Classification
Information is sorted by value, typically public, internal, confidential and restricted. Without tiers everything is guarded equally, which in reality means badly.
The order is fixed: locate the data, narrow access, shut the exits, watch for attempts. Leave out the first stage and the others achieve little.
Information is sorted by value, typically public, internal, confidential and restricted. Without tiers everything is guarded equally, which in reality means badly.
BitLocker for laptops and hardware-encrypted pen drives. Losing an encrypted laptop means buying a new one; losing an unencrypted one can mean a notifiable breach.
Approved USB devices only, a record of every connection and a total block for teams working with sensitive records, such as HR or patient registration.
Controls on outgoing attachments and on OneDrive and SharePoint links, with automatic encryption for messages containing PESEL, ID card or bank account numbers.
Sensitivity labels and Microsoft Purview policies, or their equivalent in another tool, written for your own classification instead of a stock template.
A procedure for when an attempted leak is caught, plus a periodic report of what was stopped, who triggered it and how it was resolved.
Enforcement waits until we understand how information really flows. Switching it on earlier would block legitimate work.
Identifying the small slice of data that truly matters: the customer base, price agreements, technical documentation, HR and medical files.
Encrypted laptops, restricted USB in key teams and removal of stale sharing links.
Policies run in report-only mode for an agreed period, revealing the real routes information takes.
Blocking begins once false alarms are few enough for each to be reviewed by a person.
Leaks seldom look like theft. Far more often a departing salesperson forwards the client list to a private inbox “for reference”, or someone in HR sends a payroll summary over a personal messenger because it is faster. Well-tuned DLP helps catch cases like these before they become an incident.
Not if the rules are written carefully and have been through the watch period. An invoice with a customer's NIP is routine correspondence. We aim rules at genuinely sensitive patterns, say dozens of PESEL numbers in a single file, not at every document with company details.
Often in part. Many Microsoft 365 plans include DLP features and sensitivity labels, but the scope depends on the plan. We use what you already pay for and only discuss an extra product for data of exceptional value.
Most of the protection has to be in place beforehand: no copying to private media, logging of large CRM exports and prompt removal of access. If data does leave, the DLP logs become material for your lawyer, who makes the legal assessment.
Yes, Polish employment law requires staff to be informed about email monitoring. DLP searches for patterns such as PESEL or card numbers rather than reading messages, but the form and wording of the notice should be agreed with a lawyer or HR. We describe the technical side of the solution.
Tell us which information matters most and which tools your team relies on. We will propose where to start.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.