Data Loss Prevention (DLP)
Data loss prevention (DLP) is a set of controls that detect and block sensitive data leaving an organization via email, uploads, AI prompts, or devices.
Data loss prevention (DLP) is a category of security controls that identify sensitive data — customer records, source code, financial figures, credentials, intellectual property — and detect or block it from leaving the organization through unauthorized channels: email, file uploads, messaging apps, removable media, or, increasingly, prompts typed into generative AI tools.
How it works
DLP systems combine content inspection with policy enforcement. Data is classified — by pattern matching (card numbers, national ID formats), keywords, document fingerprints, or machine-learning classifiers — and policies define what each class of data may do: where it can travel, who can send it, and through which channels. Enforcement points sit on endpoints, email gateways, web proxies, and cloud apps. When an action violates policy, the system can log it, warn the user, require a justification, or block it outright. Modern deployments favor the middle options: a real-time coaching prompt ("this file contains customer data — use the approved channel") corrects the behavior at the moment of risk without breaking legitimate work, which is why DLP has become as much a human-risk control as a technical one.
How to defend with it
DLP earns its keep only when tuned to how data actually leaks. Start by classifying the handful of data types whose loss genuinely hurts, then instrument the channels employees really use — including shadow AI tools and unsanctioned SaaS, now among the fastest-growing exfiltration paths, as our guide to shadow AI at work details. Prefer coach-then-block policies over silent blocking: silent blocks teach employees to route around controls, while visible coaching builds judgment and produces measurable behavior change. Finally, treat DLP alerts as a behavioral signal, not just an incident feed — repeated violations by a team or individual identify where training and process fixes will pay off most, the same logic that drives a human risk score.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo