Insights ·

Data egress and removable media controls

By Nanorisk

Data egress and removable media controls

A breach isn't always required for data to leave your organisation. In many cases, it just walks out through gaps that nobody has formally assessed.

Three findings that come up regularly on internal engagements: USB ports with no device control policy in place, mobile app protection policies permitting copy-paste from managed corporate apps into unmanaged personal ones, and no sensitivity labelling to indicate classification or constrain where a file can travel. Each of those is a data egress path that requires no attacker, no malware, and no privilege escalation.

Sensitivity labelling in particular tends to get deprioritised because it requires user behaviour change and a labelling taxonomy that actually reflects how the business works. But without it, there's no technical basis for enforcing where data can go, and DLP tools have very little to act on.

If removable media controls and app protection policies haven't been reviewed as part of a structured assessment, it's worth doing before your next audit cycle assumes they're in place.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights