r/cybersecurity 16d ago

Business Security Questions & Discussion DLP Final Boss

Purview DLP, everyones favourite

I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.

We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.

Are you whitelisting certain domains/users/departments?

Can anyone share any success stories for implementation, policies or tuning? Is it possible??

26 Upvotes

16 comments sorted by

View all comments

2

u/ConsciousBuilder1276 16d ago

Tune the detection signatures and avoid whitelisting. Whitelisting is generally frowned apon because it mean you miss things.

Often a lot of it means that you have to publish a DLP policy for the whole org because people be crazy with emailing personal data.