Installs into .claude/skills of the current project.
Are you the author of Dlp Pro?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/aicodedecode-dlp-pro)
---
name: dlp-pro
description: Design data loss prevention — data discovery, classification, policy enforcement across endpoint, network, and cloud.
category: security
---
## Overview
DLP protects data in use, in motion, and at rest: discovering where sensitive data lives, classifying it, and enforcing policies that prevent exfiltration — accidental or malicious. It is one of the highest-friction security controls when done badly (blocking legitimate work) and one of the most valuable when done well (catching the spreadsheet emailed to a personal account at 11 PM).
This skill covers the pragmatic DLP program: discovery and classification first, policy design that respects workflows, phased enforcement, and tuning that keeps false positives from destroying credibility.
DLP without classification is just blocking keywords: start by knowing what data you have and where it lives. The discovery phase — scanning file shares, endpoints, and cloud storage for PII, credentials, and IP — usually surprises everyone and justifies the entire program before a single block policy exists.
## When to use
- Preventing exfiltration of PII, credentials, source code, or regulated data.
- Meeting compliance requirements for data protection (GDPR, PCI DSS, HIPAA).
- Responding to insider-threat concerns or past exfiltration incidents.
- Building the data-classification program that DLP depends on.
## Core concepts
- **Discover → classify → protect.** In that order. Policies written before discovery protect imaginary data while real data walks out unmonitored.
- **Classification that humans can apply.** Three to four levels (Public, Internal, Confidential, Restricted) with clear examples beat ten levels nobody understands. Auto-classification assists; humans decide for ambiguous cases.
- **The three states:** data in use (endpoint: copy to USB, paste to web), in motion (network/email/cloud upload), at rest (file shares, databases, SaaS). Cover all three or accept the documented gap.
- **Policy modes:** monitor → warn/justify → block. Start in monitor to learn real workflows, move to block only where false positives are near zero. Blocking legitimate work is how DLP programs get disabled.
- **Content-aware vs context-aware.** Content inspection (regex, fingerprinting, ML classification) catches the data itself; context (user, destination, volume, time) catches the suspicious behavior. Combine both.
- **Insider-threat alignment.** DLP telemetry (mass downloads, off-hours access, personal-cloud uploads) feeds insider-risk programs — design the data sharing and privacy guardrails up front.
- **Privacy and legal boundaries.** Employee monitoring has legal constraints that vary sharply by jurisdiction. Involve legal and HR before enforcement, especially for content inspection of personal communications.
- **Exact data matching (EDM) and fingerprinting.** For structured sensitive data (customer databases, source code), fingerprinting beats regex — fewer false positives, harder to evade with rewording.
- **Fingerprinting thresholds.** Tune match thresholds per data type — too loose floods analysts, too tight misses exfiltration. Validate thresholds against real samples before enforcement.
- **Endpoint vs network coverage gaps.** Remote workers off-VPN bypass network DLP; unmanaged devices bypass endpoint DLP. Design coverage for the actual workforce topology.
## Practical workflow
1. **Discover:** scan endpoints, file shares, cloud storage, and SaaS for sensitive data patterns. Document where Confidential/Restricted data actually lives — expect surprises.
2. **Classify:** establish the classification scheme with business owners; deploy auto-classification for obvious cases; train teams on manual labeling for the rest. Classification is a business decision with security input, not vice versa.
3. **Design policies:** per data class and channel — e.g., Restricted data to personal cloud storage = block; Confidential to external email = warn with justification. Keep the initial policy set small.
4. **Monitor first:** run all policies in monitor/audit mode for 4–8 weeks. Analyze the hits: legitimate workflows to allowlist, true risks to prioritize, broken patterns to fix.
5. **Enforce progressively:** move to warn/justify, then block, policy by policy, watching helpdesk volume and user feedback. Each enforcement step needs a communication.
6. **Tune and investigate:** review incidents daily at first; build the investigation workflow (who triages, what constitutes a real incident, when does HR/legal get involved); tune patterns quarterly.
### Quick wins
- Run discovery scans this month — the findings justify the program
- Review last quarter's DLP alerts: what fraction were true positives?
- Confirm legal/HR sign-off covers current enforcement modes before expanding
### Sustaining the practice
- Review policy hit rates monthly; tune or retire noisy policies
- Re-run discovery scans quarterly — data sprawls continuously
- Audit classification accuracy by sampling labeled documents
- Report prevented incidents (with business context) to sustain sponsorship
### Metrics that prove it works
- True-positive rate per policy (target: high before any blocking)
- Incidents of actual exfiltration attempts detected and stopped
- User-impact metrics: blocked legitimate actions, helpdesk tickets per policy
- Coverage: % of sensitive-data locations under DLP monitoring
## Common pitfalls
- **Blocking on day one.** Enforcing untested policies breaks legitimate workflows and gets DLP ripped out. Monitor first, always.
- **Regex-only detection.** Social security numbers match lots of innocent numbers. Fingerprinting and context beat naive patterns.
- **Ignoring the cloud.** Endpoint+network DLP with no CASB/SaaS coverage misses where modern work actually happens.
- **No legal/HR involvement.** Employee content monitoring without legal review creates liability. Involve them before enforcement, not after a complaint.
- **Alerting without investigation capacity.** DLP generates nuanced alerts needing human judgment. Without triage staffing, alerts rot and real incidents hide.
- **Forgetting data at rest.** Blocking exfiltration while terabytes of Restricted data sit on open file shares is backwards. Remediate the sprawl too.
- **One-size-fits-all policies.** Engineering source code and HR PII need different policies. Tailor by data type and team workflow.
- **Declaring victory at deployment.** DLP is a tuning program, not a product install. Budget analyst time permanently.
- **DLP on encrypted channels without a plan.** TLS 1.3 and DoH blind network inspection; endpoint agents and CASB API coverage are the answer, not wishful thinking.
- **Treating DLP alerts as HR cases prematurely.** Most DLP hits are mistakes or broken workflows. Investigate as security first; involve HR only when intent is established.