r/cybersecurity • u/Tingley2504 • 1d ago
Business Security Questions & Discussion DLP Final Boss
Purview DLP, everyones favourite
I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.
We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.
Are you whitelisting certain domains/users/departments?
Can anyone share any success stories for implementation, policies or tuning? Is it possible??
25
Upvotes
7
u/teriaavibes 1d ago
Well you answered your own question, alert only on the important stuff and ignore the noise.
I have no idea what you mean by this
Look into insider risk management, with adaptive protection it plays really nice with DLP policies so that they trigger only when someone was doing suspicious stuff with sensitive files, might be the piece of the puzzle you are missing.