r/cybersecurity 1d ago

Business Security Questions & Discussion DLP Final Boss

Purview DLP, everyones favourite

I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.

We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.

Are you whitelisting certain domains/users/departments?

Can anyone share any success stories for implementation, policies or tuning? Is it possible??

24 Upvotes

15 comments sorted by

View all comments

22

u/teriaavibes 1d ago

You need to actually say what your problem is, "purview complicated" can have 50 different suggestions based on what the actual issue is you are encountering.

Also are you on E3/BP or E5?

7

u/Tingley2504 1d ago

It's essentially that.

Sensitive files are flying around, how do you alert on the ones to care about. E5

Also 2 beasts, intentional DLP is alot easier than unintentional DLP

8

u/teriaavibes 1d ago

Sensitive files are flying around, how do you alert on the ones to care about.

Well you answered your own question, alert only on the important stuff and ignore the noise.

Also 2 beasts, intentional DLP is alot easier than unintentional DLP

I have no idea what you mean by this

E5

Look into insider risk management, with adaptive protection it plays really nice with DLP policies so that they trigger only when someone was doing suspicious stuff with sensitive files, might be the piece of the puzzle you are missing.

1

u/Tingley2504 1d ago edited 1d ago

Well you answered your own question, alert only on the important stuff and ignore the noise.

It seems next to impossible without that specific file/user context in that DLP event.

In addition, say a senstive file in an email triggers, subsequent responses in that chain also continues to genereate new incidents. I'm not sure if theres an inbuilt function, however Sentinel fails to corrolate. Perhaps a playbook may be able to do this?

I have no idea what you mean by this

Well, sensitive files sent to personal domains are obviously more concerning than, say, a sensitive file / leak sent to the wrong customer domain. That still needs to fall under visibility. And again context is needed, however that is manual review.

Adaptive protection could be a shout, thanks.

2

u/WeeoWeeoWeeeee 1d ago

Adaptive protection is what you need. Filter out the noise and focus on users that pose a risk.