All insights

The DLP blind spots most small businesses never see

Most small businesses assume data loss looks like a hacker breaking in. In practice, it usually looks like an ordinary Tuesday: a spreadsheet emailed to a personal address, a client file dropped into a free file-sharing site, a laptop left in a car. No alarm goes off, because nobody is watching those paths.

Where the data actually goes

  • Personal email — staff forwarding work to a Gmail account so they can finish at home.
  • Unmanaged cloud storage — free Dropbox or Drive accounts nobody in the business controls.
  • USB drives and personal phones — copies of client data with no encryption and no way to wipe them.
  • Departing employees — an export of the client list in the last two weeks before a resignation.
  • Vendors and contractors — bookkeepers, billing services, and IT help with standing access they no longer need.

Why it stays invisible

You cannot see what you do not log. Most small businesses have never turned on the reporting that already comes with the tools they pay for — Microsoft 365 and Google Workspace both include alerting on external sharing and mass downloads. The feature is sitting there, unconfigured.

Low-cost controls that actually catch it

  • Turn on external-sharing and mass-download alerts in the email and file platform you already pay for.
  • Block auto-forwarding of company email to outside addresses.
  • Write down which three or four places client data is allowed to live, and treat everything else as an exception.
  • Remove access the same day someone leaves, including shared logins.
  • Require device encryption and a screen lock — free on every modern laptop and phone.

None of these need a new product. They need someone to decide, configure, and check. That is usually the whole gap.