Reviewed and updated in October 2026.
In the 2021 Insider Threat Report by Cybersecurity Insiders, 98% of the organizations surveyed said they feel vulnerable to insider attacks. The risk is not only the occasional malicious insider. It is the everyday, involuntary mishandling of corporate, regulated and sensitive information by employees who do not realize what they are doing. This article introduces the security layer that addresses this: Data Loss Prevention (DLP).
Data Loss Prevention (DLP), also called Data Loss Protection, is the set of tools and policies that detect and stop sensitive data from leaving an organization without authorization, whether by email, web upload, removable media or copy and paste between apps. It works in three steps: find and classify sensitive data, watch how it moves, and block or report movements that break policy.
DLP is the practice of detecting and preventing the loss or unauthorized exfiltration of data in any form. The goal is to protect your organization from financial and reputational damage by keeping business-sensitive and regulated information inside, and to support compliance with data protection regulations.
How you implement DLP depends on the type of device (desktop or mobile), the ownership model (company-owned or personal) and the usage (business only or mixed).
On desktop computers, everything happens at the file system level, with documents and their content. If sensitive information is handled and stored on desktops, use a proper DLP solution with a software agent for inventory, detection and reporting. It usually works together with an EPP or EDR agent that enforces the actions the corporate policy defines. Microsoft's overview of Purview DLP shows what such policies look like in practice.
The solution first identifies documents that match company-defined policies, for example documents containing corporate information such as company name, address or VAT number, or regulated information such as social security numbers or health data. This determines which documents are sensitive and need to be watched. Labeling documents by sensitivity at creation makes this step far more reliable.
The solution then detects and prevents exfiltration, which can happen in many ways: uploading a document to an external or unauthorized website, sending an email with sensitive content in the body or as an attachment, copying files to removable media such as a USB drive, or copying them over the network to another computer. These are everyday actions any employee takes, whatever their role, but they can have serious consequences when sensitive information ends up in the wrong place.
Finally, the solution reports to the security team, by email or, better, by forwarding events to a Security Information and Event Management (SIEM) platform where they can be correlated with other alerts. How detection and response work there is described in Human Oversight in the AI Era: Finding the Right Balance in TDIR and SIEM.
Unlike other security products, DLP software reads the content of emails and documents, not just names, headers or hashes, looking for sensitive or regulated data. In case of exfiltration, a copy of the document is usually placed in an evidence vault so the incident can be reviewed and its impact estimated. That vault may be in the cloud, hosted by the vendor, or on site in your own infrastructure so that no data leaves your premises. Confirm this with the vendor before choosing a solution.
Another way to protect corporate data is virtualization, which keeps data off the desktop entirely, whether the device is company-owned or personal. Employees work with corporate data from any device, anywhere, inside a secure environment. No corporate data reaches the device itself; only an encrypted pixel stream is sent to it using dedicated protocols.
Mobile devices handle data differently, so detection and prevention happen at the application level rather than the file system level. The aim is that sensitive corporate data cannot be shared or sent outside defined boundaries. That includes copying information from a managed work app to an unmanaged personal app with copy and paste, sending an email with sensitive content from a work account to an external address or the other way round, and accessing corporate information from a personal app.
As always in security, it is not about switching everything on or off but about finding the balance between security and usability that users accept. A typical decision is whether to allow the unmanaged phone app on a personal device (BYOD) or personal apps (BYOD and COPE) to access work contacts, so caller ID and contact sync work.
In all cases this requires managed apps with built-in DLP controls that are enabled and enforced through policies from a UEM solution, such as the Work Profile on Android Enterprise or managed apps on iOS and iPadOS.
It is always worth reassessing your critical infrastructure periodically to see where you can strengthen your security. With the basics of DLP, you can consider how it fits your environment. For the wider product landscape, read Cybersecurity Products: What's What; for access control at sign-in, see Demystifying Security: Conditional Access.
Both are abbreviated DLP and often implemented together, but they address different threats with different methods. Our article Data Loss Protection vs. Data Leakage Prevention explains the distinction in detail.
Yes. To find sensitive or regulated data, DLP inspects content, not just file names or hashes. Clarify with the vendor where inspected data and evidence copies are stored.
At the app level: managed work apps with built-in DLP controls, enforced through UEM policies, restrict copy and paste, sharing and email between work and personal apps.
DLP can only protect what it recognizes as sensitive. Classification and labeling tell the DLP engine which documents matter, which reduces both missed leaks and false alarms.
Want to classify sensitive data and keep it inside your organization? ISEC7 advises on endpoint security, and with ISEC7 CLASSIFY users classify and mark email, attachments and Microsoft Office documents according to your organization's scheme. Contact us.