4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

What Is Data Loss Prevention (DLP)?

Data loss prevention (DLP) is a security control that inspects the content of files and messages, compares it against rules describing sensitive information, and then allows, warns, logs or blocks the transfer. It is the control that stops a spreadsheet of customer bank details being emailed to the wrong address or copied to a USB stick. Antivirus asks whether a file is dangerous. DLP asks whether the file is yours to send.

Laptop on an office desk with a USB flash drive beside it.

Key facts

  • DLP works on content, not just file names, so a file called "notes.txt" containing 200 credit card numbers still triggers a rule.
  • The three places DLP is applied are the endpoint (the laptop), email, and cloud storage such as SharePoint and OneDrive.
  • Australian organisations reported 1,205 notifiable data breaches to the OAIC in 2025, an 8 per cent rise on the 1,112 reported in 2024 and the highest since the scheme started in 2018.
  • Human error caused 194 of the 670 breaches notified between July and December 2025, and the single biggest category was personal information emailed to the wrong recipient, at 66 notifications.
  • Microsoft 365 Business Premium includes Purview DLP for email, SharePoint, OneDrive and Teams, but Endpoint DLP requires Microsoft 365 E5 or the Purview Suite add-on.
  • Sophos includes DLP in Sophos Endpoint and Sophos Email, using SophosLabs Content Control Lists to define what sensitive data looks like.

What does data loss prevention actually mean?

In plain terms, data loss prevention means putting a check between sensitive information and the exits. The exits are email, removable media, printing, personal cloud storage, messaging apps and external sharing links. The check is a rule that says "if this looks like a tax file number, or a credit card number, or one of our client matter files, then do something about it".

The rules are built from data definitions. Microsoft calls them sensitive information types, Sophos calls them Content Control Lists, and both ship with a library covering the obvious things such as card numbers, identity documents and bank details. You can add your own, which is where it gets genuinely useful for an SME, because your risk is rarely the generic stuff. It is your client list, your pricing file, your matter numbers.

What problem is DLP solving?

The biggest source of accidental data loss in Australia is someone sending information to the wrong person. That is not a guess. In the six months to December 2025, the OAIC recorded 194 human error breaches out of 670 total notifications, made up of things like 66 emails to the wrong recipient, 59 unintended releases or publications, and 10 caused by nobody using BCC.

Every one of those is a notifiable data breach with the same obligations as a ransomware attack: assess it, work out whether serious harm is likely, notify the OAIC and the affected individuals if it is. The difference is that a ransomware attack takes a skilled attacker, while a mis-addressed email takes a distracted person and Outlook's autocomplete. We see the second one far more often.

How does DLP work in practice?

A DLP policy has three parts: what to look for, where it applies, and what to do about it.

What to look for is the data definition, usually with a match threshold so a single stray number does not set it off. Where it applies is the scope: which people, which channels, which destinations. What to do about it is the action, and this is where most projects succeed or fail. The available actions are usually monitor only, warn the user with the option to proceed, or block outright.

The right answer for most SMEs is a mix. Block for the things that are never legitimate, such as a client database being copied to removable media. Warn for the things that are usually accidents but occasionally genuine, such as an email with bank details going outside the business. Monitor for everything else, so you have a picture rather than a wall.

Do small businesses need DLP, or is it an enterprise thing?

DLP was an enterprise product a decade ago because it needed a dedicated appliance, a consultant and a long project. That is no longer true. If you run Microsoft 365 Business Premium, Purview DLP is already in your licence and covers email, SharePoint, OneDrive and Teams. If you run Sophos Endpoint, DLP is already in your licence and covers the device.

The barrier now is not cost, it is that nobody has turned it on and tuned it. Across the Sydney SMEs we support, the most common finding when we do a discovery pass is a shared mailbox nobody has reviewed in years and a SharePoint "Clients" folder that started tidy and drifted. The tooling was sitting there the whole time.

There is a real counterpoint, though, and it deserves saying: a badly implemented DLP rollout is worse than none. Policies that block on day one get switched off by day three, and then nobody trusts the control. The fix is not clever rules, it is patience. Run everything in monitor mode for four to six weeks first.

What DLP will not do

DLP is a control against accidents and casual insider behaviour. It is not a control against a determined attacker who already has domain admin, and it is not a substitute for access control. If everyone in the business can open the payroll folder, DLP will dutifully let them, because the person opening it is authorised.

It also has practical gaps worth knowing about. Sophos endpoint DLP does not scan webmail message content or file downloads, which is why email needs its own data control policy rather than relying on the endpoint. Microsoft's endpoint controls only apply to onboarded devices. And someone can always photograph a screen. DLP raises the effort and catches the ordinary failures, which is most of them.

Frequently asked questions

What is the difference between DLP and encryption?

Encryption protects data from someone who should not have it, by making it unreadable without a key. DLP decides whether the data should be going where it is going in the first place. They work together: a DLP rule can trigger encryption on an outbound email rather than blocking it, which is often the better outcome for a business that legitimately sends sensitive files.

Is DLP included in Microsoft 365?

Purview DLP for Exchange Online, SharePoint, OneDrive and Teams is included with Microsoft 365 Business Premium and E3. Endpoint DLP, which covers copying to USB, printing and uploads from the device, requires Microsoft 365 E5 or the Purview Suite add-on. Check what you actually hold before assuming either way.

How long does it take to set up DLP?

For a 20 to 50 person business, allow two to three weeks for discovery and policy design, then four to six weeks running in monitor mode before you enforce anything. The monitoring phase is not optional padding. It is where you find out that your bookkeeper genuinely does email remittance files every Thursday.

Will DLP stop a departing employee taking the client list?

It stops the easy routes and records the rest. Endpoint rules block copies to USB drives and uploads to personal cloud storage, and email policies catch the classic forward to a personal address. It works best alongside a proper offboarding process, because the most reliable control is removing access on the day someone leaves.

Does DLP help with Privacy Act compliance?

Yes. Australian Privacy Principle 11 requires reasonable steps to protect personal information from misuse and unauthorised disclosure, and DLP policy plus its reporting is direct evidence of those steps. It also gives you the audit trail you need when deciding whether an incident meets the notifiable data breach threshold.

If you are not sure what sensitive data your business holds or how easily it could leave, that is the first thing worth finding out. We run a discovery pass, show you what is there, and tell you which of the tools you already pay for can control it.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including data loss prevention, Microsoft 365 hardening, the Essential Eight, and incident response, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Book a meeting

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details