Hey all.
I've seen headlines on the built-in DLP setting previously and even dabbled a bit in the pre-made templates.
But I recently was looking to add some additional safety/security into our environment. I thought I was going to find what I wanted in custom DLP rules, but upon investigation, it looks like none of the things I am looking for are available there.
Are you using any custom DLP rules?
Here's what I was hoping to implement:
1.) Alert/quarantine when an email is sent to more than X amount of people (it looks like best I could find was alerting to number of emails sent in a 24 hour period). The idea being that it would help with compromised accounts sending spam.
2.) Alert/Block X number (or percentage) of Drive files downloaded in a short period of time. Again, to minimize potential damage from a compromised account.
3.) Alert upon bulk actions like - mass permissions changes, mass deletes, mass changes.
It's still surprising to me that there's this huge Gemini push and all these features, but still a massive gap between that and functional, practical, and integrated security workflows with AI.
Having just dealt with a phishing email/account compromise it because very clear that the process for investigation, mitigation, and remediation is still very disjointed, time consuming, and labor intensive process.
I suspect there may be some other ways to get the results I want - but I also expect them to be "workarounds" and compromises vs. great solutions.
What are you using (if anything)?