Classification scheme
A small number of clearly named sensitivity levels, each illustrated with documents from your own business, so anyone can place a file in a few seconds.
Most people picture a data leak as the work of an outside hacker. In smaller Turkish companies the everyday version is far more ordinary. A sales representative about to join a competitor forwards the customer list to a personal Gmail account. An architecture practice shares a project folder with “anyone with the link” and forgets about it for months. A polyclinic employee copies a patient list onto a USB stick to finish some work at home. Often nobody means any harm; the boundary was simply never drawn. Data leak prevention, usually shortened to DLP, draws that boundary. We first agree with you which information would genuinely hurt if it escaped: quotations and cost sheets, patient and personnel records, technical drawings. Then we define rules that recognise that information and adjust the exits accordingly, namely email, cloud sharing, removable media and personal cloud accounts. In most organisations the software is already part of the subscription, as Microsoft Purview or Google Workspace DLP. What is missing is a rule set tuned so that normal work carries on undisturbed.
Rules only work when they respect how people do their jobs. Overly strict controls push staff towards workarounds, and those workarounds are harder to see than the original problem.
A small number of clearly named sensitivity levels, each illustrated with documents from your own business, so anyone can place a file in a few seconds.
Labels in Microsoft Purview that mark documents and, where appropriate, encrypt them and restrict who may open them. Files containing national ID numbers or IBANs can be labelled automatically.
A prompt or a block when labelled or sensitive content is about to go to a personal address or an unknown domain. Users can override with a justification, which is recorded.
Anonymous links restricted, expiry dates on external shares and regular sharing reports. Design and engineering offices get a dedicated, controlled space for exchanging files with clients.
Removable drives set to read-only or encrypted-only, and uploads of sensitive files to personal cloud storage or web messengers restricted.
Unusual bulk downloads or new forwarding rules in the weeks before someone leaves become visible. How such signals are handled is agreed in advance with HR and your legal adviser.
DLP goes live in phases, so no workflow breaks without warning.
A workshop with management and team leads: which information would cause harm if it got out, where it is stored and who it is normally shared with.
Rules run in logging mode only. After a few weeks you can see which data leaves through which channel, how often, and which of those flows are legitimate.
Users first receive explanatory tips; blocking is reserved for clearly risky cases. Necessary exceptions are recorded.
A short monthly report on incidents and overrides, with rules adjusted when new projects or partners appear.
DLP is a guard rail, not an accusation. Most employees simply do not realise that emailing a certain file crosses a line. A well-worded prompt reminds them without blame, while a deliberate attempt to take data becomes visible. Getting that balance right achieves more than switching on the harshest rules.
No. The rules look for types of content, such as an ID number or a labelled document; nobody browses mailboxes. Who may view which events is decided upfront. We suggest involving HR and your legal adviser in informing employees and assessing the set-up from a KVKK perspective.
Business Premium covers core DLP for mail and cloud sharing plus sensitivity labels. Device-level DLP and automatic labelling need higher plans or add-ons. We show what your current plan can do and recommend extra licences only when they are clearly justified.
It should not. Legitimate exchanges get expiring, password-protected links or a separate space per client. The observation phase is designed precisely to spot these flows and build the right exceptions.
Within what existing logs allow, we extract downloads, shares and forwarding rules and preserve the records. How they are used is for your legal adviser to decide. If logging was not enabled beforehand, visibility into the past is limited, which is exactly where a DLP set-up earns its keep.
Tell us which information matters most and which platform you use. We will show what your current licence already allows.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.