4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Partners | Sophos partner | Sophos Data Loss Prevention

Sophos Data Loss Prevention

Sophos data loss prevention is built into Sophos Endpoint and Sophos Email, so it inspects files and messages against content rules and then allows, warns, logs or blocks the transfer. There is no separate DLP product to buy and no extra agent to deploy. 4iT is a Sophos partner in Sydney, and we configure, tune and manage Sophos DLP policies for SMEs across the Hills District, North Shore and Sydney metro.

Sydney MSP

Greater Sydney, NSW

extra cost for DLP
$ console
minimum file size scanned
bytes
reporting posture before enforcement
4- weeks
Content Control List matches needed before a rule fires

Laptop with an external USB drive plugged in on an office desk.

Key facts

  • Sophos DLP is included in Sophos Endpoint and Sophos Email at no additional licence cost, and is configured in Sophos Central rather than bought separately.
  • Policies are built from two rule types: file rules, which act on file type or name, and content rules, which inspect the contents of a file against a Content Control List.
  • SophosLabs maintains the Content Control Lists, covering common financial and personally identifiable data such as credit card numbers, postal addresses and identity document numbers.
  • Rules can target specific destinations, including removable storage, optical media, browser uploads and instant messaging clients.
  • Actions are allow, allow on user acceptance, or block, and a blocking rule always takes priority over a rule that allows on acceptance.
  • Known limits: files under 8 bytes are not scanned, and webmail message body content and file downloads are not inspected, so email needs Sophos Email data control rather than endpoint DLP alone.

What does Sophos data loss prevention actually do?

Sophos DLP watches what happens to files on a managed Windows or macOS device and what leaves through email, then applies the rules you have set. When someone copies a spreadsheet full of customer bank details to a USB stick, the endpoint policy fires. When someone attaches the same spreadsheet to an email heading outside the business, the Sophos Email data control policy fires. The two are configured separately and both matter, which is a detail plenty of businesses miss when they turn on the endpoint half and assume email is covered.

The detection is content aware. It is not just looking at the file name, it is reading the contents and matching them against a definition, which is why a file called “notes.txt” containing 40 credit card numbers still triggers.

How are Sophos DLP rules built?

A Sophos DLP policy contains one or more rules, and a file that matches any rule in the policy violates the policy. Each rule has conditions, an action and optional exclusions.

  • File rules act on file type or name. Useful for blunt controls, for example blocking database files from being copied to removable storage.
  • Content rules act on what is inside the file, matched against one or more Content Control Lists, with a configurable number of matches before the rule fires. Set the match count to two and a single stray number will not trigger it.

You can start from a Sophos template or build a custom policy. In our experience the templates are a decent starting point for the obvious data types and a poor fit for anything specific to the business, so most of our clients end up with a custom Content Control List covering their own client reference format, matter numbers or document markings.

Does Sophos DLP cover email?

Email is handled by data control policies in Sophos Email, not by the endpoint DLP policy. The endpoint policy does catch attachments in some desktop clients, but message content in webmail is explicitly not scanned, so relying on it for email is a gap rather than a control. If email is where your risk sits, and for most SMEs it is, the Sophos Email data control policy is the piece that does the work, and it uses the same Content Control Lists so the definitions stay consistent across both.

How does 4iT roll out Sophos DLP?

We never start with blocking. The first pass is discovery and rule design against the data your business actually holds, then the policies run in a reporting posture so we can see how people work. Four to six weeks of that tells us which rules are safe to enforce and which would break a legitimate process, such as the bookkeeper who genuinely does email remittance files to a client every Thursday.

From there, the high confidence rules move to block, the borderline ones move to allow on user acceptance so the person gets a prompt and a moment to think, and the rest stay as reporting. We then review the alerts as part of your managed service rather than handing you a console and wishing you luck.

One practical note from doing this repeatedly: content scanning reads the whole file, so scan time rises with file size. If a client works with very large exports, we scope the rules rather than pointing them at everything and letting the device crawl.

Frequently Asked Questions

No. Data loss prevention is part of Sophos Endpoint and Sophos Email, and is configured in the Sophos Central console under the relevant policy. If you already run Sophos Endpoint through 4iT, the capability is sitting there waiting to be configured.

A Content Control List is a definition of a type of data, such as a credit card number, a postal address or an identity document number. SophosLabs maintains a library of them, you cannot edit the SophosLabs ones, and you can create your own for data types specific to your business.

Yes, a content or file rule can block a transfer when the destination is removable storage. If you want to stop USB devices being used at all rather than control what goes onto them, that is Sophos peripheral control, which is a separate policy and often deployed alongside DLP.

They solve overlapping problems from different angles. Purview is strongest across Microsoft 365 data at rest and in transit, and its endpoint controls require Microsoft 365 E5 or the Purview Suite add-on. Sophos DLP is included with the endpoint and email protection you already run and applies on the device regardless of Microsoft licensing. Plenty of our clients run both, and we scope which does what rather than duplicating rules in two consoles.

Yes, Sophos endpoint DLP policy applies to both Windows and macOS devices managed through Sophos Central, though the supported destinations and applications differ between the platforms, so we test the rules on the actual device fleet before enforcing anything.

If you are already running Sophos and have never turned DLP on, you are paying for a control you are not using. Get in touch and we will review your Sophos Central policies and show you what it would catch.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting