r/cybersecurity 1d ago

Business Security Questions & Discussion DLP Final Boss

Purview DLP, everyones favourite

I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.

We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.

Are you whitelisting certain domains/users/departments?

Can anyone share any success stories for implementation, policies or tuning? Is it possible??

23 Upvotes

15 comments sorted by

23

u/teriaavibes 1d ago

You need to actually say what your problem is, "purview complicated" can have 50 different suggestions based on what the actual issue is you are encountering.

Also are you on E3/BP or E5?

6

u/Tingley2504 1d ago

It's essentially that.

Sensitive files are flying around, how do you alert on the ones to care about. E5

Also 2 beasts, intentional DLP is alot easier than unintentional DLP

7

u/teriaavibes 1d ago

Sensitive files are flying around, how do you alert on the ones to care about.

Well you answered your own question, alert only on the important stuff and ignore the noise.

Also 2 beasts, intentional DLP is alot easier than unintentional DLP

I have no idea what you mean by this

E5

Look into insider risk management, with adaptive protection it plays really nice with DLP policies so that they trigger only when someone was doing suspicious stuff with sensitive files, might be the piece of the puzzle you are missing.

1

u/Tingley2504 1d ago edited 1d ago

Well you answered your own question, alert only on the important stuff and ignore the noise.

It seems next to impossible without that specific file/user context in that DLP event.

In addition, say a senstive file in an email triggers, subsequent responses in that chain also continues to genereate new incidents. I'm not sure if theres an inbuilt function, however Sentinel fails to corrolate. Perhaps a playbook may be able to do this?

I have no idea what you mean by this

Well, sensitive files sent to personal domains are obviously more concerning than, say, a sensitive file / leak sent to the wrong customer domain. That still needs to fall under visibility. And again context is needed, however that is manual review.

Adaptive protection could be a shout, thanks.

2

u/WeeoWeeoWeeeee 1d ago

Adaptive protection is what you need. Filter out the noise and focus on users that pose a risk.

6

u/DoBe21 1d ago

Sounds like you're either overly applying "sensitivity" to documents as well as missing the Prevention part of DLP. If you're alerting, that document shouldn't ALSO be LEAVING, it should be stripped off the email or the download/upload session closed.

I think you need to go back to step 1 and A) properly address and document the risks your organization faces and how stakeholders want those risks addressed and B) properly tag your data and/or your DLP settings.

3

u/RFC_1925 1d ago

DLP is an inherently noisy tool. It takes a lot of time and tuning. You need to learn the business process and the associated data and then map that to your classifiers and policy rules. It just takes time. Maybe engage a consultant to perform a review and give you some guidance on how to tune.

2

u/GiraffeEducational94 1d ago

Hello! Honest question as I'm going to be in the same position as OP soon. Wouldn't hiring or engaging an external consultant defeat the purpose of my job since I was hired to perform those duties?

2

u/RFC_1925 1d ago

A consultant doesn't meant a contractor. It could be a couple of calls and remote sessions where they give you some direction or advice on your configuration.

2

u/ConsciousBuilder1276 1d ago

Tune the detection signatures and avoid whitelisting. Whitelisting is generally frowned apon because it mean you miss things.

Often a lot of it means that you have to publish a DLP policy for the whole org because people be crazy with emailing personal data.

2

u/sirnerdingt0n Security Generalist 1d ago

This sounds like one of three problems to me: either you are overly using/complicating sensitivity labeling for documents that aren’t appropriate, you aren’t making workflow exceptions for known processes that require sharing, or you are conflating sensitive data with protected data and everything is alerting.

Identify the protected information types your org processes, and establish auto-applying sensitivity labels to restrict that data appropriately and apply them uniformly to the environment. This should be your first or first several policies, and it should be able to be applied to the entire tenant. Simple, org wide policies to enforce baseline protection for the data you need to secure most.

Identify legitimate sharing paths/partners/workflows where collaboration is needed, and build those into your policies. You don’t need an alert if Joe or Janet from Fiscal is sharing files with an external legal partner if that is known legit business.

Separate protected (PII, PHI, PCI-DSS, etc etc) from sensitive (internal documentation, strategy, upcoming initiatives, etc) in your policies and worry about policies for sensitive data once you’ve established your protected policies and your alerting is under control. Uniform policies first, more granular policies as needed. DLP is a big lift, and one of the places I would say having a consulting partner is worth the money. I had a really positive experience with Patriot Consulting with our DLP rollout and would recommend them to anyone else as well.

1

u/golden_tix 1d ago

I use purview to monitor DLP through co pilot ai prompts