TL;DR: Content-aware USB blocking is presented as a way to stop sensitive data leaving endpoints without disabling removable media entirely, and Strac says Mandiant data cited in the article points to a three-fold rise in infected USB attacks in early 2023. The governance lesson is that endpoint DLP must be policy-driven, not port-driven, if organisations want containment without forcing users around controls.
NHIMG editorial — based on content published by Strac: USB Blocking & Content-Aware Device Control (2026 Guide)
By the numbers:
- Mandiant reported a three-fold increase in cyber attacks using infected USB drives as an initial access vector in the first half of 2023.
Questions worth separating out
Q: How should security teams control data loss when USB ports are already blocked?
A: They should treat USB blocking as one control among many, not the end state.
Q: Why do USB controls need to cover more than removable media?
A: Because USB is only one exfiltration path.
Q: What breaks when device control is too blunt?
A: Blunt controls often block legitimate work, which leads users and administrators to disable them or route around them.
Practitioner guidance
- Implement content-based USB policy Classify data types such as PII, PHI, card numbers, and secrets, then block or warn based on content rather than device alone.
- Extend DLP to all endpoint exit paths Apply the same policy logic to cloud sync, browser uploads, email, and AI tools so USB controls do not simply displace the leak.
- Standardise enforcement across operating systems Use one endpoint control model for Windows, macOS, and Linux so reporting, exceptions, and investigations remain comparable.
What's in the full article
Strac's full guide covers the operational detail this post intentionally leaves for the source:
- Step-by-step device control configuration for Windows, macOS, and Linux endpoints
- Eight-channel endpoint DLP policy options, including block, warn, and audit modes
- PII redaction and physical output restriction workflows for regulated environments
- Practical implementation guidance for balancing enforcement with user productivity
👉 Read Strac's guide to content-aware USB blocking and endpoint DLP →
USB content-aware control: what it means for data exfiltration?
Explore further
Content-aware device control is a data governance control, not a port-control feature. The useful distinction is that policy evaluates the content being transferred rather than assuming every USB action is equally risky. That aligns with modern DLP thinking, where enforcement follows data sensitivity and business context. Practitioners should treat this as a classification and policy problem first, then an endpoint problem second.
A question worth separating out:
Q: How can organisations judge whether USB blocking is actually working?
A: Measure whether sensitive transfers are being stopped, whether exceptions are falling, and whether users still complete ordinary tasks without bypassing policy. If controls cause frequent workarounds or inconsistent enforcement across platforms, the programme is not mature enough to rely on for data loss prevention.
👉 Read our full editorial: Content-aware USB control reduces data loss without breaking work