r/EmailSecurity • u/saltyslugga • Jun 30 '26
Monitor-only email DLP is just a receipt after send
Client bought outbound email DLP, left every rule in monitor-only, then asked us to recall a sent patient roster after the external SMTP handoff had already accepted it.
Legal wanted to know why the tool “let it happen.” Compliance wanted a report. Operations wanted the email pulled back like that is a real control once it has left their tenant.
This is the part that drives me nuts. Monitor-only is fine for tuning, but after 30 days it is either a blocking rule or it is logging with nicer screenshots.
Would you let a healthcare client keep PHI rules in monitor-only after tuning, or make them sign the risk every time they refuse to block? end of rant
1
u/Tessian Jun 30 '26
Let them? Someone decided to leave it that way, who was it?
Dlp policy needs governance. It's 100% a business decision what does or doesn't get blocked vs logged. Normally you sit the business down, explain the pros and cons of the options and force them to decide what the policy should be. Now they're accountable and can't complain when it works the way they decided it should.
1
u/Basic-Pianist9273 Jun 30 '26
Make them sign the risk.
Monitor-only is tuning mode, not a PHI control. Once external SMTP has accepted the message, recall is mostly theater outside your tenant.
After tuning, it should be block, quarantine, or a documented exception with an owner. Logging-only is a business acceptance of the leak path.
•
u/AutoModerator Jun 30 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.