Group Purchasing
Group Purchasing

Be a DLP Hero: How to Quickly Deliver Value from Your DLP Program and Set It Up for Future Success

Be a DLP Hero: How to Quickly Deliver Value from Your DLP Program and Set It Up for Future Success (PDF, 1.46MB)Published: 03 Jun, 2025
Created by:

The white paper "Be a DLP Hero: How to Quickly Deliver Value from Your DLP Program and Set It Up for Future Success," written by Kevin Garvey and published by SANS Institute in May 2025, provides a practical framework for launching, operationalizing, and governing a data loss prevention (DLP) program. The paper outlines an iterative approach to DLP that prioritizes quick, high-impact wins over one-size-fits-all tooling, covering program design, executive buy-in, common objections, and the people, process, and technology needed to sustain a program long-term.

Key recommendations:

  • Start small: launch a DLP program by first identifying an organization's most valuable data and understanding where it is stored and how it moves
  • One-size-fits-all DLP tools are a risk; DLP strategy should be tailored to an organization's specific business operations, compliance needs, and data classification
  • A four-step framework anchors program design: understand the business, learn the data, execute the program, and govern it continuously
  • Executive buy-in should be sought from the CTO, chief compliance officer, chief privacy officer, general counsel, enterprise risk management, communications, and business unit heads
  • Common roadblocks to DLP adoption include unclear ownership, perceived cost, perceived complexity, and the assumption that cloud or SaaS vendors already protect data by default
  • A bifurcated ownership model, where technical teams operate DLP tooling while compliance teams architect the content and policy, can resolve ownership disputes
  • DLP programs depend equally on people (in-house staff or a managed security service provider), process (documentation and policy updates), and technology (design, implementation, and continuous monitoring)
  • Open communication with end users, including explaining the "why" behind new controls, reduces the risk that users will devise unapproved workarounds
  • AI adoption introduces new DLP considerations, since data fed into private large language models can be poisoned or expose unapproved data such as personally identifiable information, and outputs should be reviewed by a human
  • Governance should track metrics tailored to each stakeholder group, including mean time to detect and respond, DLP agent coverage, toolset uptime, and data types discovered

The paper frames DLP not as a single tool deployment but as an ongoing program that matures through incremental stages, with success measured differently by technical, security, legal, compliance, and risk stakeholders. Its central argument is that organizations that start narrow and iterate, rather than attempting comprehensive coverage from day one, are more likely to sustain long-term buy-in and reduce data-oriented risk. Guidance in the paper draws on experience architecting and governing enterprise DLP programs across technology, compliance, risk, and security functions.

Be a DLP Hero: How to Quickly Deliver Value from Your DLP Program and Set It Up for Future Success

Related Webcast

Join us for this practical, insight-packed webcast and learn how to confidently launch or strengthen your DLP program for immediate value and long-term success.

Webcast Abstract Image

FAQ

According to SANS Institute's May 2025 paper, the best approach is to start small by identifying an organization's most valuable data, understanding where it is stored, how it moves, and how it is used, then building the program in incremental stages rather than deploying a broad, one-size-fits-all solution. 

The paper recommends a top-down approach involving the CTO, chief compliance officer, chief privacy officer, general counsel, enterprise risk management teams, internal/external communications teams, and department heads responsible for the organization's mission.

People, process, and technology. People includes in-house staff or a managed security service provider; process covers documentation and policy updates; technology covers design, implementation, and continuous monitoring of DLP tooling. 

The paper notes that data submitted to private large language models can be poisoned or expose unapproved data such as personally identifiable information, and recommends that a DLP solution flag information submitted to or produced by an LLM, with human review of outputs. 

Success is measured with stakeholder-specific metrics: technical teams track toolset uptime and agent coverage, security teams track alert triage and incident response, legal and compliance teams track data misuse incidents, and risk teams track key risk indicators tied to data security controls. 

Meet Your Author

Kevin Garvey
Kevin Garvey

Kevin Garvey

Certified Instructor

Kevin Garvey brings incident response, vulnerability management, threat intelligence, SOC, and leadership experience to SANS training, helping students connect security management concepts to real decisions teams and businesses need them to make.

Read more about Kevin Garvey