



Every week, a fresh data-breach headline reminds Indian CISOs of the same uncomfortable truth: sophisticated perimeter defences are necessary but not sufficient. Attackers exfiltrate data. Careless employees mis-send files. Malicious insiders deliberately copy crown-jewel records to personal drives. The common thread in all three scenarios is that data left the organisation — and nobody saw it go.
Data Loss Prevention (DLP) addresses exactly that blind spot. Yet in Indian enterprises, DLP remains one of the most under-deployed and misconfigured security controls. This guide walks you through why that is, how to close the gap, and what a practical DLP programme looks like when combined with a 24/7 managed security operation.
Three converging pressures make DLP a boardroom-level requirement in 2026:
India’s DPDP Act imposes obligations on “data fiduciaries” — any entity that determines the purpose and means of processing personal data. Section 8 requires fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. A demonstrable DLP programme is the most direct evidence that you are doing so. Critically, the Act requires you to notify affected individuals and the Data Protection Board when a breach occurs. DLP controls that prevent the breach in the first place are therefore better than any notification programme.
Under CERT-In’s 2022 direction, covered entities must report 20 categories of cyber incidents — including “data breach or data leak” — within six hours of becoming aware. If your organisation does not have tooling that detects and alerts on unauthorised data movement in near-real-time, meeting that six-hour window becomes a fire drill. DLP telemetry feeding a SIEM can convert a potential breach into a detected, contained, and reportable event — all within the compliance window.
India’s enterprise workforce is permanently hybrid. Employees access corporate data from home networks, personal devices, and shared coworking spaces. Sensitive files move to personal cloud storage, WhatsApp, and personal email — often without malicious intent. Without DLP policies enforced at the endpoint, email gateway, and cloud proxy, that data movement is invisible to your security team.
DLP tools are only as good as the data classification that drives them. Before you configure a single policy, you must answer:
A pragmatic approach is to classify data into three tiers: Restricted (Aadhaar, financial account data, M&A information), Confidential (internal contracts, HR records, technical designs), and Internal (general business documents). DLP policies then enforce controls proportional to each tier.
A mature DLP programme covers four distinct enforcement points. Gaps in any layer create exploitable blind spots.
Endpoint DLP agents sit on Windows, macOS, and Linux workstations, monitoring file operations at the OS level. They can block or alert on actions such as:
Endpoint DLP is the most granular and the most resource-intensive to tune. Expect a 4–6-week calibration period to bring false-positive rates to an acceptable level before switching from monitor to block mode.
Email remains the highest-volume channel for accidental data leakage. A misaddressed email carrying customer PAN card data can expose thousands of records in seconds. FortiMail’s integrated DLP engine inspects both outbound SMTP and Microsoft 365/Google Workspace-routed mail. Key capabilities include:
FortiGate NGFW can perform deep packet inspection on cleartext protocols and — with SSL/TLS inspection enabled — on encrypted HTTPS traffic. Network DLP policies can detect and block sensitive data transmitted over web uploads, FTP, and custom-port applications. For organisations with a central internet breakout, this layer provides coverage for endpoints that have not yet received DLP agents, including unmanaged contractor devices accessing internal systems via VPN or ZTNA.
Network DLP works best when paired with URL categorisation and application control. Blocking uploads of classified data to uncategorised cloud storage services, while permitting uploads to corporate-sanctioned OneDrive, is a common and effective policy pattern.
As Indian enterprises adopt Microsoft 365, Google Workspace, Salesforce, and other SaaS platforms, data increasingly resides in and moves between cloud services. CASB-mode DLP — delivered inline through FortiGate or via API integration — extends policy enforcement to cloud-native sharing, external collaboration links, and service-to-service data movement. This layer is particularly important for protecting data shared with third-party auditors, legal counsel, and supply-chain partners.
Having deployed DLP programmes across Indian enterprises of varying maturity, our team repeatedly encounters the same failure patterns:
A DLP alert is the beginning of a process, not the end. Your workflow should cover:
Key principle: DLP effectiveness is measured not by alerts generated but by data-loss incidents prevented and mean-time-to-contain for those that slip through. Track both metrics quarterly and present them to your board as evidence of programme value.
DLP controls generate significant telemetry — email quarantine events, endpoint policy violations, network block events, cloud access anomalies. Without a platform to correlate that telemetry across sources, you end up with multiple isolated alert streams that no SOC analyst can action coherently. This is where the platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — becomes operationally essential.
SIEM: PrahiX Ora’s SIEM ingests DLP events from FortiGate, FortiMail, endpoint agents, and cloud CASB APIs alongside identity logs (Active Directory, Azure AD), vulnerability scanner output, and threat intelligence feeds. Correlation rules mapped to the MITRE ATT&CK framework connect DLP violations to broader attack storylines — for example, a DLP alert for unusual file-copy activity followed by a VPN login from an anomalous geography becomes a single correlated incident rather than two unrelated events. The platform’s graph-based attack storyline reconstruction lets SOC analysts see the full kill chain at a glance rather than pivoting between five separate consoles. For Indian enterprises, a critical feature is tiered retention — hot storage for active investigation, cold storage for operational queries, and archive-tier retention to meet CERT-In’s direction on 180-day in-country log retention.
NMS: The network management module provides unified observability across FortiGate firewalls, switches, access points, and WAN/SD-WAN links in a single topology view. For enterprises running multi-vendor estates — where fragmented NOC visibility has historically meant that DLP network blocks go unnoticed until a helpdesk ticket arrives — LLDP/CDP topology discovery and ML-based anomaly detection close that gap. When a DLP-related block event coincides with a network path anomaly, the correlation is automatic.
Video Surveillance (VMS): Physical security events matter in DLP investigations. Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with integrated video analytics, bringing physical and network security events under one operations view. For manufacturing sites, retail chains, and multi-site enterprises, this matters: a DLP alert for data copied to a USB drive is far more actionable when it can be correlated with badge-access logs and camera footage of who was physically at that workstation.
SOAR: The platform’s playbook automation is what makes CERT-In’s 6-hour reporting window realistic rather than aspirational. Pre-built connectors and automated response actions — including pushing IP or domain blocklists directly to FortiGate — mean that the first 30 minutes of a DLP incident response can run autonomously: quarantine the email, block the destination IP, snapshot the endpoint process list, and open a case ticket with evidence pre-populated. The SOC analyst reviews and approves rather than manually executing each step under time pressure. For DPDP Act obligations, automated evidence packaging supports the notification workflow required under the Act.
If you are operating DLP controls without a platform of this kind, you are generating telemetry that no one is correlating — a common and dangerous gap. To see how Ora’s capabilities map to your current DLP and SOC architecture, speak with our team.
Based on deployments across Indian manufacturing, BFSI, and healthcare enterprises, we recommend a phased approach:
CISOs presenting DLP programme results to boards benefit from a small set of clear metrics:
These metrics tell a board not just that controls exist but that they are working — and that the organisation can demonstrate evidence of “reasonable security safeguards” required under the DPDP Act.
PJ Networks deploys and operates DLP programmes for Indian enterprises as part of our managed security service. Our approach combines FortiGate and FortiMail’s built-in DLP capabilities with endpoint agent deployment, SSL inspection tuning, CERT-In-aligned incident workflows, and 24/7 SOC monitoring through PrahiX Ora. We have delivered DLP programmes across BFSI, manufacturing, healthcare, and IT/ITeS sectors — each with data classification requirements and compliance obligations specific to their industry.
If your current DLP posture is limited to email gateway rules, or if you are running DLP in permanent monitor mode because the false-positive rate was never tuned, we can assess your programme against the DPDP Act requirements and CERT-In directives, and give you a prioritised roadmap to close the gaps — typically within a 90-day engagement.
To discuss your DLP requirements, reach out to the PJ Networks team. The cost of a DLP programme is a fraction of the cost of a DPDP enforcement action, a CERT-In investigation, or a breach that makes the front page of the Economic Times.