Infocentric
← Back to Blog

How Should Philippine Companies Scope a DLP Program?

Infocentric6 min read
Filipino security analysts reviewing data movement alerts on office monitors

What should a Philippine DLP program protect first?

A Philippine data loss prevention program should begin with named data owners and actual movement paths, not a company-wide block policy. Identify the information that would cause regulatory, financial, or operational harm if disclosed, then control its highest-risk exit routes. A tool purchase comes after that map is defensible.

Key takeaways

  • A DLP scope should name protected data, accountable owners, approved destinations, and prohibited movements.
  • Data discovery should precede blocking because an unlabeled file cannot be handled consistently.
  • Email, browsers, cloud storage, endpoints, removable media, and generative AI require separate policy tests.
  • The first rollout should measure false positives and response ownership before it blocks ordinary work.
  • DLP evidence should feed incident investigation instead of becoming an isolated alert queue.

The 2026 Verizon Data Breach Investigations Report Executive Summary analyzed more than 31,000 incidents, including more than 22,000 confirmed breaches across 145 countries. Its workplace-AI findings are more useful for DLP scope: 45% of employees were regular AI users on corporate devices, up from 15% in the previous year, and shadow AI showed a fourfold percentage increase in Verizon’s DLP dataset.

Verizon also found research and technical documentation in 3.2% of DLP policy violations involving uploads to unauthorized AI systems. Its figure covered 858,440 select untrusted DLP events targeting generative AI tools. These are global observations, not a Philippine loss forecast. They show why scope now has to include AI prompts and uploads alongside familiar channels. Start with personal data, financial records, credentials, source code, contracts, and board material. Assign one business owner to each class. Infocentric’s data discovery and classification service addresses the prerequisite; its DLP service page covers enforcement.

Which data exit routes should receive controls first?

Prioritize routes by the sensitivity of the data, the number of people who can use the route, and the quality of the evidence available when something goes wrong. For most enterprises, that produces separate tests for corporate email, web uploads, sanctioned and unsanctioned cloud storage, endpoint copy actions, printing, removable media, source-code repositories, and generative AI services.

The NIST Cybersecurity Framework 2.0, published in February 2024, gives a practical design sequence without pretending to be Philippine law. It calls for inventories of designated data types and protection for data at rest, in transit, and in use. CISA’s 2020 Insider Threat Mitigation Guide describes DLP coverage across email, endpoints, the web, networks, and cloud, including tools that can monitor, alert on, or block removable-media activity. Together, those sources support data-first scoping across distinct movement channels.

Translate that model into business decisions. Payroll may be allowed from the HR system to the bank’s approved channel but blocked from personal email. A contract may be shared with outside counsel through an approved repository but not pasted into a public AI service. Source code may move to a sanctioned repository while USB copying remains blocked for most developers. Each rule needs a named owner, approved destination, exception path, and retained event record.

Do not treat every route as equally urgent. Score each route from one to five for data sensitivity, user reach, external exposure, and investigation difficulty. Test the highest combined score first. The scoring method is an original planning device, not an industry benchmark. It makes the decision reviewable and gives the CISO a reason for sequencing one channel ahead of another.

How can DLP controls avoid blocking legitimate work?

Begin with observation. Run high-risk policies in monitor-only mode long enough to see normal movement, then separate expected business transfers from events that deserve a warning, manager approval, quarantine, or block. The duration depends on transaction volume and business cycles; a payroll route should include at least one payroll run, while a finance policy should include a close period.

The Philippine legal anchor is specific about proportionality. Section 20 of the Data Privacy Act of 2012 states: “The determination of the appropriate level of security under this section must take into account the nature of the personal information to be protected, the risks represented by the processing, the size of the organization and complexity of its operations, current data privacy best practices and the cost of security implementation.”

That language does not say a DLP product by itself creates compliance. It points to a control system with policy, people, technology, monitoring, and corrective action. A useful rollout therefore assigns three roles before enforcement: the business owner decides whether a movement is legitimate, security investigates the event, and IT changes the policy. Exceptions need an expiry date and a recorded approver.

Measure the operating cost weekly. Track total alerts, confirmed policy violations, false positives, average decision time, repeated exceptions, and cases with missing context. If analysts cannot decide because the event lacks identity, endpoint, or cloud evidence, connect the feed to the investigation process. Infocentric’s SIEM evaluation guide explains how to test whether evidence improves an analyst’s decision, while its security services page describes the wider operational layer.

What should the first 90 days of DLP produce?

A 90-day DLP phase should produce evidence that the organization knows what it is protecting, where that information moves, who can approve exceptions, and whether the controls can operate without flooding analysts. It should not promise complete coverage. Unknown repositories and new SaaS services will continue to appear.

Use a control card for every policy:

FieldRequired decisionProof at review
Data classWhat information is protected?Classification rule and sample match
Business ownerWho decides legitimate use?Named role and escalation contact
RouteWhere may the data move?Approved source and destination
ActionMonitor, warn, approve, quarantine, or block?Test event and expected outcome
ExceptionWho may override the rule, and for how long?Approver, reason, and expiry date
EvidenceWhat must an investigator receive?User, device, application, destination, and policy match
MeasureHow will the policy be judged?Violation, false-positive, and decision-time trend

This card is the original element in the rollout. It forces security and the data owner to agree before a rule reaches production. Review the cards at days 30, 60, and 90. Promote a rule from monitoring only when the owner accepts the match logic, the exception route works, and investigators receive enough context to decide.

The 90-day output should also include a list of uncovered repositories, unsupported channels, and policies held back because of poor classification. That list is part of the result, not a failure. It tells the next funding decision where another connector, discovery pass, or process change is needed. Infocentric’s Zero Trust guide offers a related way to stage controls around verified access rather than assumed trust.

What else should a security lead ask about DLP?

What is the difference between DLP and data classification?

Data classification identifies what a file, record, or message contains and assigns a handling label. DLP evaluates how that information is moving and applies a response such as monitoring, warning, approval, quarantine, or blocking. Classification supplies the context; DLP uses that context at an exit route.

Should a DLP rollout start by blocking personal email?

Not by default. First observe which data classes move to personal email, who sends them, and whether an approved business route exists. Immediate blocking is justified only where the risk and business process are already understood. Otherwise, monitor, warn, and fix the legitimate route before enforcing a block.

Does DLP satisfy the Data Privacy Act of 2012?

No single product establishes compliance. Section 20 of RA 10173 requires organizational, physical, and technical measures selected according to the information, processing risk, organizational complexity, current practices, and cost. DLP can support technical enforcement and monitoring, but ownership, policy, exceptions, investigation, and corrective action remain necessary.

How should generative AI be included in DLP scope?

Treat generative AI as a separate upload and text-submission route. Define which data classes may never enter public services, which approved enterprise services may receive limited information, and what evidence is retained. Verizon’s 2026 report found regular AI use on corporate devices rose from 15% to 45% in one year.

When is a DLP policy ready to move from monitoring to blocking?

Move a policy only after its business owner accepts the match logic, the false-positive level is tolerable, an approved alternative route exists, and the exception process has been tested. Investigators also need identity, device, application, destination, and policy context. CISA’s 2020 guide includes monitor, alert, and block responses rather than prescribing one response for every event.