



Every large breach has a pre-breach phase. Stolen credentials, misconfigured cloud buckets, compromised third-party integrations — but the final act is almost always the same: sensitive data quietly leaves the organisation before anyone notices. In India, that act now carries legal weight. The Digital Personal Data Protection (DPDP) Act 2023 and CERT-In’s Cyber Security Directions make data exfiltration both a security failure and a regulatory event. For Indian enterprise CISOs, Data Loss Prevention (DLP) has moved from a compliance checkbox to a first-order security control.
DLP is a set of technologies and processes designed to detect, classify, and block the unauthorised movement of sensitive data — whether it travels over the network, resides on endpoints, or sits in cloud storage. A robust DLP programme answers three questions in near real time: Where is our sensitive data? Who is accessing it? Is it leaving the organisation through an approved channel?
Traditional perimeter defences — firewalls, web gateways, email filters — inspect traffic for malware. They are not designed to identify whether an outbound HTTPS stream contains a spreadsheet of customer PAN numbers or a database dump with Aadhaar-linked records. Without DLP, those files travel freely as encrypted blobs. By the time the CISO learns about the exfiltration, days or weeks have passed.
India’s DPDP Act 2023 classifies organisations that process personal data as Data Fiduciaries. The Act requires fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. While the Act deliberately avoids prescribing specific technologies, the draft rules — and the Data Protection Board’s enforcement posture — make it clear that organisations are expected to demonstrate active, documented controls over how personal data moves.
CERT-In’s 2022 Cyber Security Directions add teeth: a personal data breach must be reported within six hours of detection. That timeline is impossible without automated detection — and impossible to evidence without logs that DLP policies generate. DLP does not make an organisation “DPDP compliant” by itself, but it supports compliance with the Act and helps evidence that required safeguards were in place.
“The DPDP Act does not ask whether you were breached. It asks whether you had reasonable safeguards. DLP is how you prove the answer is yes.”
Understanding where data leaks is the first step in stopping it. In PJ Networks’ NOC/SOC experience across Indian enterprise clients, the most frequent exfiltration channels are:
Effective DLP requires three overlapping layers — no single layer provides complete coverage.
Inspects data in motion at the perimeter and on internal segments. The engine classifies content using regular expressions, fingerprinting, and ML-based pattern matching to identify sensitive data types — Aadhaar numbers, PAN card formats, credit card numbers, healthcare records, and custom-defined intellectual property. When a match occurs, the engine can block, quarantine, or alert in real time.
Enforces policy at the source — on the user’s laptop or desktop — before data reaches the network. Endpoint agents can block copy-paste to unsanctioned applications, restrict USB write operations, and prevent screen capture of sensitive windows. This layer is critical for catching insider threats and for remote workers outside corporate network controls.
Scans data at rest and in motion within cloud platforms — IaaS storage, SaaS applications, and collaboration tools. Cloud DLP is increasingly important as Indian enterprises accelerate cloud adoption; it also feeds discovery and classification feeds into the broader DPDP compliance programme.
FortiGate next-generation firewalls include an integrated DLP engine that works alongside application control, SSL/TLS inspection, and web filtering. For Indian enterprises already running FortiGate as their core network security platform, this means DLP can be enabled as part of the existing security profile — without deploying a separate inline appliance.
FortiGate DLP profiles support:
PJ Networks configures FortiGate DLP profiles as part of a layered security deployment, tuning sensitivity thresholds to minimise false positives while maintaining meaningful coverage on high-value data classifications. When combined with endpoint and cloud DLP controls, the FortiGate layer closes the perimeter gap that most organisations currently leave open.
Individual DLP alerts are useful; DLP alerts correlated with identity, network, and endpoint context are decisive. That is the gap that PrahiX Ora — a unified SecOps platform built by PrahiX Tech Pvt Ltd — is designed to close. PJ Networks is PrahiX Ora’s primary field deployment and operations partner, and we deploy and operate the platform across client environments. Here is how each pillar applies to DLP use cases in India.
Ora’s SIEM ingests logs from DLP engines, FortiGate, Active Directory, endpoint agents, SaaS audit trails, and cloud infrastructure in a single pipeline. Correlation rules mapped to the MITRE ATT&CK framework surface patterns that individual tools miss — for example, a DLP alert for PAN number exfiltration correlated with a recent failed MFA event and an anomalous login time. The platform’s graph-based attack storyline reconstruction connects these dots visually for the SOC analyst within seconds, not hours. Critically for CERT-In compliance, Ora supports tiered log retention (hot, cold, and archive tiers) aligned to the 180-day in-country retention direction issued by CERT-In.
When a DLP event fires, context matters: which device, which segment, which uplink is that traffic flowing through? Ora’s NMS provides unified observability across firewalls, switches, wireless APs, and WAN/SD-WAN links. LLDP/CDP topology discovery and network path tracing let the SOC analyst place the triggering endpoint precisely in the network map — accelerating containment decisions by eliminating the topology lookup step that typically adds minutes to incident response.
For manufacturing, retail, and multi-site enterprises, a significant DLP event may have a physical dimension — was someone in the server room? Did a visitor bring an unregistered device? Ora’s video surveillance (VMS) capability supports ONVIF, Hikvision, and Dahua camera management with video analytics. Aligning a DLP alert timestamp with a physical access event from the same location brings physical and network security under one operations view, eliminating the manual cross-referencing that delays post-incident investigation.
CERT-In’s six-hour reporting window is challenging without automation. Ora’s SOAR module includes pre-built playbooks for DLP incidents: on a high-severity alert, the playbook can automatically push a block rule to FortiGate (stopping further exfiltration on that session), quarantine the endpoint, generate a draft CERT-In incident notification with pre-filled fields, and page the SOC analyst — all within the first few minutes of detection. Automation does not replace analyst judgment, but it compresses the response window to a point where the six-hour clock is manageable rather than aspirational.
CERT-In’s 2022 Directions require Indian organisations to report a data breach or cybersecurity incident to CERT-In within six hours of becoming aware of it. In practice, organisations that rely on manual detection and manual reporting routinely miss this window — not because they are negligent, but because the detection-to-confirmation step alone can take longer than six hours without automation.
A DLP-to-SOAR-to-notification pipeline changes that calculus. By the time a SOC analyst reviews the alert, a significant portion of the incident evidence has already been collected, correlated, and drafted into a notification template. This is the practical difference between meeting the CERT-In deadline and explaining to the Board why the organisation was late.
Before deploying DLP technology, a readiness assessment reduces false-positive noise and improves policy precision. Key steps:
PJ Networks designs and operates layered DLP programmes as part of its broader managed security service offering. Our implementation model covers:
Whether you are building a DLP programme from scratch or strengthening an existing one ahead of DPDP Act enforcement, PJ Networks brings the combination of technology expertise and operational depth needed to make DLP effective — not just installed.
The DPDP Act 2023 is not a future obligation — it is an active regulatory framework with a Data Protection Board that is beginning enforcement activity. For Indian enterprise CISOs, the question is no longer whether to implement DLP, but how quickly and how comprehensively. The organisations that will navigate DPDP Act enforcement well are those that deploy DLP as part of a unified SecOps architecture — not as a standalone product collecting alerts that no one acts on.
If you would like a technical assessment of your current data exfiltration exposure or a discussion on how PJ Networks can deploy a DLP programme aligned to your DPDP Act posture, reach out to our team. Our managed security, NOC/SOC, and FortiGate expertise means we can move from assessment to active protection without the months-long deployment cycles common with point products.