Data Loss Prevention: Control How Sensitive Data Is Used and Shared
Sensitive information does not have to be stolen to create risk. It can be copied to a USB drive, uploaded to a personal cloud account, sent through an unapproved application, printed, or transferred outside the organization by an authorized user.
ProCirrus Data Loss Prevention (DLP) provides controls at the endpoint and server level to monitor and manage how sensitive information is accessed, copied, moved, and transmitted.
What Our DLP Service Does
Our DLP service uses an updated security agent installed on supported endpoints and servers to evaluate data activity as it occurs.
Policies can be configured to identify sensitive information and then allow, block, alert on, or log specific actions based on the user, device, application, data type, and activity being performed.
Data Classification
DLP can identify sensitive information such as:
Social Security numbers and personally identifiable information
Financial information
Protected health information
Legal and client documents
Confidential business information
Other defined or classified data
Policies can inspect the content within files rather than relying only on filenames or folder locations.
Data Movement Controls
Policies can control how sensitive information is moved or shared, including:
Copying files to USB drives or removable storage
Uploading files through a web browser
Transferring data to personal cloud-storage services
Copying or pasting sensitive information into applications
Printing protected documents
Moving information through local applications
Uploading sensitive information to unapproved AI or web services
Each activity can be handled differently depending on your organization's requirements.
Policy-Based Enforcement
DLP policies can evaluate several factors before deciding whether an action should be permitted.
These can include:
User identity — who is accessing the information
Endpoint — which workstation or server is being used
Data sensitivity — what type of information is involved
Application — which application or website is being used
Action — whether the user is viewing, copying, printing, uploading, or transferring the information
This allows organizations to apply targeted controls rather than simply blocking entire applications or categories of activity.
For example, a policy could:
Allow employees to open and edit financial spreadsheets, allow approved internal sharing, block copying those files to USB storage, and alert when a user attempts to upload them to a personal email account.
Device Control
The service can also control removable storage devices such as:
USB drives
External hard drives
Connected phones and storage devices
Organizations can define whether removable media is allowed, restricted, monitored, or blocked based on policy.
Monitoring and Audit Logging
Data transfer attempts can be logged and associated with the user and endpoint involved.
This provides visibility into:
What information was involved
Which user performed the action
Which endpoint was used
Where the information was being moved
Which application or transfer method was involved
Whether the activity was allowed or blocked
Organizations can also begin with monitoring-only policies before introducing stricter enforcement.
Extending Security to the Data Itself
Traditional security controls help protect systems and user access.
DLP adds another layer by controlling what authorized users can do with sensitive information after they have access to it.
With ProCirrus Data Loss Prevention, organizations can establish clear policies around how sensitive data is handled and enforce those policies directly on the endpoints and servers where users interact with that information.