Data Loss Prevention: Control How Sensitive Data Is Used and Shared

Sensitive information does not have to be stolen to create risk. It can be copied to a USB drive, uploaded to a personal cloud account, sent through an unapproved application, printed, or transferred outside the organization by an authorized user.

ProCirrus Data Loss Prevention (DLP) provides controls at the endpoint and server level to monitor and manage how sensitive information is accessed, copied, moved, and transmitted.

What Our DLP Service Does

Our DLP service uses an updated security agent installed on supported endpoints and servers to evaluate data activity as it occurs.

Policies can be configured to identify sensitive information and then allow, block, alert on, or log specific actions based on the user, device, application, data type, and activity being performed.

Data Classification

DLP can identify sensitive information such as:

  • Social Security numbers and personally identifiable information

  • Financial information

  • Protected health information

  • Legal and client documents

  • Confidential business information

  • Other defined or classified data

Policies can inspect the content within files rather than relying only on filenames or folder locations.

Data Movement Controls

Policies can control how sensitive information is moved or shared, including:

  • Copying files to USB drives or removable storage

  • Uploading files through a web browser

  • Transferring data to personal cloud-storage services

  • Copying or pasting sensitive information into applications

  • Printing protected documents

  • Moving information through local applications

  • Uploading sensitive information to unapproved AI or web services

Each activity can be handled differently depending on your organization's requirements.

Policy-Based Enforcement

DLP policies can evaluate several factors before deciding whether an action should be permitted.

These can include:

  • User identity — who is accessing the information

  • Endpoint — which workstation or server is being used

  • Data sensitivity — what type of information is involved

  • Application — which application or website is being used

  • Action — whether the user is viewing, copying, printing, uploading, or transferring the information

This allows organizations to apply targeted controls rather than simply blocking entire applications or categories of activity.

For example, a policy could:

Allow employees to open and edit financial spreadsheets, allow approved internal sharing, block copying those files to USB storage, and alert when a user attempts to upload them to a personal email account.

Device Control

The service can also control removable storage devices such as:

  • USB drives

  • External hard drives

  • Connected phones and storage devices

Organizations can define whether removable media is allowed, restricted, monitored, or blocked based on policy.

Monitoring and Audit Logging

Data transfer attempts can be logged and associated with the user and endpoint involved.

This provides visibility into:

  • What information was involved

  • Which user performed the action

  • Which endpoint was used

  • Where the information was being moved

  • Which application or transfer method was involved

  • Whether the activity was allowed or blocked

Organizations can also begin with monitoring-only policies before introducing stricter enforcement.

Extending Security to the Data Itself

Traditional security controls help protect systems and user access.

DLP adds another layer by controlling what authorized users can do with sensitive information after they have access to it.

With ProCirrus Data Loss Prevention, organizations can establish clear policies around how sensitive data is handled and enforce those policies directly on the endpoints and servers where users interact with that information.

Previous
Previous

User Activity Productivity Monitoring

Next
Next

Leverage AI without exposing your business