Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Data loss prevention in 2026: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Data loss prevention now has to follow sensitive information across SaaS, cloud, browsers, GenAI, endpoints, APIs, and MCP-connected workflows, because detection-only controls no longer stop data from moving into the wrong place, according to Strac. The shift matters for IAM and NHI teams because AI tools and agents increasingly create new data egress paths that must be governed, not just observed.

NHIMG editorial — based on content published by Strac: Top Components of Data Loss Prevention

Questions worth separating out

Q: How should organisations control sensitive data in GenAI tools?

A: Organisations should treat prompts, uploads, and model outputs as governed data flows, then apply classification, inspection, and logging at the point of use.

Q: Why do DSPM and DLP need to work together?

A: DSPM finds sensitive data and shows where it lives.

Q: What breaks when DLP is still built around endpoints and email gateways?

A: It misses the way data now moves through SaaS, cloud, and AI workflows that do not pass through a small set of inspection points.

Practitioner guidance

  • Define policy around sensitive-data movement paths Inventory the main routes sensitive content takes across SaaS, cloud storage, browsers, endpoints, and AI tools, then decide which paths require blocking, redaction, masking, or quarantine.
  • Pair DSPM findings with DLP enforcement Use discovery to locate the highest-risk data stores, then attach movement controls to the specific repositories, applications, and collaboration channels where those records can be exposed.
  • Treat AI prompts and MCP connectors as egress points Review how employees and agents move information into GenAI tools and through MCP-connected workflows, and apply policy to both content entering the model and content leaving connected tools.

What's in the full article

Strac's full article covers the operational detail this post intentionally leaves for the source:

  • Specific DLP capability examples for SaaS platforms such as Slack, Zendesk, Google Workspace, and Microsoft 365
  • The article's breakdown of detection methods including OCR, machine learning, and contextual classification
  • Examples of inline remediation actions such as redaction, masking, blocking, quarantine, deletion, and encryption
  • The source's discussion of how browser DLP and MCP DLP fit into modern data security workflows

👉 Read Strac's analysis of modern data loss prevention across SaaS, cloud, GenAI, and MCP →

Data loss prevention in 2026: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Modern DLP is becoming a governance layer for data movement, not just a detection tool. The article reflects a broader market shift away from alert-only controls toward inline remediation across collaboration, cloud, and AI workflows. That matters because policy now has to follow the data into systems where identity, context, and destination all change at runtime. Practitioners should treat DLP as a control architecture, not a point product.

A question worth separating out:

Q: When should organisations treat MCP as a data governance issue?

A: As soon as MCP-connected tools can retrieve enterprise data or forward it to another service, the protocol becomes a governance concern. Organisations should classify connected tools, restrict tool permissions, inspect the content moving through those connections, and apply the same policy discipline they use for other sensitive data transfer points.

👉 Read our full editorial: Modern DLP must govern data movement across SaaS, AI, and MCP



   
ReplyQuote
Share: