Phase 5 – Real Ops and Future State Real-World DLP Incident Scenarios – Exchange Online. Overview Everything built across this series – the operating model, the RBAC personas, the triage...
Read morePhase 5 – Real Ops and Future State Metrics That Matter. Overview If the first question your leadership asks about the DLP programme is “how many alerts did we get...
Read morePhase 4 – Tools and Architecture Automation Patterns for DLP Response. Overview Automation in DLP incident response is frequently over-promised and under-scoped. Teams automate the easy parts – notifications, ticket...
Read moreLast time we uncovered why a search for "admin" can miss a page titled "Administrator". In this post, we fix it - with a small, purpose-built tool that teaches your...
Read moreEver searched for "admin" and watched the page that's actually about Administrators sink to the bottom of the results? It's tempting to assume something's broken — but usually nothing is....
Read morePhase 4 – Tools and Architecture DLP Integration Patterns. Overview Post 09 covered which tooling model fits your operating model. This post covers how to build the connections between those...
Read morePhase 4 – Tools and Architecture The DLP Tooling Decision Model. Overview Every DLP team eventually hits the same question: where should DLP incidents live? Defender XDR? SIEM (e.g. Sentinel)?...
Read morePurview DLP Incident Management (IM) – From Alert to Outcome
Read morePhase 3 – Investigation Context Is the Real Investigation Engine. Overview A DLP investigation that starts and ends with the alert is not an investigation. It is a policy match...
Read morePhase 3 – Investigation The DLP Triage Framework. Overview A DLP alert arrives. The analyst opens it. Now what? Most teams have an instinct at this point to look at...
Read more