If the concern is that data leaves the organisation, the class of tool is insider risk rather than productivity, and the first useful step is to notice how much of the problem is not on an endpoint at all.
Map the routes before buying an agent
Data leaves through a personal cloud account, through email to a personal address, on removable media, through an over-broad access grant that never needed a departure to be a problem, through a third party you gave it to deliberately, and through a photograph of a screen taken with a phone.
An endpoint agent addresses some of those and is blind to others. The access grant is a permissions problem. The third party is a contract problem. The photograph is unaddressable by any monitoring product, and mentioning it early is useful because it sets the realistic ceiling on what any purchase can achieve.
The cheapest reductions are not monitoring
Most organisations are carrying a large amount of unnecessary access. People accumulate permissions across roles and never lose them, service accounts outlive their systems, and shared drives are readable by everybody because that was easier in year two.
Reducing what a given person can reach reduces what they can take, permanently, with no ongoing observation and no effect on anybody's working day. It is unglamorous, it is a project rather than a purchase, and it removes more risk per unit of effort than any tool in this section.
Then decide between detection and prevention
Detection tells you afterwards, which is useful for investigation and does not stop anything. Prevention blocks the action, which stops some things and generates false positives that interrupt legitimate work, producing the fatigue described in the alerting section with a stronger version of the base rate problem, because deliberate exfiltration is rare.
Most successful deployments block a very small number of unambiguous things and detect everything else.
Access review and permission reduction
- Best forEvery organisation, before any purchase in this class
- PricingNo licence; the cost is the project and the arguments it causes
- StandoutRemoves the capability rather than watching it, and the effect is permanent
- Watch out forIt is tedious, it makes people's lives briefly harder, and nobody gets credit for it
Controls in the systems that already hold the data
- Best forOrganisations whose data is concentrated in a few platforms
- PricingFrequently included in tiers already being paid for
- StandoutSharing controls, external-recipient warnings and download limits at the source, where the data is
- Watch out forOnly covers what lives in that platform, and shadow copies elsewhere are untouched
Network and gateway inspection
- Best forTraffic leaving over routes you control
- PricingAppliance or subscription, priced by throughput or seats
- StandoutSees uploads regardless of which application made them
- Watch out forEncrypted traffic requires interception to inspect, which is its own decision with its own consequences
Endpoint data loss prevention
- Best forRemovable media, local file movement and copy operations
- PricingMid to high tier, usually part of a larger suite
- StandoutThe only class that sees a file copied to a device that never touches the network
- Watch out forIt is an agent with high privilege on every machine, and everything in the workforce section applies
Full insider-risk platform with activity capture
- Best forOrganisations with an actual programme, counsel involved, and a named owner
- PricingThe highest tier in this market, quoted rather than listed
- StandoutReconstruction to an evidential standard, which is what a serious investigation requires
- Watch out forAdministrative burden is a role, and it collects material about everyone to catch a very small number
The departure window is where most of it happens
Copying before resignation, and access retained after it, account for a large share of real cases. Two process changes address that without watching anybody continuously: tighten access at notice rather than at the last day, and check the access list against the leaver list on a schedule, because the accounts that outlive people are found by reconciliation rather than by monitoring.
Say what is being watched
Insider-risk tooling is where the temptation to deploy quietly is strongest, and the covert monitoring article sets out why it does not pay. The narrow, documented investigation remains available for a specific suspicion. A standing undisclosed programme is a different thing and is defended with arguments that only apply to the first.
What we cannot verify
Detection rates for this class of product are published by their vendors, are not independently reproducible, and are measured against scenarios they design. We reproduce none. Legal characterisation of inspection, particularly of encrypted traffic and of personal accounts, is jurisdictional and belongs with counsel. No product is named or ranked.
The short version
- Map the routes first; half of them are not on the device the agent watches.
- A photograph of a screen sets the realistic ceiling for any purchase.
- Reducing accumulated access removes capability permanently and costs no observation.
- Detection informs an investigation; prevention stops things and interrupts legitimate work.
- Deliberate exfiltration is rare, so the base rate problem is at its worst here.
- Most real cases cluster around the departure window, which is a process fix.