← All articles

ARTICLE · DATA LEAK ACTIVE TESTING

DLP and exfiltration glossary: the essential terms from A to Z

  • Glossary
  • 6 min read
  • Updated
Server racks captured in motion in a data centre, an image of the technical vocabulary of data protectionDeployed, configured, proven

The key points in 30 seconds

  • DLP covers the rules and tools that prevent sensitive data from leaving the authorised perimeter.
  • Exfiltration, leakage and loss are not synonyms: exfiltration is a deliberate leak, loss is compromised availability.
  • Deployed, configured, proven: only “proven” shows that blocking works, on the scenarios actually tested.

We maintain this glossary for a simple reason: in a DLP project, the CISO, the DPO (data protection officer) and the SOC use the same words without giving them the same meaning, and it ends in misunderstanding. Let us start with the two central terms. Data leak prevention (DLP, short for Data Loss Prevention) covers the technologies and rules that prevent sensitive information from leaving the authorised perimeter. Exfiltration is the deliberate, unauthorised removal of data, usually orchestrated by an attacker or an insider. What follows, from A to Z, are the terms you will come across in a data protection project, with the meaning we give them at Enforcis.

Before the list, a distinction we make again in almost every meeting: leakage, loss and exfiltration are not synonyms. The table below sets the vocabulary.

Exfiltration, leak or loss: what changes for you

Term Intent Typical example Question to ask
Exfiltration Deliberate and malicious An attacker transfers a customer database to a server they control Do my controls block this egress channel?
Data leak Often unintentional An employee sends an HR file to the wrong recipient Do my rules catch the mistake before it is sent?
Data loss None, the data disappears A disk encrypted by ransomware with no usable backup Can I restore?

Glossary from A to Z

A

Agent, endpoint
DLP software installed on the workstation that monitors copying, printing, removable media and uploads from the machine.
Blind spot
an egress channel your controls do not inspect, or inspect without being able to block. This is what active testing sets out to reveal.

B

BAS (Breach and Attack Simulation)
a family of tools that automatically simulate attack techniques to check defences. Exfiltration testing is a specialisation of it, focused on data leaving the organisation.
Blocking
the action of a DLP rule that actually prevents the transfer. Not to be confused with an alert, which lets the data through.

C

Channel, egress
any path through which data can leave the perimeter: email, web, cloud storage, USB stick, printing, instant messaging, generative AI prompts.
CASB (Cloud Access Security Broker)
an intermediary that applies security policies, including DLP, to the use of cloud and SaaS services.
Classification
labelling data according to its sensitivity (public, internal, confidential). DLP without reliable classification relies on guesswork.

D

DLP (Data Loss Prevention)
a set of controls that identify sensitive data and prevent it from leaving without authorisation.
Decoys (synthetic data)
synthetic data that mimics the format of real data (numbers, documents, customer files) without containing any. It lets you test in production without using any real business data. Further reading: testing exfiltration in production with synthetic data.
Double extortion
a ransomware technique that combines encryption with the threat of publishing stolen data. Exfiltration is the step that comes first.

E

Egress filtering
control of the traffic leaving the company network. Firewalls, proxies and web gateways all play a part.
Fingerprinting
a technique that computes a signature of a reference document in order to recognise copies of it, even partial ones.
Exfiltration
the deliberate, unauthorised transfer of data outside the perimeter. In the MITRE ATT&CK framework, it is tactic TA0010. See our explanation of the Exfiltration tactic for defenders.
Expression, regular (regex)
a text search pattern (IBAN format, social security number) used by DLP to spot a piece of data.

F

False negative
sensitive data that gets out without triggering any rule. It is the most dangerous error, because it is silent.
False positive
an alert or block wrongly triggered on legitimate data. Too many false positives push teams to relax their rules, which creates false negatives.

H

Hierarchy of fixes (prioritisation)
ranking fixes by impact and effort, so that the channels with the greatest exposure are dealt with first.

I

Insider (insider threat)
a legitimate user, employee or contractor, who gets data out through malice, negligence or coercion.
Inspection, TLS
decryption of HTTPS traffic by a proxy to allow content analysis. Exclusions (banking, healthcare, pinned applications) often create blind spots.

M

Monitor mode (or audit mode)
a DLP rule that logs without blocking. Useful during deployment, risky if it becomes permanent without anyone knowing.

P

Policy, DLP
a coherent set of rules applied to a data type, a group of users and given channels.
Posture
the actual level of protection at a given moment, measured by tests rather than inferred from the configuration.
Proof
an observable result showing that a control blocked or detected an exfiltration attempt. It answers an auditor better than a console screenshot.

R

Replay
re-running an attack scenario that has already been played, to check that a fix holds or that an update has not broken anything.
Remediation
a corrective action that closes a blind spot (rule added, exclusion removed, channel closed).

S

Scenario, attack
a realistic chain of techniques reproduced during a test, for example an upload to personal storage or exfiltration through an authorised web service.
Shadow IT
tools and services used without approval from the IT department. Every unlisted service is a potential egress channel.

T

Testing, active exfiltration
a controlled attempt to get synthetic data out through different channels, to see what is really blocked or detected. Our reference page details the definition, method and stakes of exfiltration testing.
Tunnelling, DNS
hijacking the DNS protocol to carry data. Rarely inspected as rigorously as web traffic.

V

Validation, continuous
repeated, automated verification of control effectiveness, as opposed to a one-off pentest that captures a single date.

Scenario: why vocabulary matters in meetings

A DPO asks the CISO: “Are we protected against leaks?” The CISO replies that DLP is deployed. The CIO hears “blocked”. The SOC team knows that half the rules are running in audit mode. Each of them is right in their own terms. And the DPO still has no answer.

Diagram · three words, three levels

Deployed, configured, provenThree increasing levels. Deployed: the tool exists. Configured: rules are active. Proven: a test has shown the block. Only the last level answers the DPO’s question.Deployedthe tool existsConfiguredrules activeProvenblock observedby a testAnswers the DPO

What each level allows you to claim in front of a DPO.

Next step

Deployed, configured or proven: where does your DLP stand?

A 30-minute demo: a full campaign across the 8 channels we test, on our demo environment. The POC shows, on site, how the solution behaves in your environment, on one simple scenario in a synthetic environment. What actually leaves through your channels is what the pilot shows you.

Checklist: the terms to align within your team

  • Do you distinguish between alerts and blocks in your dashboards?
  • Do you know which rules are still in audit mode?
  • Does your list of egress channels include DNS, generative AI and personal storage?
  • Do you measure false negatives, or only false positives?
  • Do your tests use synthetic data rather than copies of real data?

If several answers are unclear, start by checking whether your DLP really blocks.

FAQ

What is the difference between a data leak and data exfiltration?

A leak is the outcome: data has left the authorised perimeter, often by mistake. Exfiltration is a deliberately caused leak, by an external attacker or an insider.

Does DLP protect against data loss?

Not directly. Loss (deletion, encryption, outage) is a matter of backup and continuity. DLP deals with the unauthorised removal of information.

What is a blind spot in DLP?

It is an egress channel your controls do not inspect, or inspect without being able to block. Three typical examples: a TLS inspection exclusion (online banking, healthcare site, pinned application), a shadow IT service that was never listed, a DNS tunnel nobody looks at. None of them produces an alert. That is why we look for them through active testing, with decoys.

What is the difference between an alert and a block in DLP?

A block prevents the transfer: the data stays inside the perimeter. An alert reports the event, but the data still leaves. A rule in audit mode, for its part, logs without blocking. Useful during deployment, risky if nobody knows it has stayed that way. In your dashboards, keep these 3 states separate: presenting an alert as a block gives the DPO false assurance.

A configuration is not proof.

With synthetic payloads, we run controlled campaigns on the configured paths and observe how your controls actually behave, scenario by scenario.