Cybersecurity
The full domain, and the other capabilities within it.
Know where the data is, then decide what may happen to it.
Data protection covers classification, encryption at rest and in transit, key management, data loss prevention, and the retention and residency rules that govern how long data lives and where. It is the capability most directly tied to regulatory exposure and to what a breach would actually cost.
It also fails more often than the others, and for one reason: programmes start with a classification policy instead of with discovery. A policy describing four sensitivity tiers is worthless while nobody knows which of forty file shares holds customer records. Discovery comes first here.
If more than one of these is true, this is usually the right place to start.
| Deliverable | What it contains |
|---|---|
| Data map | Where sensitive data is, in what volume, who can reach it, and where it flows outside the systems that own it. |
| Classification and handling | The tiers, the rules per tier, and worked examples for the cases people actually get wrong. |
| Key management design | Key hierarchy, custody, rotation schedule, and a recovery procedure that has been tested rather than written. |
| DLP policy set | Rules, monitor-mode findings, the false-positive tuning applied, and the staged path to enforcement. |
A reference, not a template. Your estate decides which parts apply and in what order they arrive.
Targets are agreed with you before the work starts, and reported against for its duration.
Discovery, always. Classification schemes written before discovery describe an estate nobody has looked at, and they are abandoned within a year. Find the data first; the scheme then almost writes itself.
Encryption at rest protects against physical theft and improper disposal. It does nothing against a compromised account that is authorised to read the data, which is how most data actually leaves. It is necessary and it is not sufficient.
It will if it is switched to blocking on day one, and that is how most DLP deployments come to be disabled. Monitor mode first, tune against what your business genuinely does, then enforce narrowly on the cases that matter.
It depends on the jurisdiction and the data class, and it is one of the places where a general answer is unsafe. What we can do is map the requirement you are subject to against where your data and its backups actually sit — which is frequently where the surprise is.
Yes, and they are often the weak point: production is encrypted and access-controlled while backups sit with broader access and longer retention. A data map that stops at production is not a data map.
This capability builds the controls; governance, risk and compliance decides which are required and evidences them to an auditor. They are usually run together, because a control built without knowing which requirement it serves tends to be built to the wrong standard.
The full domain, and the other capabilities within it.
Asset discovery, authenticated scanning, risk-based prioritisation and patch orchestration — a process that closes findings rather than counting them.
Segmentation, next-generation firewalling and network detection designed as one control set — so a compromised host stays a compromised host.
The fastest way to a useful answer is a short, scoped look at what you already have.