Hey everyone. I wanted to open a discussion in this space about a persistent gap we’re seeing in our DLP strategy. We invest heavily in software-based controls like CASBs and network traffic monitoring, but I’m finding that it only takes one physical device to bypass all of it.
During a recent internal audit, we realized how easily data could walk out the door using basic USB mass storage. Whether it’s an employee backing up files to a personal external hard drive for convenience, or someone plugging in an unverified SD card, these physical exit routes render our network monitors effectively useless. We are currently looking into strict hardware-level restrictions via our MDM to enforce a “Deny All, Permit by Exception” policy for peripherals.
Aside from USB mass storage, what hardware or physical data vectors are causing the biggest blind spots in your environments right now?