4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Solutions | Data Loss Prevention

Data Loss Prevention for Sydney Businesses

Data loss prevention (DLP) is a set of controls that finds sensitive information in your emails, files and devices, then stops it leaving the business in ways you have not approved. 4iT designs, builds and runs DLP for Sydney SMEs using the tools you already pay for, starting with Microsoft 365 and Sophos. Most breaches we see are not clever attacks, they are an ordinary person sending the wrong file to the wrong address, and that is exactly what DLP is built to catch.

Sydney MSP

Greater Sydney, NSW

notifiable data breaches reported to the OAIC in 2025
notifications caused by human error (Jul to Dec 2025)
of 670
monitor mode before enforcement
4- weeks
extra licence cost for DLP in Sophos Endpoint and Email
$

Office laptop and external drive on a desk, representing files leaving a business network.

Key facts

  • Australian organisations reported 1,205 notifiable data breaches to the OAIC in the 2025 calendar year, the highest since the scheme began in 2018 and 8 per cent up on the 1,112 reported in 2024.
  • Human error caused 194 of the 670 notifications in the July to December 2025 period, including 66 cases of personal information sent to the wrong email recipient and 10 caused by failing to use BCC.
  • Microsoft 365 Business Premium includes Purview DLP for Exchange Online, SharePoint, OneDrive and Teams, but not Endpoint DLP, which needs Microsoft 365 E5 or the Purview Suite add-on.
  • Sophos includes DLP in Sophos Endpoint and in Sophos Email at no extra licence cost, using SophosLabs Content Control Lists for things like credit card and passport numbers.
  • A workable SME rollout runs in three stages: discover what sensitive data you hold, run policies in monitor mode for four to six weeks, then switch the high confidence rules to block.
  • 4iT delivers DLP as a managed service, including policy design, tuning, staff communications and ongoing review.

What is data loss prevention?

Data loss prevention is technology that inspects content against rules you define, then allows, warns, logs or blocks the transfer. The rules look for patterns such as Australian tax file numbers, Medicare numbers, credit card numbers, bank account details or your own document markings, and the transfer might be an email to an external address, a file dragged onto a USB stick, an upload to a personal cloud drive, or a document shared out of SharePoint with a link that works for anyone.

The important word is content. Antivirus asks whether a file is malicious. DLP asks whether a file is yours to send. Those are different questions and they need different tooling, which is why a business can be fully patched, running EDR and still lose a client list to an outbound email.

Why do Australian SMEs need DLP?

Under the Notifiable Data Breaches scheme, an accidental disclosure of personal information is a breach in the same way a ransomware attack is, and it carries the same assessment and notification obligations. The OAIC’s own numbers make the point: in the six months to December 2025, 194 of 670 notifications came from human error, with the single largest category being personal information emailed to the wrong recipient.

None of those were sophisticated. Someone hit send with the client spreadsheet attached, or put 300 addresses in the To field. DLP is the only control that gets in the way at that exact moment, and it is the reason we now put it in front of insurers and auditors as evidence of reasonable steps under APP 11.

What sensitive data does an SME actually hold?

Most SMEs underestimate this, and the discovery pass is usually the most uncomfortable part of the project. An accounting practice holds tax file numbers and bank details for every client. A medical or allied health practice holds Medicare numbers and clinical notes. A law firm holds matter files that are privileged. A recruiter holds identity documents. A trades business holds a customer database that is the whole value of the business if a departing salesperson walks off with it.

Across the Sydney SMEs we support, the two places sensitive data collects most are shared mailboxes nobody has audited for years, and a “Clients” folder in SharePoint that started tidy and stopped being tidy in about 2019. Start there.

How does 4iT implement data loss prevention?

We run DLP as a staged programme rather than a switch, because policies that block on day one get turned off by day three. The stages are:

  1. Discovery. We scan Microsoft 365 and your file locations to find where sensitive data actually lives, and agree with you what matters most.
  2. Policy design. We write the rules against real data types, scoped to the people and channels that need them, not the whole business at once.
  3. Monitor mode. Policies run in audit only for four to six weeks. Every alert is a conversation about whether it is a genuine risk or a normal business process we have not accounted for.
  4. Tune and enforce. High confidence rules move to block, medium confidence rules move to warn with a user override, and the rest stay as reporting.
  5. Run and review. We review alerts, adjust rules as the business changes, and report on what has been stopped.

The user override matters more than people expect. A policy tip that says “this looks like it contains bank details, confirm before sending” stops accidents without stopping work, and it trains staff far more effectively than an annual slide deck.

Which DLP tools do we use?

We build DLP on the platform you already own where we can. In Microsoft 365, Purview DLP covers email, SharePoint, OneDrive and Teams and is included with Business Premium, while endpoint controls such as blocking copies to USB or uploads to personal cloud storage require Microsoft 365 E5 or the Purview Suite add-on. For endpoint and email control outside that licensing, Sophos includes DLP in Sophos Endpoint and Sophos Email, with SophosLabs Content Control Lists covering common financial and identity data types.

In practice a lot of our clients end up with both: Purview for data at rest and in Microsoft 365, Sophos for what happens on the laptop. We are a Sophos partner and a Microsoft partner, so the recommendation follows the licensing you hold rather than a product we are trying to move.

Frequently Asked Questions

Partly. Microsoft 365 Business Premium and E3 include Purview DLP for Exchange Online, SharePoint and OneDrive, so you can build policies that stop sensitive information being emailed or shared externally. Endpoint DLP, which covers copying to USB, printing and uploads from the device, requires Microsoft 365 E5 or the Purview Suite add-on. We check your current licensing before recommending anything.

Not if it is rolled out properly. We run every policy in monitor mode first, so we can see what normal work looks like before anything blocks. Most rules end up as a warning with an override rather than a hard block, which stops the accidents while leaving genuine business exceptions possible.

For a typical 20 to 50 person SME, expect two to three weeks to discovery and policy design, then four to six weeks in monitor mode before enforcement. Rushing the monitoring phase is the most common reason DLP projects get abandoned.

Yes. Insurers increasingly ask about controls over sensitive data, and DLP reporting gives you evidence of the reasonable steps required under Australian Privacy Principle 11. It also produces the audit trail you need when assessing whether an incident is a notifiable data breach.

It can stop the obvious routes and record the rest. Endpoint DLP blocks copies to removable media and uploads to personal cloud storage, and email policies catch the classic "sending it to my personal Gmail" move. A determined insider with enough time can still photograph a screen, which is why DLP sits alongside offboarding process and access control rather than replacing them.

If you want to know what sensitive data your business is holding and how easily it could walk out the door, we will run a discovery pass and show you. Get in touch to arrange a data loss prevention review.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting