Data Loss Prevention (DLP) Survival Guide w/ Ashley Knowles

Data Loss Prevention (DLP) Survival Guide w/ Ashley Knowles

Source: YouTube · Black Hills Information Security · published Feb 27, 2026 · 1:11:43

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This webcast introduces a survival guide for Data Loss Prevention (DLP) systems, outlining how attackers can evade detection and providing defensive recommendations for security teams 0:00.

Key Takeaways:
• The presentation addresses the gap in pentest reporting regarding DLP evasion, noting that clients often struggle to understand how data exfiltration occurs despite existing protections 0:21.
• Attackers can bypass DLP by using standard protocols like HTTPS, DNS, or cloud storage APIs, which often appear as legitimate traffic to security appliances 0:30.
• Evasion techniques include encrypting data before exfiltration, using steganography to hide data within images or files, and fragmenting large data sets to avoid threshold-based alerts 1:15.
• Defenders should implement network segmentation, monitor for anomalous outbound traffic patterns, and utilize endpoint detection and response (EDR) tools to complement network-level DLP 2:00.

Effective DLP requires a layered defense strategy that combines network monitoring with endpoint visibility to detect sophisticated exfiltration attempts. Security teams must regularly test their DLP configurations against real-world evasion techniques to ensure robust protection.

Sources:

  • 0:00 Introduction to the webcast and speaker.
  • 0:21 Context on client needs for DLP survival guides.
  • 0:30 Overview of DLP evasion methods.
  • 1:15 Specific technical evasion techniques.
  • 2:00 Defensive recommendations

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everybody. Welcome to today's Black Hills Information Security webcast. My name is Jason Blanchard. I'm content community director here at Black Hills Information Security. Thank you so much for joining us today. If you ever need to hire us for a pentest, red team, thread hunt, sock services, or continuous pentesting, you know where to find us. Uh today Ashley's going to talk about data loss protection survival guide. Uh so how this came up is that I always ask the testers, what do you want to talk about? And so Ashley said, there's a need for this. We had clients talk about this and I want to talk about that. And so she's going to give a little more context to that as she gets started. But Ashley is a fantastic presenter. She's a great educator and she's a wonderful tester and she's…