A Fortify 24x7 brand. Managed protection for businesses rebuilding after a security incident.Client sign insupport@hacked.help
Hacked.Help
Home / The board / Data loss prevention
Step 03 · Take away the leverage

Data loss prevention

The second demand is not about your files being locked. It is about them being published. That threat is only as strong as what you were holding unencrypted.

Discovery firstActifileDynamic encryptionCompliance profiles
Controls in this family2 lines · live rates
Data DiscoveryFortify-DLP-Classify
per device, per month
Loading
QTY
Discovery & EncryptionFortify-DLP-Enforce
per device, per month
Loading
QTY
Per unit, per month · billed in advance by Fortify 24x7 Review the full board
Technical specification 2 lines
Fortify-DLP-ClassifyDiscovery, risk baseline, vulnerability scanning and reporting on Windows, Linux and macOS
Fortify-DLP-EnforceEverything in Classify, plus dynamic file encryption, compliance profiles and channel whitelisting
PlatformActifile, deployed to Windows, Linux and macOS endpoints and operated by Fortify 24x7
DiscoveryPersonally identifiable information and cardholder data located across endpoints and servers
Risk baselineA measured starting position for data breach exposure rather than an estimate
Vulnerability scanningScanning with trend reporting so the direction of travel is visible over time
ReportingData breach risk report with a per-device breakdown of insecure data
EncryptionDynamic encryption and decryption of files in place, transparent to the person using them
Compliance profilesMultiple profiles so different regimes can be applied to different parts of the estate
Channel controlApplication and channel whitelisting governing which routes secured data may travel
Billing unitPer device, per month
01Problem

Double extortion changed what a backup protects you from

For most of the last decade, a good restore point ended the conversation. It largely does not any more. Operators now copy data out before encrypting anything, so the second demand does not care whether you recovered. It is about publication: customer records, payroll, medical detail, card data, the contract terms you agreed with a client who would be unhappy to see them.

Backup is no defence against that, and it was never designed to be. What reduces the second demand is holding less exposed material, and holding what remains in a form that is worthless when copied.

02Discovery

Nobody knows where their sensitive data is. Including you.

This is not an accusation, it is an observation from every assessment we have run. Cardholder data sits in a spreadsheet somebody built for a reconciliation in 2019. Personal records live in an export from a system that was decommissioned. Copies propagate into downloads folders, shared drives, and the laptop of the person who was covering that month.

Fortify-DLP-Classify is Actifile, and it locates that material. Personally identifiable information and cardholder data are discovered across Windows, Linux and macOS, producing a data breach risk report with a per-device breakdown of insecure material, alongside vulnerability scanning with trend reporting. The output is a baseline: a real figure for your exposure, on a specific date, that you can move.

Deletion is usually the cheapest control on that list. A substantial share of what discovery surfaces is material nobody needed to keep, and removing it costs nothing per month.

03Enforcement

Encryption in place, and the channels data may travel

Fortify-DLP-Enforce is the same Actifile agent with its enforcement half switched on. It carries everything in the discovery line and adds the controls that change the outcome of a copy. Files are encrypted and decrypted dynamically, so the person working on a document sees a document, while the same file lifted off the machine by someone without the entitlement is unreadable rather than merely inconvenient.

Application and channel whitelisting governs which routes secured data is permitted to travel. This is the difference between knowing that a spreadsheet of customer records exists and controlling whether it can be attached, uploaded, or written to a USB stick at all. Multiple compliance profiles let a regulated part of the business run stricter rules than the rest without imposing them on everyone.

04Evidence

The report your insurer, auditor and largest client will all ask for

Three separate audiences ask the same question in different words: what sensitive data do you hold, where, and what protects it. Answering with a policy document is noticeably weaker than answering with a scan.

The risk report and its trend line do double duty. Internally it directs effort at the machines that actually carry the exposure. Externally it is evidence of a measured position rather than an assertion, which is generally what separates a smooth renewal from a long one.

Sequencing these two lines

Buy discovery first, even if you intend to buy both

Encryption applied before you know what exists is a policy written against a guess. Discovery routinely finds that the sensitive material is concentrated on a small number of machines, which changes both the scope you enforce on and the number of devices you are paying for.

Run discovery, read the baseline, then decide. Some businesses move the whole estate to the enforcement line, some enforce on a department, and some find the honest answer is to delete a great deal and enforce on very little.

Where this stops

This is prevention and measurement, not forensics. Discovery tells you what sensitive data is present on a device today. It does not establish whether data has already been taken, by whom, or when, and it is not a substitute for an investigation where exfiltration is suspected.

These lines support a compliance programme rather than constituting one. No product makes an organisation compliant with any regime on its own, and any breach notification decision remains a legal question for your counsel rather than a technical one for us.