The essentials in 30 seconds
- 7 templates to fill in plus pre-audit checkpoints, in a 10-page PDF.
- For CISOs, DLP leads and compliance teams preparing an ISO 27001 (8.12), NIS2, UK NIS or DORA review, or a management review.
- The templates are filled in by hand or in your spreadsheet: you do not need Enforcis to use them.
- Three pages are below, readable with no form. The full PDF is sent by email.
What is in the kit
| Template | What it is for |
|---|---|
| 01 · Egress channel matrix | Map the routes by which data can leave your organisation, and the control meant to act on each one. |
| 02 · Test scenario sheet | Write each scenario and its expected result before you run it. |
| 03 · Campaign log | Log each replayed scenario, dated, in the same format at every campaign. |
| 04 · Microsoft Purview™ validation matrix | Apply the tests to the 5 Purview locations, after 4 checks to make first. |
| 05 · Gap register and action plan | Rank the gaps by data sensitivity and ease of the action, fix, then retest. |
| 06 · Board report template | One page for leadership: blocking rate, open channels, time to fix, decisions requested. |
| 07 · Mapping to your frameworks | Link each piece of evidence to ISO 27001, NIS2, DORA and GDPR. |
| + · Pre-audit checkpoints | Eight boxes to tick before the audit or the committee. |
Preview, page 2: “How do you know it works?”
That is the question the auditor asks on reaching control 8.12 in your Statement of Applicability. In other words, it is also the question behind NIS2 Article 21(2)(f), behind DORA for financial entities, and the one your CFO asks in committee. A console screenshot shows that a rule exists. It does not show that a file was stopped.
This kit brings together the templates we recommend for moving from configuration to proof: a dated test trace, per channel, obtained with synthetic data, then followed by corrective action and, where needed, a retest.
What declares, what demonstrates
| Type of evidence | Examples | What it demonstrates |
|---|---|---|
| Policy | Data leakage prevention policy, classification rules | Intent and scope |
| Configuration | Export of DLP rules, mail filters, egress controls | That controls exist |
| Logs | Alerts, blocks, incidents handled | That the tool reacts to some real events, the ones it saw |
| Test traces | Controlled exfiltration scenarios, replayed and dated, per channel, with synthetic data | How the controls reacted to the scenarios actually tested, within the scope and at the time of the test |
| Action plan | Gaps found, priority, owner, fix date, retest | Continual improvement (ISO 27001, clause 10) |
A simplified reading grid: 3 states per tested scenario
| State | What it means and what to do |
|---|---|
| Blocked | The transmission of the synthetic data was blocked. Check separately that the event was logged and that the alert reached the SOC with the expected context. |
| Detected, not blocked | The transmission got past the control, but an alert was observed. Decide whether this channel warrants blocking and record how long the alert took to be picked up. |
| Not detected | The data was observed getting through with no alert identified. Fix as a priority, according to the sensitivity of the data and of the channel. |
The examples in this kit are typical scenarios, not customer cases.
Preview, template 01: egress channel matrix
List the routes by which data can leave your organisation and, for each one, the control that is meant to act. This list forms the basis of your coverage matrix. Coverage is only established as scenarios are actually tested. Without a written pass criterion, the assessment has nothing to measure against.
| Egress channel | Actions to test (examples) |
|---|---|
| Endpoint: removable media | Copy a synthetic file to a USB stick, then to an encrypted external drive |
| Endpoint: printing, clipboard | Print a “Confidential” document; copy and paste into an unauthorised application |
| Mobile endpoint | Same actions off the corporate network, working remotely without VPN |
| Outbound email | Send to a personal address; ZIP attachment, then password-protected ZIP; Bcc; image or scanned PDF |
| Encrypted web (HTTPS) | Upload to a file transfer service; destination not categorised by the proxy; TLS inspection coverage |
| DNS | Exfiltration through queries to an external domain |
| Personal cloud storage | Sync to a personal Dropbox or OneDrive; sharing through a public link |
| Collaboration tools | File posted in a Teams or Slack channel open to external guests |
| Business SaaS applications | Bulk download from a business application |
| Generative AI assistants | Pasting sensitive content into Copilot, Gemini or a web form |
| Out of scope | Same file from an unenrolled device or an unmanaged browser |
In the PDF, each row also has columns for the control meant to act, the pass criterion, the date of the last test and the result (blocked; detected, not blocked; not detected).
Preview, template 07: mapping to your frameworks
The same traces serve several files. No tool makes you compliant: these documents provide elements of evidence of effectiveness, on the scenarios actually tested, for one specific risk: data leakage.
| Framework | What you will be asked for | Kit templates |
|---|---|---|
| ISO 27001 · A 8.12 (data leakage prevention) | Measures applied to systems, networks and devices, and tangible evidence that they are effective | 01, 02, 03 |
| ISO 27001 · A 5.12 (classification) | Classified information, with labels that the tools actually use | 01, 04 |
| ISO 27001 · 9.1, 9.3, 10 | How you evaluate effectiveness; measurement results in management review; gaps addressed | 03, 06, 05 |
| NIS2 · Art. 21(2)(f) | Policies and procedures to assess the effectiveness of measures: dated test results, a history over several months | 02, 03, 05 |
| NIS2 · Art. 21(2)(a) and Art. 20 | Channels linked to the risk analysis; management bodies that approve the measures and oversee their implementation | 01, 06 |
| DORA · Art. 5, 9, 10, 13 | An accountable management body; protection and prevention; detection of anomalous activities; learning and evolving | 06, 03, 05 |
| DORA · Art. 24 and 25 | A risk-based testing programme; scenario-based tests, alongside audits and TLPT | 02, 03 |
| GDPR / UK GDPR · Art. 32 | A process for regularly testing, assessing and evaluating the effectiveness of security measures | 03, 05 |
NIS2 is an EU directive (Directive (EU) 2022/2555): Article 21 sets the measures, and each Member State transposes it into national law. In the United Kingdom, the applicable framework is the Network and Information Systems Regulations 2018 (UK NIS). Check the text that applies to each of your entities before making any decision. This kit is not legal advice.
Get the full kit (10 pages)
The PDF adds the scenario sheet, the campaign log, the Microsoft Purview matrix, the gap register, the board report template and the pre-audit checkpoints.
Get the DLP Proof Kit by email
Next step
Rather see a campaign than fill in the templates by hand?
A 30-minute demo: a campaign replayed across the channels covered by the demo scenario, on our demo environment. What gets out of your own network, on the scenarios tested, is what a pilot on a limited production scope shows you.
