Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reduce data-exfiltration risk by controlling the entire data path: identify sensitive information, limit who and what can access it, require strong authentication, encrypt stored data, watch outbound activity, and rehearse a response. No single control is sufficient; the five measures below work as a layered program.

1. Inventory and classify sensitive data

You cannot protect information you cannot locate. Build a current inventory of sensitive repositories and record what each contains, who owns it, which users and applications can access it, and every approved way it can be copied or transferred.

Map the data and its paths

  • List databases, file shares, SaaS services, email stores, endpoints, removable media and cloud buckets that hold personal, financial, health, intellectual-property or regulated information.
  • Document owners, user groups, service accounts, integrations, export functions and transfer destinations.
  • Mark internet-facing assets and services that could provide an attacker with a route to the data.

Reduce unnecessary access and retention

Apply least privilege: give each person and application only the access required for its job, and review privileged access regularly. Set retention rules so obsolete copies are deleted rather than left available for theft. CISA’s ransomware guidance also recommends understanding exposed assets and looking for abnormal outbound volumes, newly created services and unexpected scheduled tasks.

2. Require strong authentication and protect privileged accounts

Stolen credentials frequently turn a foothold into an exfiltration event. Make long, unique passwords and multifactor authentication (MFA) the baseline, with the strongest controls on administrator, cloud and remote-access accounts.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Protect identities

  • Use a password manager to generate and store unique passwords; never reuse an administrator password across systems.
  • Require phishing-resistant MFA where your identity provider supports it, and at minimum require MFA for administrator, email, VPN and cloud-console access.
  • Separate everyday accounts from administrative accounts, limit standing privileges and review dormant accounts and service credentials.
  • Store recovery codes and privileged credentials in a controlled, audited system rather than in email or shared documents.

Apply lessons from Emergency Directive 24-02

CISA issued Emergency Directive 24-02 on April 11, 2024, after a campaign exfiltrated email through compromised Microsoft corporate accounts. The directive required affected agencies to analyze potentially accessed content, reset credentials and secure privileged Azure accounts. The practical lesson for any organization is to treat a suspected identity compromise as an incident: investigate mailbox and cloud activity, revoke active sessions or tokens, reset credentials and verify that privileged access is protected.

Do not send sensitive information through unprotected channels. CISA specifically encourages MFA and prohibits sharing unprotected sensitive information over insecure communications.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

3. Encrypt data and maintain recoverable backups

Encryption limits what an intruder can read if a device or storage medium is stolen or accessed. CISA warns that an attacker who gains access to an unencrypted device may be able to read, manipulate, steal or deny access to its data.

Encrypt every storage layer

  • Enable full-disk encryption on laptops and mobile devices.
  • Encrypt internal and external drives, removable media and sensitive files before they leave a controlled environment.
  • Protect encryption keys, recovery keys and passwords separately from the data they unlock, with access logging and a documented recovery process.

CISA identifies the Advanced Encryption Standard (AES) as the authorized U.S. government encryption standard. AES-128, AES-192 and AES-256 are considered highly secure; AES-256 is generally regarded as the strongest of the three. Select an implementation that your operating systems and applications support and that your organization can recover reliably.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Back up for recovery, not just storage

Keep a secure external-drive backup or a properly vetted cloud backup, restrict who can delete or alter it, and maintain an offline or otherwise immutable copy when feasible. Test restoration on a schedule. A backup that has never been restored is an assumption, not a recovery capability. An encrypted external hard drive can serve as one implementation of encrypted removable storage, but the organization still needs controlled custody and a workable key-recovery process.

4. Monitor egress and deploy data-loss-prevention controls

Prevention controls can be bypassed. Detailed visibility into network traffic, user activity and data flow gives defenders a chance to spot and stop unusual transfers. CISA describes this level of detail as “high visibility.”

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Collect the evidence needed to see an incident

  • Centralize network-flow, endpoint, identity and cloud-audit logs, and synchronize timestamps so events can be correlated.
  • Baseline normal outbound volume by user, device, application and destination.
  • Alert on unusual outbound volume, unexpected destinations, newly created services, new scheduled tasks and archive or compression activity that precedes a transfer.
  • Investigate unexpected use of Rclone, Rsync, FTP, SFTP, web-storage services or tunneling over common ports.

Make DLP enforceable

Configure data-loss-prevention (DLP) rules around the classifications in your inventory. Depending on sensitivity and business need, a rule can block a transfer, require manager approval, quarantine the message or file, or generate an investigation alert. Tune exceptions for legitimate workflows and retain the event details needed for forensics; an unreviewed stream of alerts is not effective protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Practice detection, response and recovery

When an alert fires, delay increases the amount of data that may leave. Maintain a written incident playbook and exercise it so every participant knows the first action, decision authority and communication route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Include these response steps

  1. Detect and triage: identify the account, device, application, destination and time range involved; preserve relevant logs.
  2. Contain: isolate affected systems or disable the transfer path while preserving evidence.
  3. Revoke access: invalidate sessions and tokens, reset compromised credentials and secure privileged accounts.
  4. Scope the exposure: determine what data was accessed, copied or potentially transmitted, and which obligations may apply.
  5. Notify: involve legal, privacy, security, leadership, customers, regulators or law enforcement according to your requirements and the facts established.
  6. Recover: remove persistence, restore trusted systems and data, and verify that monitoring is active before returning systems to normal operation.
  7. Learn: document the cause, missed signals and control changes, then track those changes to completion.

Exercise the playbook with realistic scenarios and verify that backups actually restore. NIST Special Publication 1800-29, published February 23, 2024, is designed to help organizations “detect, respond to, and recover from a data confidentiality attack.” It addresses the monetary, reputational and legal consequences that can follow a confidentiality breach.

How to choose supporting tools and services

Whether you are evaluating a DLP platform, a managed detection service, an identity product or an encrypted backup drive, compare the control against the same operational questions rather than buying on a feature list alone.

Decision area What to verify
Coverage Whether it protects the endpoint, email, SaaS applications and network paths that hold or move your data.
Control type Which actions it prevents, which it only detects, and whether approval workflows are supported.
Administration Staff time, policy-tuning effort and ownership for reviewing alerts and exceptions.
Evidence Log retention, searchability, event detail and forensic export capabilities.
Integration Compatibility with your identity provider, endpoint tools, cloud platforms and ticketing or incident-response systems.
Key and recovery handling Who controls encryption keys, how recovery is authorized, and how loss of a key or administrator is handled.
Backup resilience Immutability or offline options, deletion protection and the time required to restore.
Cost and obligations Total operating cost and fit with contractual, privacy and regulatory requirements.

For an encrypted removable drive, also verify the manufacturer’s hardware-encryption claims, independent validation, capacity, interface speed, physical durability and your own key-recovery procedure. Product specifications and availability change, so confirm current details before purchase.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.