DLP
In data security, DLP (data loss prevention) classifies, monitors and blocks sensitive data as it leaves an organisation. The channels have moved on: alongside email and removable media, data now leaves through SaaS, browsers, personal storage, code repositories and, above all, pasting into AI assistants. It is bought inside a wider SSE or endpoint platform.
What it is
Data loss prevention, or DLP, is the set of measures and technologies that keep sensitive information from leaving an organisation without authorisation: financial information, personal data, intellectual property or trade secrets.
It does three things. It watches activity on data across networks, endpoints and storage, to spot transfers and access that fall outside the pattern. It enforces the organisation’s policies on that data, from classification and restriction by role through to blocking a transfer. And it alerts, so that somebody can look at what was blocked and decide.
How it works
DLP identifies sensitive content (by pattern, by fingerprint, or by the label a data classification scheme applied) and watches the points where it could leave, taking an action when it sees a match: log, warn, or block. Enforcement happens across several places at once in a modern deployment: on the endpoint through an agent, in the browser, and in the cloud through an SSE or cloud access security broker that inspects traffic to SaaS applications. The single-appliance, single-channel product of a decade ago has been absorbed into these platforms, because the data no longer leaves through the one gateway that older DLP watched.
What goes wrong
The dated understanding is that data leaks through email, uploads and removable media, and DLP tuned only for those misses where it actually goes now. In 2026 the sensitive information leaves through a SaaS app the security team does not control, a sync client copying a folder to personal storage, a secret committed to a public repository, or a paragraph pasted into a public AI assistant, which is the shadow AI channel with no exfiltration event to catch. From an insider’s or attacker’s view, the winning move is the channel DLP does not inspect: the paste, the personal cloud, the unmanaged browser. Coverage of the old channels while the new ones are open is a false sense of control.
Where this shows up in an audit
We test where sensitive data can actually leave, not where the DLP is pointed. That means checking the modern channels (browser paste into AI tools, sync to personal storage, code repositories, unsanctioned SaaS) as well as email and removable media, and confirming whether the platform can even observe each one. We assess this alongside the insider threat scenario, since the person leaking is often authorised. The finding is written against the uninspected channel. This is part of how we test where sensitive data can leave.