Comment Re:How would you exfiltrate data? (Score 1) 31
EDR is sometimes all you have to know something happened. Waiting for DLP to note a loss can be too late if there is behavior which isn't currently being flagged as suspect. I've seen cases where employees attempted to establish a new baseline of behavior which EDR caught before they got around to leaking things and were told by management how they should be doing backups of their work machine and to stop the ways they were trying. If it happens again, then you have stronger reason to think they are up to no good and need stronger re-training or axing.