Categories
How does a security officer identify an insider using the DLP system?
Every organisation can face data leaks because of what insiders do.
Information Security control today is not a matter of trust in employees, but strategic necessity, especially given the growing number of information leaks caused by internal users. For example, the number of insider attacks increased by 25% in 2024, and about 35% of all Information Security incidents were somehow related to the human factor.
The tightening of legislation in the field of Information Protection, significant increase in regulatory fines, and introduction of criminal liability for violations in the field of Personal Data of citizens, also raise the question of creating the reliable and sustainable information protection system.
In this article, we will examine who is responsible for protecting corporate data, how to identify potential threats, and what tools can help effectively prevent leaks caused by insider actions.
What does a security officer do?
The security officer plays a key role in building the reliable data protection system within an organisation:
- participates in the development and implementation of Information Security policies within an organisation;
- monitors compliance with adopted security policies;
- manages Information Security incidents;
- promotes employee awareness of cybersecurity, i.e. staff security training;
- identifies insiders and suspicious employee behaviour.
To address these challenges, security officers have various tools at their disposal, including DLP. Next, we will look at how our DLP can be used to identify insiders.
How to identify an insider using the DLP system?
Configuring security policies
The security officer activates the security policies pre-installed in the system, edits them in accordance with the organisation's needs, or creates new ones.
Over 180 security policies have already been set up in the system. For convenience, we've sorted them into groups like "Suspicious Activity", "Banking Data Leakage", "Login and Password Leakage", "Information Leakage", and others.
When the policy is triggered, the security officer or other authorised employee receives a notification.
Security incident management
When a rule indicating an attempt to steal protected information or transfer it to a third party is triggered, the security officer may:
- conduct a retrospective analysis of an employee, i.e. assess what violations they have already committed, whether there are any accomplices, and what role each person played in the incident;
- monitor an employee's current activity during the working day: what operations they perform with files (including confidential ones), what contacts they communicate with;
- if necessary, take screenshots of the employee's desktop at any frequency, as well as connect to the microphone or take pictures from the webcam to analyse what is happening near a workstation.
Important! If necessary, you can configure blocking of unwanted operations, including sending confidential documents by email and copying to external media.
Let's look at identifying an insider using a real-life example. A client company was facing leaks of important information, so a decision was made to install the DLP system.
Digital fingerprints were taken from important documents, appropriate security policies were configured, and blocking rules were set up.
The employee of the organisation copied a fragment of confidential information into the middle of a multi-page document with a neutral title, and then attempted to send it to an external contact by email.
The situation did not appear suspicious. It was a typical, routine letter, of which there could be hundreds in a single working day, even in a small company.
However, the digital fingerprint rule worked — the system intercepted the document, analysed it for confidential information, identified the match with a previously taken digital fingerprint and blocked the transaction.
The security officer was instantly notified, and the leak was prevented.
The insider has been caught.
Establishment of a case
All details of the incident can be added to the case file, including:
- documents from search results, User Activity module, other system files, external files;
- cards of individuals suspected of involvement in the incident;
- comments from the security officer that may be useful in conducting the investigation.
Preparation of reports for management
Facts gathered in a case can be compiled into a convenient report accepted by an organisation, which a security officer can submit to management.
Detailed incident reports can be used to analyse and eliminate vulnerabilities in the information system, as well as to impose measures of responsibility on an offender: from instruction on Information Security techniques for minor violations to dismissal with compensation for damages.
In conclusion
Minimising risks associated with insider threats is an important part of an organisation's Information Security strategy. DLP systems help security services quickly detect potential threats, manage access to confidential data and prevent its unauthorised distribution.

















