The key points in 30 seconds
- DLP covers the rules and tools that prevent sensitive data from leaving the authorised perimeter.
- Exfiltration, leakage and loss are not synonyms: exfiltration is a deliberate leak, loss is compromised availability.
- Deployed, configured, proven: only “proven” shows that blocking works, on the scenarios actually tested.
We maintain this glossary for a simple reason: in a DLP project, the CISO, the DPO (data protection officer) and the SOC use the same words without giving them the same meaning, and it ends in misunderstanding. Let us start with the two central terms. Data leak prevention (DLP, short for Data Loss Prevention) covers the technologies and rules that prevent sensitive information from leaving the authorised perimeter. Exfiltration is the deliberate, unauthorised removal of data, usually orchestrated by an attacker or an insider. What follows, from A to Z, are the terms you will come across in a data protection project, with the meaning we give them at Enforcis.
Before the list, a distinction we make again in almost every meeting: leakage, loss and exfiltration are not synonyms. The table below sets the vocabulary.
Exfiltration, leak or loss: what changes for you
| Term | Intent | Typical example | Question to ask |
|---|---|---|---|
| Exfiltration | Deliberate and malicious | An attacker transfers a customer database to a server they control | Do my controls block this egress channel? |
| Data leak | Often unintentional | An employee sends an HR file to the wrong recipient | Do my rules catch the mistake before it is sent? |
| Data loss | None, the data disappears | A disk encrypted by ransomware with no usable backup | Can I restore? |
Glossary from A to Z
A
- Agent, endpoint
- DLP software installed on the workstation that monitors copying, printing, removable media and uploads from the machine.
- Blind spot
- an egress channel your controls do not inspect, or inspect without being able to block. This is what active testing sets out to reveal.
B
- BAS (Breach and Attack Simulation)
- a family of tools that automatically simulate attack techniques to check defences. Exfiltration testing is a specialisation of it, focused on data leaving the organisation.
- Blocking
- the action of a DLP rule that actually prevents the transfer. Not to be confused with an alert, which lets the data through.
C
- Channel, egress
- any path through which data can leave the perimeter: email, web, cloud storage, USB stick, printing, instant messaging, generative AI prompts.
- CASB (Cloud Access Security Broker)
- an intermediary that applies security policies, including DLP, to the use of cloud and SaaS services.
- Classification
- labelling data according to its sensitivity (public, internal, confidential). DLP without reliable classification relies on guesswork.
D
- DLP (Data Loss Prevention)
- a set of controls that identify sensitive data and prevent it from leaving without authorisation.
- Decoys (synthetic data)
- synthetic data that mimics the format of real data (numbers, documents, customer files) without containing any. It lets you test in production without using any real business data. Further reading: testing exfiltration in production with synthetic data.
- Double extortion
- a ransomware technique that combines encryption with the threat of publishing stolen data. Exfiltration is the step that comes first.
E
- Egress filtering
- control of the traffic leaving the company network. Firewalls, proxies and web gateways all play a part.
- Fingerprinting
- a technique that computes a signature of a reference document in order to recognise copies of it, even partial ones.
- Exfiltration
- the deliberate, unauthorised transfer of data outside the perimeter. In the MITRE ATT&CK framework, it is tactic TA0010. See our explanation of the Exfiltration tactic for defenders.
- Expression, regular (regex)
- a text search pattern (IBAN format, social security number) used by DLP to spot a piece of data.
F
- False negative
- sensitive data that gets out without triggering any rule. It is the most dangerous error, because it is silent.
- False positive
- an alert or block wrongly triggered on legitimate data. Too many false positives push teams to relax their rules, which creates false negatives.
H
- Hierarchy of fixes (prioritisation)
- ranking fixes by impact and effort, so that the channels with the greatest exposure are dealt with first.
I
- Insider (insider threat)
- a legitimate user, employee or contractor, who gets data out through malice, negligence or coercion.
- Inspection, TLS
- decryption of HTTPS traffic by a proxy to allow content analysis. Exclusions (banking, healthcare, pinned applications) often create blind spots.
M
- Monitor mode (or audit mode)
- a DLP rule that logs without blocking. Useful during deployment, risky if it becomes permanent without anyone knowing.
P
- Policy, DLP
- a coherent set of rules applied to a data type, a group of users and given channels.
- Posture
- the actual level of protection at a given moment, measured by tests rather than inferred from the configuration.
- Proof
- an observable result showing that a control blocked or detected an exfiltration attempt. It answers an auditor better than a console screenshot.
R
- Replay
- re-running an attack scenario that has already been played, to check that a fix holds or that an update has not broken anything.
- Remediation
- a corrective action that closes a blind spot (rule added, exclusion removed, channel closed).
S
- Scenario, attack
- a realistic chain of techniques reproduced during a test, for example an upload to personal storage or exfiltration through an authorised web service.
- Shadow IT
- tools and services used without approval from the IT department. Every unlisted service is a potential egress channel.
T
- Testing, active exfiltration
- a controlled attempt to get synthetic data out through different channels, to see what is really blocked or detected. Our reference page details the definition, method and stakes of exfiltration testing.
- Tunnelling, DNS
- hijacking the DNS protocol to carry data. Rarely inspected as rigorously as web traffic.
V
- Validation, continuous
- repeated, automated verification of control effectiveness, as opposed to a one-off pentest that captures a single date.
Scenario: why vocabulary matters in meetings
A DPO asks the CISO: “Are we protected against leaks?” The CISO replies that DLP is deployed. The CIO hears “blocked”. The SOC team knows that half the rules are running in audit mode. Each of them is right in their own terms. And the DPO still has no answer.
Diagram · three words, three levels
Next step
Deployed, configured or proven: where does your DLP stand?
A 30-minute demo: a full campaign across the 8 channels we test, on our demo environment. The POC shows, on site, how the solution behaves in your environment, on one simple scenario in a synthetic environment. What actually leaves through your channels is what the pilot shows you.
Checklist: the terms to align within your team
- Do you distinguish between alerts and blocks in your dashboards?
- Do you know which rules are still in audit mode?
- Does your list of egress channels include DNS, generative AI and personal storage?
- Do you measure false negatives, or only false positives?
- Do your tests use synthetic data rather than copies of real data?
If several answers are unclear, start by checking whether your DLP really blocks.
FAQ
What is the difference between a data leak and data exfiltration?
A leak is the outcome: data has left the authorised perimeter, often by mistake. Exfiltration is a deliberately caused leak, by an external attacker or an insider.
Does DLP protect against data loss?
Not directly. Loss (deletion, encryption, outage) is a matter of backup and continuity. DLP deals with the unauthorised removal of information.
What is a blind spot in DLP?
It is an egress channel your controls do not inspect, or inspect without being able to block. Three typical examples: a TLS inspection exclusion (online banking, healthcare site, pinned application), a shadow IT service that was never listed, a DNS tunnel nobody looks at. None of them produces an alert. That is why we look for them through active testing, with decoys.
What is the difference between an alert and a block in DLP?
A block prevents the transfer: the data stays inside the perimeter. An alert reports the event, but the data still leaves. A rule in audit mode, for its part, logs without blocking. Useful during deployment, risky if nobody knows it has stayed that way. In your dashboards, keep these 3 states separate: presenting an alert as a block gives the DPO false assurance.
