DLP can match data patterns but cannot reliably infer the business purpose of a transfer
A tool can recognise that something looks like a card number. It cannot tell whether sending it was legitimate.
The same file going to the same address is routine in one context and a breach in another, and the difference is business intent, which is not present in the data. That is why tuning these systems is endless and why they are best positioned as a prompt for a human decision rather than an automated verdict.
More on Data security
- Classification should change handlingThe label throws the points
- Tokenisation changes what systems need to holdHand over the ticket, not the coat
- Data lineage explains where sensitive data travelsFollow the dye
- Data residency is not automatic securityThe line goes round the building
- Retention is a security controlWhat you no longer hold
- Data access logs need object contextRead a record. Which one?
