Start here
Three entry points for when you have to prove, not just declare, that data leaks are under control.
- ISO 27001 auditISO 27001 control 8.12: proving data leakage preventionWhat the auditor expects on control 8.12 and how to produce dated, reproducible test records.6 min read
- NIS2 complianceNIS2 and data protection: proving your measures are effectiveArticle 21 requires you to assess how effective your measures are: build dated evidence of what your controls really stop, on the scenarios actually tested.6 min read
- Board reportingDLP metrics: presenting protection effectiveness to the boardReplace the alert count with the share of scenarios blocked, its trend and the decisions to be made.6 min read
-
Understanding exfiltration
Definition, test method, decoys and vocabulary: the basics for knowing what really gets out.
- The guideData exfiltration testing: definition, method and what is at stakeThe definition, the egress channels and the method for seeing what your controls really stop.6 min read
- Test planHow to test your DLP: a channel-by-channel checklist and test plan to see whether it blocksA channel-by-channel test plan, using synthetic data, to find out whether your DLP blocks or merely raises alerts.6 min read
- ConfigurationDLP false negatives: 7 misconfigurations that let data leakThresholds, exceptions, audit mode: the settings that let data out while the console stays green.6 min read
- MethodSynthetic data: testing exfiltration in production without using any real business dataDesign realistic decoys to test where the attacker operates, without any real data leaving.6 min read
- FrameworkMITRE ATT&CK Exfiltration (TA0010): the guide for defendersRead the Exfiltration tactic as families of channels and map each technique to a verifiable control.6 min read
- GlossaryDLP and exfiltration glossary: the essential terms from A to ZA shared vocabulary so that CISOs, SOC teams and DPOs are talking about the same thing.6 min read
-
Compliance and evidence: ISO 27001, NIS2, DORA, GDPR
What each regulation requires and how to produce dated evidence that your measures work.
- ComplianceISO 27001 control 8.12: proving data leakage preventionWhat the auditor expects on control 8.12 and how to produce dated, reproducible test records.6 min read
- ComplianceNIS2 and data protection: proving your measures are effectiveArticle 21 requires you to assess how effective your measures are: build dated evidence of what your controls really stop, on the scenarios actually tested.6 min read
- ComplianceDORA resilience testing: where data leak testing fitsPosition data leak testing within the DORA testing programme, alongside audits and TLPT.6 min read
- ComplianceGDPR Article 32: testing the effectiveness of your security measuresArticle 32 requires you to test your measures regularly: a procedure and evidence the DPO can use.6 min read
-
By channel: DNS, HTTPS, email, generative AI, Microsoft 365
Every egress channel has its blind spots: how to test them one by one.
- By channelDNS exfiltration: the controls defenders must verifyResolvers, encrypted DNS, outbound filtering: check that exfiltration over DNS is seen, then blocked.6 min read
- By channelTLS inspection and DLP: the blind spots of HTTPS exfiltrationExclusions, pinned applications, endpoints outside the proxy: measure what TLS inspection does not see.7 min read
- By channelEmail DLP: how to test your outbound email rulesA rule shown as active proves nothing: test outbound email with synthetic data.6 min read
- By channelGenerative AI and data leakage: testing the prompt channelUse decoys to replay copy-pasting into an AI assistant and check what your controls stop.6 min read
- ConfigurationMicrosoft Purview™ DLP: how to validate your policies with evidenceSimulation mode does not prove that a rule blocks: validate your policies across Microsoft 365 locations.6 min read
-
Report and decide: board, method, choosing a tool
Present clear results, choose the right testing approach and the tool to deliver it.
- ReportingDLP metrics: presenting protection effectiveness to the boardReplace the alert count with the share of scenarios blocked, its trend and the decisions to be made.6 min read
- ComparisonContinuous DLP validation, pentest or red team: which should you choose?What each approach verifies, how often, and in what order to combine them.6 min read
- ComparisonBAS and data exfiltration testing: why specialisation mattersA BAS covers the whole attack chain; exfiltration testing digs into how data gets out, channel by channel.6 min read
- Buyer’s guideChoosing a DLP testing tool: criteria and questions for vendorsThe criteria grid and the questions to ask before selecting a DLP testing tool.6 min read