Service · Cybersecurity

Data leak prevention (DLP)

Most people picture a data leak as the work of an outside hacker. In smaller Turkish companies the everyday version is far more ordinary. A sales representative about to join a competitor forwards the customer list to a personal Gmail account. An architecture practice shares a project folder with “anyone with the link” and forgets about it for months. A polyclinic employee copies a patient list onto a USB stick to finish some work at home. Often nobody means any harm; the boundary was simply never drawn. Data leak prevention, usually shortened to DLP, draws that boundary. We first agree with you which information would genuinely hurt if it escaped: quotations and cost sheets, patient and personnel records, technical drawings. Then we define rules that recognise that information and adjust the exits accordingly, namely email, cloud sharing, removable media and personal cloud accounts. In most organisations the software is already part of the subscription, as Microsoft Purview or Google Workspace DLP. What is missing is a rule set tuned so that normal work carries on undisturbed.

Three or four labels
from public to strictly confidential
Monitoring first
at least four weeks before any block
Purview
or Google DLP, usually already licensed
Nudge before block
a warning is often enough

What the work covers in practice

Rules only work when they respect how people do their jobs. Overly strict controls push staff towards workarounds, and those workarounds are harder to see than the original problem.

Agree the scope with the engineer who will do the work

Classification scheme

A small number of clearly named sensitivity levels, each illustrated with documents from your own business, so anyone can place a file in a few seconds.

Sensitivity labels

Labels in Microsoft Purview that mark documents and, where appropriate, encrypt them and restrict who may open them. Files containing national ID numbers or IBANs can be labelled automatically.

Mail controls

A prompt or a block when labelled or sensitive content is about to go to a personal address or an unknown domain. Users can override with a justification, which is recorded.

Cloud sharing

Anonymous links restricted, expiry dates on external shares and regular sharing reports. Design and engineering offices get a dedicated, controlled space for exchanging files with clients.

Devices and USB

Removable drives set to read-only or encrypted-only, and uploads of sensitive files to personal cloud storage or web messengers restricted.

Leavers

Unusual bulk downloads or new forwarding rules in the weeks before someone leaves become visible. How such signals are handled is agreed in advance with HR and your legal adviser.

How we approach the job, from first call to handover

DLP goes live in phases, so no workflow breaks without warning.

01

Agree the labels

A workshop with management and team leads: which information would cause harm if it got out, where it is stored and who it is normally shared with.

02

Observe

Rules run in logging mode only. After a few weeks you can see which data leaves through which channel, how often, and which of those flows are legitimate.

03

Prompt, then block

Users first receive explanatory tips; blocking is reserved for clearly risky cases. Necessary exceptions are recorded.

04

Review

A short monthly report on incidents and overrides, with rules adjusted when new projects or partners appear.

DLP is a guard rail, not an accusation. Most employees simply do not realise that emailing a certain file crosses a line. A well-worded prompt reminds them without blame, while a deliberate attempt to take data becomes visible. Getting that balance right achieves more than switching on the harshest rules.

Frequently asked questions

No. The rules look for types of content, such as an ID number or a labelled document; nobody browses mailboxes. Who may view which events is decided upfront. We suggest involving HR and your legal adviser in informing employees and assessing the set-up from a KVKK perspective.

Business Premium covers core DLP for mail and cloud sharing plus sensitivity labels. Device-level DLP and automatic labelling need higher plans or add-ons. We show what your current plan can do and recommend extra licences only when they are clearly justified.

It should not. Legitimate exchanges get expiring, password-protected links or a separate space per client. The observation phase is designed precisely to spot these flows and build the right exceptions.

Within what existing logs allow, we extract downloads, shares and forwarding rules and preserve the records. How they are used is for your legal adviser to decide. If logging was not enabled beforehand, visibility into the past is limited, which is exactly where a DLP set-up earns its keep.

Keep confidential information where it belongs

Tell us which information matters most and which platform you use. We will show what your current licence already allows.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.