The essentials in 30 seconds
- An exfiltration test pushes synthetic data out to see whether your controls block it, flag it or let it through.
- Five families of channels to cover: endpoint, network, email, cloud and SaaS, generative AI. Enforcis 1.0 tests the web, network and cloud ones: see the 8 channels.
- Every failure calls for a ranked corrective action, then a rerun of the scenario to check.
- We replay it, because a single agent update is enough to reopen a path.
Since 2021, the founding team has been pushing synthetic data out of real information systems: first at Holiseum with the ransomware blank-fire exercise (Tir à Blanc de Ransomware), which won awards in 2022 at the Cybernight and the Cas d’Or, then over more than 40 deployments. The lesson: until someone has tried to get a file out, nobody knows whether it can get out. Enforcis grew out of this in 2025. We call it data exfiltration testing.
A data exfiltration test is a controlled simulation of sensitive information leaving your information system, to check whether your controls block it, detect it or let it through. At the end, you have a list giving one result per scenario: blocked; detected, not blocked; or not detected.
What an exfiltration test is, and what it is not
What it is
- An active test: we actually push a decoy out, instead of rereading rules.
- A single question: can sensitive data get out, through which channel, and does anyone notice?
- Repeatable: the same scenario runs again after an update or a migration.
- Remediation-driven: every failure leads to an identifiable corrective action.
What it is not
- A configuration audit: it reads the rule without ever seeing it run. DLP false negatives hide in that gap.
- A general-purpose pentest: a pentest tries to get in; here, the attacker, or the insider, is already there.
- A full BAS platform: specialisation changes the depth. See the comparison below and our article BAS and exfiltration testing.
- A controlled real leak: no production data is moved.
At a glance
| Approach | Question asked | What it delivers | Its limit for exfiltration |
|---|---|---|---|
| Exfiltration testing | Can sensitive data get out, and does anyone see it? | Scenario-by-scenario evidence, repeatable, in production, with synthetic data | Assumes access is already gained: does not test ingress |
| BAS | Are the simulated techniques stopped? | Automated, broad-spectrum attack simulation | Little evasion, often in a simulated environment, less depth on egress |
| Pentest | Can someone get in and move further? | Proof of exploitability | Point-in-time and not exhaustive, focused on ingress |
| DLP configuration audit | Is the rule set up as intended? | Configuration compliance | Reads the rule without seeing it run; siloed view |
Why test egress rather than ingress
Your defensive budgets often go to ingress: email, perimeter, endpoints. The damage, however, happens when the data leaves. In double-extortion ransomware, exfiltration is what underpins the blackmail, even before encryption.
247 days
on average to identify and contain a breach worldwide.
Source: IBM, Cost of a Data Breach Report 2026 (Ponemon Institute), July 2026.
48%
of the breaches analysed by Verizon involve ransomware, the attack in which stolen data becomes leverage for blackmail.
Source: Verizon, 2026 Data Breach Investigations Report, more than 22,000 confirmed breaches analysed.
204
nationally significant cyber incidents handled by the UK’s NCSC in one year, more than double the previous year (89).
Source: NCSC (the UK’s National Cyber Security Centre), Annual Review 2025, period from September 2024 to August 2025.
Diagram · the replayed workflow
- 1DiscoveryLocate sensitive data
- 2CollectionGather the target files
- 3StagingStructure, archive or compress
- 4AutomationTool up the operation
- 5ExfiltrationLeave through an authorised channel
The channels to cover
| Family | Example channels | Controls involved |
|---|---|---|
| Endpoint | Removable devices, clipboard, printing, local applications | Endpoint DLP agent, EDR |
| Network | HTTPS, DNS, transfer protocols, unusual ports | Proxy, firewall, egress filtering |
| Attachments, message body, automatic forwarding to a Gmail inbox | Email DLP, gateway | |
| Cloud and SaaS | Personal storage (Google Drive, Dropbox), collaboration tools (Teams, Slack), link sharing | CASB, SaaS DLP, native policies |
| Emerging uses | Prompts to generative AI (ChatGPT, Copilot), browser extensions | Browser controls, web gateway |
Put simply, two channels are rarely checked: DNS and HTTPS and the limits of TLS inspection. And then there are prompts: pasting a contract into a generative AI assistant is also a way of getting data out.
A typical scenario: every exfiltration attempt to GitHub succeeds. There is a reason for this: GitHub is a legitimate destination for your developers, often excluded from TLS inspection, and git pushes slip past the DLP. The point is not to block GitHub. We advise you to distinguish the company’s own GitHub space, allowed with a compensating measure such as MFA at the CISO’s discretion, from any third-party repository, which should never be reachable.
The method: five steps, replayed continuously
- Define what is sensitive. Without classification, the DLP does not know what to recognise. Our decoys mimic your real data categories: customer files, blueprints, health records, credentials.
- Build realistic synthetic data. Credible enough to trigger your rules, with no value at all: enough to test in production without using any real business data.
- Replay the attack scenarios. One channel after another, from your workstations and servers, with at least one Windows or Linux agent per subnet.
- Observe the three possible outcomes. Blocked; detected, not blocked; not detected. An alert that nobody handles does not count as a success.
- Prioritise and start again. Rank failures by criticality and effort, fix them, then rerun the scenario. On the Enforcis side, upcoming versions will bring contextual, prioritised recommendations, validated by retest.
One-off or continuous?
Diagram · the loop
A concrete scenario
Picture a manufacturer using Microsoft DLP that blocks files labelled “Confidential” when they are emailed outside the company. The team replays four variants with a fake technical blueprint: direct send, compressed archive, copy into the message body, upload to personal storage from the browser.
Diagram · assumed control, actual egress
Next step
How many paths do your rules really cover?
A 30-minute demo: a full campaign across the 8 channels we test, on our demo environment. The POC shows, on site, how the solution behaves in your environment, on one simple scenario in a synthetic environment. What actually leaves through your channels is what the pilot shows you.
Who it is for, and where to start
- CISOAn objective measure of your controls, to present to senior management. See what NIS2 expects from management and the DLP metrics for the board.
- SOC or SecOpsCheck that exfiltration alerts reach the SIEM and are actionable.
- DPO and complianceDocument, with dates, that security measures are tested.
- IT director at a mid-sized company without a CISOKnow where to focus effort without a specialist team.
Checklist before a first test
- Sensitive data categories are identified.
- Controls in place are inventoried (endpoint, network, email, cloud).
- The SOC is informed, unless you want to measure its detection blind.
- Only decoys will be used for the test.
- An owner is assigned for each family of fixes.
- The date of the next run is set.
To compare solutions, see our criteria for choosing a DLP testing tool; for vocabulary, the DLP and exfiltration glossary.
Frequently asked questions
How does an exfiltration test differ from a DLP configuration audit?
An audit rereads your rules and checks that they are set up as intended. It never sees them run. We push a decoy out through a real channel (HTTPS, DNS, Google Drive, GitHub Gist), from a real Windows or Linux machine, and record what happens. False negatives hide in that gap: a rule that is compliant on paper but does not fire on a remote salesperson’s laptop.
Why test data egress rather than ingress?
Because the damage happens at the moment the data leaves. Double-extortion ransomware shows this clearly: the exfiltrated file underpins the blackmail, even before encryption. Yet your defensive budgets often go to ingress: email, perimeter, endpoints. Since 2021, we have worked from the opposite assumption: the attacker, or the insider, is already in the network, and we measure what they could take away.
Do you need a DLP already?
No. Without a DLP, the test shows which channels are open (HTTPS, DNS, FTP, Google Drive or GitHub Gist) and helps you decide where to invest. With a DLP, it measures what it really stops, on the scenarios actually tested.
Should you block GitHub after a test like this one?
Rarely: your developers need it. What needs closing is any third-party repository. The company’s own GitHub space can stay open, with a compensating measure such as MFA, at the CISO’s discretion.
