TL;DR: Traditional DLP misses the real risk because it focuses on data classification and movement rather than user behaviour, intent, and unmanaged browser-based workflows, according to Above. The gap matters most where phishing, sanctioned and unsanctioned SaaS use, and generative AI prompts create leakage paths that reactive controls detect only after the risky action occurs.
NHIMG editorial — based on content published by Above: Data Loss Prevention: What It Is and Why It’s Not Enough
Questions worth separating out
Q: Why do traditional DLP controls often fail to reduce real-world data leakage risk?
A: Traditional DLP often struggles when it produces alerts without taking action.
Q: How should security teams detect insider threats without overwhelming analysts?
A: Start with a small set of high-signal indicators such as unusual login patterns, unauthorized application use, excessive downloads, and privilege changes.
Q: What breaks when users move sensitive data through browser-based AI tools?
A: The old assumption that sensitive data must travel through managed files or sanctioned apps breaks down.
Practitioner guidance
- Map identity-linked leakage paths Identify where authenticated users can create exposure through browser AI tools, personal SaaS, extensions, and unmanaged workspaces.
- Correlate user intent with data sensitivity Combine search behaviour, application context, role, and session metadata so analysts can distinguish routine work from suspicious information-seeking or exfiltration preparation.
- Expand policy coverage beyond sanctioned applications Apply governance to browser-based tools and unsanctioned apps that can receive sensitive text without a file event, especially generative AI services and unmanaged collaboration spaces.
What's in the full article
Above's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor breaks DLP into endpoint, network, and cloud models and where each one fails in practice.
- The specific examples of browser-based AI prompts, unmanaged SaaS, and cross-application workflows that create leakage paths.
- The article’s full explanation of how behaviour signals can be used to reduce false positives in insider-risk investigations.
- The vendor’s framing of how its platform correlates SaaS, clipboard, OAuth, and extension activity into a single investigation surface.
👉 Read Above's analysis of why data loss prevention is not enough →
Data loss prevention is missing intent signals, not just data controls?
Explore further
Data-centric DLP creates a behavioural blind spot: when controls focus on documents, labels, and transfer events, they miss the user decisions that actually create leakage. That is why modern insider-risk governance has to correlate identity context, application context, and activity context. The practical conclusion is that DLP should be treated as one telemetry layer inside a broader identity-led risk model, not as the model itself.
A question worth separating out:
Q: Should organisations prioritise DLP or identity-led behaviour monitoring first?
A: If the main risk is human misuse of authenticated access, identity-led behaviour monitoring should come first. DLP still matters for classification and enforcement, but it works better when paired with context about who acted, how they acted, and which unmanaged workflows they used. That combination improves triage and reduces blind spots.
👉 Read our full editorial: Data loss prevention is failing because it watches data, not intent