Skip to content

Data Protection

Know where the data is, then decide what may happen to it.

What this is

Data protection covers classification, encryption at rest and in transit, key management, data loss prevention, and the retention and residency rules that govern how long data lives and where. It is the capability most directly tied to regulatory exposure and to what a breach would actually cost.

It also fails more often than the others, and for one reason: programmes start with a classification policy instead of with discovery. A policy describing four sensitivity tiers is worthless while nobody knows which of forty file shares holds customer records. Discovery comes first here.

When you need it

If more than one of these is true, this is usually the right place to start.

  • Sensitive data believed to be in known systems, with no recent evidence for that belief.
  • A data residency or sovereignty requirement that the current architecture cannot demonstrably meet.
  • Encryption in place but keys managed by whoever set the system up, with no rotation and no recovery plan.
  • Departures or contractor exits where nobody can say what data left with them.

What the scope covers

  • Discovery: where sensitive data actually resides, including the shares, mailboxes and endpoints it was copied to.
  • A classification scheme with few enough tiers that people apply it correctly, and handling rules per tier.
  • Encryption design at rest and in transit, with key management, rotation and a tested recovery path.
  • Data loss prevention policy, deployed in monitor mode first so blocking is based on observed traffic rather than guesses.
  • Retention and residency: how long each class is kept, where it may be stored, and how deletion is evidenced.

What you receive

DeliverableWhat it contains
Data mapWhere sensitive data is, in what volume, who can reach it, and where it flows outside the systems that own it.
Classification and handlingThe tiers, the rules per tier, and worked examples for the cases people actually get wrong.
Key management designKey hierarchy, custody, rotation schedule, and a recovery procedure that has been tested rather than written.
DLP policy setRules, monitor-mode findings, the false-positive tuning applied, and the staged path to enforcement.

Reference architecture

A reference, not a template. Your estate decides which parts apply and in what order they arrive.

Data protection reference architecture: data, control and governance layersData: Classification, Encryption at Rest, Encryption in Transit. Control: DLP Policy, Key Management, Rights Management. Governance: Retention Policy, Data Residency, Audit TrailDataClassificationEncryption at RestEncryption in TransitControlDLP PolicyKey ManagementRights ManagementGovernanceRetention PolicyData ResidencyAudit Trail
Data protection reference architecture: data, control and governance layers

How success is measured

Targets are agreed with you before the work starts, and reported against for its duration.

  • Share of known sensitive data stores that are classified and covered by a handling rule.
  • Encryption coverage at rest and in transit, with the exceptions listed rather than averaged away.
  • DLP false-positive rate during monitor mode — the number that decides whether enforcement is survivable.

Questions we are asked

  • Where should a data protection programme start?

    Discovery, always. Classification schemes written before discovery describe an estate nobody has looked at, and they are abandoned within a year. Find the data first; the scheme then almost writes itself.

  • Is encryption enough by itself?

    Encryption at rest protects against physical theft and improper disposal. It does nothing against a compromised account that is authorised to read the data, which is how most data actually leaves. It is necessary and it is not sufficient.

  • Will DLP block legitimate work?

    It will if it is switched to blocking on day one, and that is how most DLP deployments come to be disabled. Monitor mode first, tune against what your business genuinely does, then enforce narrowly on the cases that matter.

  • What does data residency actually require?

    It depends on the jurisdiction and the data class, and it is one of the places where a general answer is unsafe. What we can do is map the requirement you are subject to against where your data and its backups actually sit — which is frequently where the surprise is.

  • Does this cover backups?

    Yes, and they are often the weak point: production is encrypted and access-controlled while backups sit with broader access and longer retention. A data map that stops at production is not a data map.

  • How does this relate to GRC work?

    This capability builds the controls; governance, risk and compliance decides which are required and evidences them to an auditor. They are usually run together, because a control built without knowing which requirement it serves tends to be built to the wrong standard.

Continue reading

  • Cybersecurity

    The full domain, and the other capabilities within it.

  • Vulnerability Management

    Asset discovery, authenticated scanning, risk-based prioritisation and patch orchestration — a process that closes findings rather than counting them.

  • Network Security

    Segmentation, next-generation firewalling and network detection designed as one control set — so a compromised host stays a compromised host.

Start with an assessment

The fastest way to a useful answer is a short, scoped look at what you already have.