Security Consulting & Compliance
Data Loss Prevention
DLP strategy, tooling selection and policy tuning.
Every engagement includes manual validation, a two audience report and free re-testing.
Get a scoped quote+91 96682 00222What this actually is
Most DLP projects fail the same way. The tool goes in, blocking is switched on too early, the business revolts, and six months later everything is in monitor mode and nobody reads the alerts.
We do discovery first. You cannot write a sensible policy until you know where the sensitive data actually is and how people legitimately move it around, which is almost never how the architecture diagram says.
Then we tune in monitor mode, agree exceptions with the business, and only enforce once the false positive rate is low enough that people trust it.
What we go after
- Sensitive data discovery across endpoints, servers and cloud
- Classification scheme design and rollout
- Legitimate data flow mapping
- Policy design with the business rather than at it
- Tuning in monitor mode before enforcement
- Exception and approval workflow
- Insider risk detection use cases
- DPDP and sectoral obligation mapping
How we run it
- 01
Gap assessment
We measure you against the standard as it is actually audited, not as it reads on paper.
- 02
Remediation plan
Every gap gets an owner, an effort estimate and a date. You decide what lands this quarter.
- 03
Implement and evidence
We write the policy, build the control and collect the artefact that proves it is working.
- 04
Internal audit
A dry run under audit conditions, so nothing in the real one is a surprise.
- 05
Certify and maintain
We sit on your side of the table for the audit, then keep the evidence current between cycles.
What you receive
- Sensitive data inventory and classification scheme
- DLP policy set with tuned thresholds
- Exception handling procedure
- Rollout plan staged from monitor to enforce
- Operational runbook for the team who will own it
Who needs this
Organisations handling regulated or commercially sensitive data, particularly where staff move data between cloud services and personal devices.
How long it takes
Eight to sixteen weeks from discovery to enforcement.
Standards this satisfies
- DPDP Act
- ISO 27001
- PCI DSS
- GDPR
Why it matters
Almost nobody starts a certification because they want one. It starts because a customer will not sign without it, a regulator has asked, or a deal is sitting still while procurement waits for evidence. The commercial driver is real and it is worth being honest that it, rather than security, is usually what pays for the programme.
The security benefit is real too, but it comes from a specific place: the discipline of having to evidence that a control operated over a period, rather than that it was configured once. That is the part that changes behaviour, and it is also the part organisations consistently underestimate.
Choose how you want this delivered
Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.
Gap assessment, then we work alongside your team through remediation, internal audit and the certification audit itself. Your people do the work and own the outcome, which is what makes the management system survive after we leave. This is what most organisations should choose.
Choose this when
- You have a team who can absorb the work alongside their day job
- You want the capability to remain in-house afterwards
- First certification where documentation is the main gap
Effort and cost
Moderate. The calendar is longer than a managed programme because the work competes with everyone's existing responsibilities.
Scope it yourself, before you call anyone
Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.
Which framework are you going for?
What we look for, and keep finding
These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.
Sensitive data nobody knew existed
Discovery almost always finds personal or regulated data in places it was never meant to be: test environments, exports, shared drives and analytics copies.
Egress routes that are not covered
Policy applied to email while the actual leakage happens through personal cloud storage, messaging apps or a browser upload. We test the routes people really use.
Classification nobody applies
A four tier scheme that staff ignore because it is unclear and slows them down. Automated classification with a small number of tiers works better than a taxonomy nobody uses.
Blocking tuned so hard it gets disabled
False positives that interrupt legitimate work produce pressure to switch the control off. We tune for the flows that matter rather than for maximum coverage.
Insider exfiltration over time
Slow, low volume extraction by someone with legitimate access, which threshold based rules are specifically bad at catching.
Who runs your engagement
A lead assessor who has sat on the other side of the table
Compliance work is led by an assessor who has taken organisations through certification, not by a consultant reading the standard for the first time with you. They know which findings a certification body will actually raise, which is a different list from what the standard technically says.
Questions we get asked
Which DLP product should we buy?
That depends on where your data lives and what you already own. We work with Safetica, Data Resolve and Seqrite among others, and if your existing platform is adequate we will tell you rather than sell you another one.
How long before we can turn on blocking?
Usually two to three months of monitoring first. Enforcing early is the single most reliable way to lose the organisation's goodwill and end up back in monitor mode permanently.
Often scoped alongside
- CERT-In Cyber Security AuditCERT-In empanelled audit and certification for government and regulated entities.Read more
- ISO 27001 Audit & CertificationISMS design, implementation, internal audit and certification support end to end.Read more
- ISO 27017 Compliance AuditCloud-specific security controls for providers and customers.Read more
- ISO 27018 Compliance AuditProtection of personally identifiable information in public clouds.Read more
Ready to scope your data loss prevention?
Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.












