product floods the administrator with alerts that go unread by week four. So we begin with a short list of genuinely critical information and only then write rules covering email, cloud storage, pen drives and printing.

3-4
sensitivity levels
Watching
before enforcing
PESEL
spotted by rules
USB
whitelisted devices only

Included in this service

The order is fixed: locate the data, narrow access, shut the exits, watch for attempts. Leave out the first stage and the others achieve little.

Talk the scope through with an engineer

Classification

Information is sorted by value, typically public, internal, confidential and restricted. Without tiers everything is guarded equally, which in reality means badly.

Device encryption

BitLocker for laptops and hardware-encrypted pen drives. Losing an encrypted laptop means buying a new one; losing an unencrypted one can mean a notifiable breach.

Removable media

Approved USB devices only, a record of every connection and a total block for teams working with sensitive records, such as HR or patient registration.

Email and sharing

Controls on outgoing attachments and on OneDrive and SharePoint links, with automatic encryption for messages containing PESEL, ID card or bank account numbers.

DLP policies

Sensitivity labels and Microsoft Purview policies, or their equivalent in another tool, written for your own classification instead of a stock template.

Incident handling

A procedure for when an attempted leak is caught, plus a periodic report of what was stopped, who triggered it and how it was resolved.

How we work together

Enforcement waits until we understand how information really flows. Switching it on earlier would block legitimate work.

01

Crown jewels

Identifying the small slice of data that truly matters: the customer base, price agreements, technical documentation, HR and medical files.

02

Quick protection

Encrypted laptops, restricted USB in key teams and removal of stale sharing links.

03

Watch period

Policies run in report-only mode for an agreed period, revealing the real routes information takes.

04

Enforcement

Blocking begins once false alarms are few enough for each to be reviewed by a person.

Leaks seldom look like theft. Far more often a departing salesperson forwards the client list to a private inbox “for reference”, or someone in HR sends a payroll summary over a personal messenger because it is faster. Well-tuned DLP helps catch cases like these before they become an incident.

Questions and answers

Not if the rules are written carefully and have been through the watch period. An invoice with a customer's NIP is routine correspondence. We aim rules at genuinely sensitive patterns, say dozens of PESEL numbers in a single file, not at every document with company details.

Often in part. Many Microsoft 365 plans include DLP features and sensitivity labels, but the scope depends on the plan. We use what you already pay for and only discuss an extra product for data of exceptional value.

Most of the protection has to be in place beforehand: no copying to private media, logging of large CRM exports and prompt removal of access. If data does leave, the DLP logs become material for your lawyer, who makes the legal assessment.

Yes, Polish employment law requires staff to be informed about email monitoring. DLP searches for patterns such as PESEL or card numbers rather than reading messages, but the form and wording of the notice should be agreed with a lawyer or HR. We describe the technical side of the solution.

Keep information where it belongs

Tell us which information matters most and which tools your team relies on. We will propose where to start.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.