Webinar On Demand - 45 min
Modern Day DLP: Navigating AI & Off-Channel Risks
29 January 2026
Watch this webinar to understand how AI and off-channel communications have dramatically increased the DLP stakes and to learn how your organisation can respond.
What You’ll Walk Away With:
The DLP Evolution
Where we’ve been, where we are, and why simply disabling cut and paste is not longer enough
The New Risk Landscape
How AI tools and off-channel communications are creating blind spots your current DLP can’t see.
Boardroom-Level Stakes
The financial, reputational, compliance, and legal risks keeping executives up at night.
Actionable Next Steps
1 – 2 things you can do today, plus our DLP Audit Guide to assess your gaps.
Great. So we're gonna kick off. Firstly, thank you all for, for joining us today. You're very, very welcome. We're very excited to, turn you through today's webinar, which is based on modern day DLP and the challenges it presents. And today is gonna be split into two parts. Firstly, our CEO column is gonna be taking us through the the evolution of DLP over the years and then also the impact of mobile and generative AI on how DLP needs to further evolve. I'll then take over, and we're gonna talk about more of the regulatory components of of DLP within the boardroom and how compliance drivers are reshaping that conversation within companies. And then we're gonna touch on the the gaps that exist within DLP across corporations and then the business impact of potential incidents or potential, visibility gaps. So with that, just some housekeeping points. Today's session is gonna run for about forty five minutes. It will be recorded. So if anybody has to drop off, you will be you will receive the recording after today's call. You're welcome to put your questions into the q and a box. And should there be time at the end, we will get to as many as we can. Any unanswered questions will be followed up on after the call. And so with that, I'd like to hand over to Colm, and we can start today's session. Thanks, Matt. Looking forward to to to talking it through, and and certainly looking forward to hearing some of the questions that, the audience will will direct our way, near the end. Just, to sort of manage expectations here. So, my plan is really I'm gonna talk about trying to set some context about DLP, overview the overview the topic as it were, and really focus in it then in on how things are changing with generative AI and also with with mobile as well. Obviously, Corrata has some really powerful features in the DLP space. It's not something I'm gonna be covering today. More than happy. I know Matt and the team will be more than happy to talk to anyone who wants to go into depth on on our capability specifically. But without without further ado, let's just get on to, onto the meat of the presentation. So I suppose before talking specifically about DLP and how it's evolved and where we're at today and and how it needs to change. It's worth just putting it in the context of the broader cybersecurity landscape. I guess, you know, the the if we I think I'm most familiar with the the confidentiality, integrity, and availability triads that we all sort of work to in in the information security sector. And I guess it's very clear that DLP is all about the confidentiality side of things. But the scope of what was considered to be confidential or something that was worthy of our attention as information security professionals has really evolved over the years. I mean, initially, I would say most cyber attacks, most of the things we're concerned about were were around financial loss. We really wanted to make sure that we weren't disclosing things like credit card details, bank details, authorization codes, that kind of information, which would lead to a direct financial loss because because most of the attackers at that point were mostly concerned about trying to adapt kind of low hanging fruit. Let's just get directly to the money type of attacks. But that has that evolved as we digitize more and more of our businesses. I think a a second sort of order of scope expand the scope expanded, and it expanded specifically initially into being concerned about, the confidential information that are company confidential or maybe first party confident confidential information that's held by organizations, which whose release might directly harm the organization. So, you know, there there continue to be really, really high profile examples of these kind of, of breaches. So for example, only in November, the office of budgetary responsibility in the UK, released their analysis of the budget before Rachel Reeves got up to deliver it. Obviously, market impacting, hugely embarrassing, and actually an event which led to the, the head of the o the chair of the, of the budget budget responsibility standing down. And we've had even sort of closer to home here in in Ireland, we had a very, very, very, very concerning leak, by the PSNI of details of over ten thousand of their, up to ten thousand of their officers and civilian employees, details of those individuals. Now, you know, that was a leak which was just the spreading the the the sharing of spreadsheets. It was as a as a result of a just very routine freedom information request, but it caused you could see how it could lead to physical harm as well as to the reputational damage for the organization. It did lead to a fine for the PSNI of seven hundred and fifty thousand, but really that pales into insignificance and relative to the broader implications of a leak like that. So, you know, so that kind of information, really confidential information held by organizations, that's something that it was a it's also the second level of scope for, for what we're concerned about when we're talking about, data loss prevention. I suppose but really, you know, that is the the scope has dramatically increased in recent years. When we look at all of the third party information that's now held in digital form by organizations. So I'm talking about all the the the personally identifiable information, the private information of individual customers, information from our partners and other third parties. All of this information is very, very much within scope, not just because it matters from a reputational perspective to the to the organization, because clearly, an organization has responsibility to its customers and to its partners to keep information confidential, but also because of the rise of regulation, particularly in the UK and Ireland, and in Europe, a GDPR and equivalent legislation elsewhere. But also, we've seen that that expand across the globe, those that kind of, that kind of regulation, which leads, which is designed to protect the privacy of of of citizens as it were, but which has a direct impact in terms of fines. So I know that Matt is gonna touch a little bit more on the regulatory evolution, as we go through, today's presentation. So, I mean, that's the kind of context. That's the scope that we're dealing with when we're talking about data loss prevention. But let's look specifically now at how the controls that we use, the the prevention bit of data loss, the controls that we use in order to ensure that we don't have have data loss. So, you know, in the in the what I call the the PC era, I mean, the main concern was on the physical loss of devices, of equipment, of file share, of of actual floppy disks or USB drives. That's where the the the the the first sort of set of concerns arose around data loss. So this was about people leaving an unencrypted laptop on a train and people sending information about millions of individuals in disks through the post and it being lost. It was about people having, their laptop stolen, not from the office, but from their home with confidential data on the on the laptop. And it's it's it's an ongoing risk. And, actually, if you look at a lot of the, if you look at a lot of the standards around cybersecurity, they put a lot of emphasis on physical security, on the control of the physical device, the control of physical space as well within our offices. And it is it remains a a real risk, but it's a a risk which is it it's kind of it's a analog. It's nearly an analog risk in a digital world. In terms of the speed, it requires physical access. It's not something where two or three clicks or single click or send button in an email can give rise to a massive loss of of data. It's it it is it was DLP in a a slower, more stately world in many ways. It still exists. I mean, I have a personal anecdote to share here. My son recently picked up a laptop that was left in this the on the on the pavement in in the street locally. And when we found when we opened it up, we discovered that there was a laptop. Sorry. It was a backpack you picked up, but there was a laptop. The password was written on a piece of paper. We could access the laptop and all of the corporate information that was kept on that laptop. So, you know, it still is a risk, but it's not the thing that looms mostly in our imagination today when we think about DLP and controlling DLP. So we now move on as opposed to the Internet era. So, you know, the and and and this really hyper hypercharged the risks around digital loss. And the main vectors were around things like FTP servers and and email. So, you know, there are multiple, multiple examples of data loss as a result of people sharing, in inadvertently, in most cases, sharing information, sending information to to to the unintended recipients for email. So so in that world, the I would say that the main this is when DLP started really in terms of being a specific element of of cybersecurity. And in that world, what we were talking about there was mainly perimeter controls. So it was around having controls at the perimeter of your network that prevented, and inspecting anything going out of your network. So it was, it was it was email gateways. It was secure web gateways. It was filtering web proxies and other types of technology tools, which essentially made sure that what shouldn't get out didn't get out. Now how effective it was? I mean, it it relied in a lot of cases on pretty crude techniques for recognizing what was a sensitive document. So it might be down to document hashes. It might be down to the, presence of, say, Social Security numbers or the equivalent or credit card numbers. So crude enough in terms of what it was trying to identify, and ran into, you know, a lot of challenges because of that crudity, be a lot of false positives, Big issue when more and more information was encrypted using SSL, and and then the whole issue of decrypting and and using SSL decryption, all the the challenges and and, issues that that throws up, became part of the DLP story at at that particular point. The the I mean, we have there were lots of examples. I mean, in two thousand and two, for example, Microsoft, a huge amount of internal Microsoft information was leaked on an FTP server, which was designed for use, for distributing patches for support purposes, but which employees had inadvertently understood was an internal share. And so competitive information, slide decks, financial information, a whole range of presense of information was was was shared through that kind of environment. But again, again, not the cloud era, the Internet era, we were talking mainly about if you had the right configurations on your FTP server, if you had good controls around around your your get good gateways, good perimeter controls, you were in a good position to to address this. But all of these changes really fundamentally with the cloud era. So, you know, the cloud era has kind of evolved through the two thousands. It has various different aspects. So Salesforce, for example, launched in two thousand. Really, it was the first main SaaS prod product. AWS launched, I think, in in two thousand and six. So here we have we have cloud services, the ability you know, remote hosting, public cloud, suddenly a a the availability of compute on demand. So another major step towards the cloud world we live in today. The third a third milestone would have been, when Outlook, was the the leading enterprise email system became available as a cloud hosted, service. So that was two thousand and eleven. So, you know, we've moved gradually to that. We are firmly in that world now. And, really, you know, it it changes what we worry about from data in transit. We still need to worry about data in transit, but, really, this is about how you control data at risk. Because the big issue in this environment is actually oversharing. The issue here is do people do your employees give permission to the wrong people to access data? Now that could be in the form of a say, if you're on your cloud, on your on your Google Workspace or your Microsoft SharePoint or or OneDrive, someone enabling a link such as anyone with this link can can access this information. It can be in the form of information stored in s three buckets, which are, Nordics, which are, which are accessible to the public as it were. We've lots of examples of those of that kind of data loss, data loss as a result of that kind of poor security hygiene. And the the focus in this environment then, you know, it moves from it moves from this perimeter style defense situation. It really moves into managing what's what's the the the term of ours today is, data data security posture management. So this is understanding where is your data, understanding which of that data is sensitive, what's categorizing that data. It's about monitoring access to that data and monitoring how that data is is is accessed, looking for anomalous, access patterns. So why is some if you're a for example, if you're a a a company that works in the air in a very sensitive sector with lots of IP, I'm thinking maybe semiconductor design. Why is someone from your marketing department trying to access a semiconductor design detailed semiconductor design information, which will be highly valuable to a competitor. Why is someone like that doing that? Even if you're blocking it, you need to know that someone's actually attempting to do that kind of thing. So that's how, you know, we we have that's where we've moved to in terms of of of data of of, DLP now. We're worried not alone about data in transit that were in the more to do not alone about physical, which we talked about before. We're concerned about data in transit. We're also now concerned about data at risk at rest and monitoring and understanding how that data is being shared. So the next challenge. So we've seen the evolution. Most organizations are struggling to deal with the cloud era. I mean, they are struggling with it. They have to deal with complex environments because they have both internal networks often. They have cloud hosted applications, and they're using lots and lots and more and more of, SaaS applications. So they have and they have then lots of different devices trying to access that, both traditional laptops. They have people working from home, working in the office. They have people using mobile phones, etcetera. But there are two, I suppose, big changes that are are adding to that complexity and presenting new challenges. The first of those, and I suppose the one that people talk a lot about, it's because it's very high profile and and and and also because it's a very much a discontinuity. It's kind of it appeared. So ChatGPT launched at the end of twenty twenty two, and ever since then, all our brains have been bombarded, flooded with, overflowing with information about the impact of AI and trying to understand what that means for our for our organizations, for business, and then obviously for information security. The second trend has been more of a slow burn. It's it's mobile. It's it's when it's mobile becoming a first class platform in the enterprise. I mean, people might say, okay. Mobile's been around for a long time. It absolutely has. It's been around really in practical terms. We have BlackBerry back in the two thousands. Obviously, they launched the iPhone two thousand and eight, that kind of era, Android, etcetera, explosion in mobile. And, obviously, people have had email on their mobile for an awful long time. But, really, what has changed, and it's been a gradual change, a gradual buildup, has been the move to mobile as a first class platform or platform which is on an equal footing with traditional laptops and and and desktop. So that has implications for lots of things, but for for DLP among other things. Let's talk a little bit about Jet AI and and what do we need to to focus on on, if we were talking about the impact of generative AI? Because it's so it's so massive and and there's so much hype. Hype is the wrong word. There's just a lot of attention being paid to it, rightly so, because it's a transformative technology. There's a number of things that I think we need to think about from a a, from a data loss prevention perspective specifically. I would say three key things. So the first is looking at the actual use of chatbots within your organization. Typically, now at this point, most organizations have adopted a, say, a sanctioned or approved AI chatbot. It might be Copilot if you're a Microsoft title. It might be Gemini if you're Google. Or indeed, it might be claw it might be Claude or Entropic for your coders, and it might be ChatGPT from some of the in in other other departments. So you have sanctioned applications that chat chat applications, chatbots that are actively being used, and and, frankly, that you want people to use because, you know, this is a this is an important inflection point and organizations that whose staff become familiar with and confident in the use of AI, have with a huge advantage. So it's definitely something we wanna see done. But, really, what we need to know is, you know, we need to guard against, however, people using personal AI accounts, unauthorized or unsanctioned AI chatbots, and sharing confidential information in that. And and it's very difficult if if, you know, with the statistic there, it talks about thirty percent of of people admitting that they have used unsanctioned or improved, AI chatbots to do their work, not not just. They've used them for whatever. They've used them to do their work. So they're actually, I had a great great example, not from our organization, I'll tell you, but from a very, very large organization of a presales engineer who what was, was was answering an RFP. And because the internal chatbot was inadequate or provided a poor answer, uploaded the RFP and a lot of confidential information into their own personal ChatGPT account. So, you know, classic. They're trying get their job done. They're not bad people, but they're they're they're adopting really, really dangerous practices. A second area is we've had have to realize that it's not just file upload that's the worry with, with select with the these the ChatGPT. It's also prompts as well. But another thing that that it opens up is even when you're using sanctioned AI, there's a real risk that information which was pre previously segregated off from different parts of your organization can suddenly blow up into other parts of organization. So I gave the example of IP designs, being axed being accessed by the marketing department. You could absolutely see how financial information that was being analyzed by one of your financial analysts using your in house or or sanctioned copilot instance or whatever. You could easily see how people outside that environment or outside that that particular department could get access to that kind information as well through through, right the right prompts to be put into the chat sheet the the into into into the, chatbot. The the the third area, and I think this is an area that's is has has is probably gonna become the biggest concern in the in the in the in the the next few years, and this is the use of indirect prompt injection to extract sensitive information out to organizations. We are linking up a lot of the most sensitive or information in the organization, information about customers, information about service, information about finance. We're linking that up together to AI applications. And the the we don't know, frankly, because of the nature of AI because it's a probabilistic rather than a deterministic technology. We do not know what what prompt where that information might end up if we're not very careful. So there is a real risk that third parties with act who manage to send in prompts to these applications, and often these applications are designed to be to help service third parties, will be able to trick or social engineer your AI application into disclosing sensitive information. So lots lots of lots of concerns there in the in the generative AI, as generative AI becomes part of our our day to day as it were. But as I said earlier, I mean, there's a second trend here, which, as I say, it's been more of a slow burn that and hasn't received the same attention. We certainly see it with our customers. We see that mobile now and you see the statistic there. I mean, mobile now is a first class platform for the enterprise. It's no longer about email. It's about everything that you get done in the enterprise is now accessible through your mobile phone. And and for that reason, you know, the and and, unfortunately, it's typically mean being doesn't benefit from the controls that are typically deployed on on on on traditional laptops as well. And, typically, the security tooling is limited to MDM. And, course, you've got your BYO devices, which are accessing these applications, are often not managed at all. And the the as a result of this, it's not just about people uploading files or using the wrong SaaS services or those kind of things. There are also we also see very specific risks emerging. Now Matt, I think, is gonna talk a little bit more about the, off channel communications and the very specific regulatory issue there, and that's when people are using personal WhatsApp and Signal and other messaging applications to do business to to do business communications for specific issues around that. But there's also other emerging other emerging issues in the mobile in the mobile segment, one of which is the leaking of of of employee data through the advertising network. So very briefly, this is something that's really started to bubble up now about as being a concern. It's a novel use case. This is because of the way in which the online advertising networks work. When a anyone is on the Internet, on their phone, or whatever, and huge amounts of information about that particular person are shared very, very widely. I mean, I think the figure is in the US, I think about I'm gonna say it's in the thousands of data brokers who would receive notification about a particular ads opportunity. So here we are. Someone is now on a website. These are the characteristics of this person. And if it's a mobile, this is where the person is at this moment, and they are being then, those data brokers are the intention is they would use it then to optimize advertising, make more money for the advertiser. And but there have been recorded cases now where some of these data brokers, their objective is not advertising. It's actually, what they call advertising intelligence or collecting information about individuals via the their usage of the advertising network of specific individuals. So you can see where someone goes in where they've accessed the Internet in the morning, maybe where at night, where they live, and then where they do during the day, where they work, and pretty quickly, you can probably narrow that down to a specific individual. So, again, it's an emerging it's kind of a data leakage that an unexpected sort of start of data leakage, but it's one that's that's real and and a concern. So all is to be done. Just to to finish off now, just to have a quick, quick sort of some thoughts about what you as information security professionals need to do to try to, to to address these emerging challenges. So I think on the on the, on the AI side, it's in the first instance, about being very clear that you can control, the use of of, unsanctioned AI chatbots. You really that's a kind of a baseline requirement now that you make sure that people are not using personal, chatbots or personal accounts for business purposes or indeed just using unauthorized, unsanctioned AI across your organization. The second thing, obviously, is just to make sure that your AI what I your in house, your sanctioned AI is actually very is is properly configured to make sure that the kind of data leakage within your organization that might break down access controls or segmentation that you spend a lot of time in to to putting in place and and you've spent a lot of time governing and making sure that there aren't aren't simply overwhelmed by the, the power of the the chatbot. And the final thing is that, you know, if you are launching if you were using AI as an application, so in customer service and sales, whatever, an application within your organization, you have to put it through the same sort of app sec framework that you would use for any application. You need to do testing. You need to think through the architecture. You need to be aware of what information is available and could potentially be shared with that with that, that application by that application with the people who are connecting to it. On the mobile side, it's about making sure that you are continuously evaluating the security posture of your mobile devices. Any mobile device that is accessing your organization, you need to know that it's secure, and that's both BYOD and and and corporate devices. You need to be in a position to enforce, rules on on ShadowAI mobile as well as on on, desktop because a lot of a lot of people we speak to initially when we talk to them, they go, we are we we have an MDM. We can prevent people installing particular chatbot apps. But we also know that people are really good at getting around this, and the browser is wide open. So even if you say you can't use Anthropic, if someone can just log on to their to the browser to Anthropic, unless you have the right controls in place on the mobile endpoint, you're gonna get you're gonna get you're you're gonna be exposed. And the in relation to more broadly, the use of, the data loss issue, really, is important to make sure that you know what SaaS applications are being used across your organization. Again, how you deal with a lot of us you you have marketing departments who are using SaaS applications for relatively low risk unsanctioned SaaS applications for relatively low risk activities, probably not something you need to get particularly concerned about. But what you do need to know is that that is going on, but you also need to be in a position to be able to flag when there is when people are starting to use more applications which involve more more sensitive data. So, I mean, a lot there. I appreciate, a lot going on in this space at the moment. We are moving from a world we've moved, I suppose, already from physical to data in transit to data at rest. And and now we are moving on to the data, which is ultra a huge channel of mobile and being a huge channel for the potential exploitation of data. And also generative AI as a a whole new class of equivalent really to to moving to cloud, a whole new class of of of risk associated with, that could lead to to data loss. So thanks for that. I'm gonna hand over now to to Matt, who's gonna go into some of the the board level issues and concerns in this area. Great. Great. Thanks so much for that, Colm. A really, really, really insightful start to webinars. Hopefully, I'll keep up with the same level of value. Yeah. So everybody I I we want to take some time just to focus on the regulatory compliance risks around the kind of modern DLP landscape. You know, Colm has walked us through how that threat landscape has evolved over the previous over the last few years. Now I want to show you what this means for your business, essentially, because these are fast becoming more than just technical problems. They're becoming boardroom priorities. So let's start with how their regulatory conversation has fundamentally changed. For years, we all know that the question around DLP has been very simple and has been focused on do you have DLP controls in place? Typically, a checkbox compliance policies in a drawer and mentality looking at DLP, which is you know, that's very, very much gone, gone now. And the question is more around, can you prove that the controls that you have in place as a business work? There's three expectations with, regulators, and they circle around protection. So a demonstrable controls across all channel channels that Colin has spoken about, so including mobile, messaging app, all types of AI products and tools. It's visibility. So it's being able to have auditable evidence within hours and not weeks when there are incidents and cases of of data loss. And then it's very much all about accountability. So board level signing off on cyber risk policies, which has taken the overall ownership away from IT teams, security teams, and making it a board level a boardroom level, a c suite level priority. Without all three of these, essentially, there is a compliance gap within a company. And so let me now show you what's driving this shift in conversation within businesses. It very much comes down to two core pillars, and I want to be really clear about what what regulators are looking for, and it's it's protection and visibility. So on protection, you really need to demonstrate control, that covers all areas that data could potentially leave a business, including mobile devices, you know, messaging apps like WhatsApp, AI tools that I spoke about. You need to be able to prove protection within all of these different channels and then visibility. So incidents audit trails, real time monitoring, instant incident detection within hours, and having board level kind of reporting functionality ready there to be accessed when when needed. And I as I kinda mentioned with the previous pillars, when I've got these layers on top, again, there is a gap when it comes from a regulator's regulator's expectations. You know, as a business, you might have great controls in place, but if you can't prove that they work in, you know, real life situations, on spot audits, they will be treated as a failure, and it will be treated as a compliance gap. And so let me just show you two of the specific regulations that are kinda driving these enhanced expectations. So there are two very much two main compliance drivers reshaping that conversation within businesses, the DLP conversation within businesses. G GDPR, which we all know and love so dearly, and then. So GDPR has, since twenty eighteen, issued in total of six point five billion euro on fines. Ireland specifically accounting for just over four billion euro of that, with eight of the top ten largest fines coming from the Irish Data Protection Commission. So, you know, within this, there's need for seventy two hour breach notification requirements, which may which means that businesses can't hide. There is that fundamental requirement there. You have to disclose. In not doing so, fines, as we know, can reach up to four percent of global turnover. So reframing the need to have all of these the abilities across all channels to access this information and to dive with the data when and as needed. And this too and Dora have, as we know, introduced something that kind of has changed this conversation entirely or changed the game entirely, and it's that boardroom level accountability piece. So management all management must now personally sign off in cyber cyber risk measures within the company, meaning it's not just an IT problem anymore. It is very much a boardroom problem. We know, again, that penalties here can reach ten million euro or two percent of turnover. And, essentially, fundamentally, businesses have a really reduced response time frame when you're looking at critical incidents, and that's kinda brought down to twenty four hours. The shift here is, you know, DLP now for businesses and the conversations being held internally isn't just about prevent preventing data leaks. It's about proving comprehensive visibility and controls that are in place to assist as well. And the board question is commonly being asked is what's our exposure? That's always been the case, but now it's being continued on to, can we demonstrate compliance? So having identified what the expectation is now and what's driving those standards, I wanted to just kind of benchmark some, some of the current gaps through four numbers from a recent IBM cost of breach report. That should definitely kind of enlist a bit of concern. Sixty three percent of organizations lack, AI governance policies. Ninety seven percent of AI breach firms lacked proper access controls. Seventy seven percent of employees paste that into AI chatbots. And to link back to Column's previous stuff, over thirty percent admit to uploading corporate data into these, into these, kind of assistant platforms. Two hundred and forty seven days is the average amount of time it takes to detect a shadow AI breach, which is eight months of data leakage before a company might even know that it's happening. And and I suppose the core problem here being framed is traditional DLP measures as we know them within businesses. You know, they watch emails. They manage endpoints, net network perimeter, and but data kind of as we've displayed and as we're all well aware, is now leaving through, you know, personal corporate mobile devices, WhatsApp, chat GBT, unmanaged, unsanctioned SaaS, AI, multiple different areas of the business that traditionally are fairly invisible to the securities team, but are are are highly, accessed by our by our day to day, employees. So we all know that the traditional DLP measures don't see any of those additional channels that we mentioned. And essentially, what you can see, you can't protect, and, you certainly can prove protection there, which is fundamental in a lot of the, in a lot of the cases, previously mentioned. So what happens when DLP fails? Let's talk about that business impact across three main main dimensions. Financial impact, you know, the average cost, of a breach in Europe now sits at three point nine million euro. System downtime alone costs five thousand six hundred euro per minute on average, and sixty five percent of firms admit that they're still recovering financially months after the breach has been contained. Within reputational damage, you know, we all know GDPR. You're given seventy two hours to notify, you know, regulators of a breach. The problem here is that companies can't can't manage the message. You can't control the narrative. And what we're what we tend to see and what we're seeing now is kind of a a naming and shaving trends going on across EU regulators. You know, they're publishing who has gotten fined and why they've gotten fined to just, you know, to use those those bigger companies or use those more public cases to to drive compliance across wider markets. You know, within this reputational damage, obvious, you know, repercussions here. Mean, stocks are dropping, customers churn, media scrutiny, headlines, businesses that got headlines that they don't particularly want. And then there's the trust element, which I I think we'll all agree could be the most damaging of all. You know, trust is really easy to break and and typically very, very hard to rebuild once lost. You know, the questions you gotta ask is will customers come back or will customers stay after a breach? Will partners want to work with you? And and then, fundamentally, how does this affect your investor relationships and potential company valuation should evaluation should this happen? So these are hypothetical questions or situations. Boards are actively living through these scenarios, working through these scenarios, and asking these questions right now. These you know, it it formulates a lot of the conversations we're having internally way beyond products and hand solutions around DLP. So let me bring you through to concrete use cases, and and I'm bringing some of this to life into real world situations. So scenario one would be a very common risk we face, a very common conversation we're having through the use of shadow AI within businesses. So setting the scene here, a financial analyst copies client data into ChatGPT, mapping back for the staff that Colin and myself had shared, on a personal mobile to draft a report or response faster faster, whatever it might be. This, of course, bypasses all traditional enterprise controls. The obvious risk here is it's, you know, it's a GDPR breach. Personal data is being processed without legal basis, and there's no visibility. There's no audit trail. Two hundred and forty seven days average to detect a breach within this scenario should it happen. What a business needs within this scenario to make sure they're protected is full visibility into AI tool usage on all devices, managing all endpoints, personal and corporate mobile phones, obviously, included in that. Policy controls that work regardless of network, real time blocking, all the logs. Luckily, this these are all those kind of enhanced features that Colin mentioned of Corrado, and this is this is some of the the massive value that we're delivering to our our customers throughout these use cases. The second scenario then we're gonna work through is kind of, off channel communication, which, again, is a is a is a huge toke topic of many of the conversations we're having through the highly regulated customers within, you know, financial services. Setting the scene here, your sales team uses WhatsApp for client conversations, discussing deals, pricing, contracts. It's convenient. It's easy. It's friendly. It in times, breaks down the barriers of our customers because it takes it out of a more formal email or or or or Google or Teams call. It's unmonitored. It's unarchived. Regulators like FCA, they ask for records here. You have nothing to produce. You have nothing to give them to prove this communication. And obvious obvious risk here, it's a rep keeping breach. I suppose to put some weight behind it from a monetary perspective, US US firms, many of the major major banks that we know of and that we that that we many of us work with day to day, have been fined a total of three point five billion dollars since twenty twenty one. And the UK and EU, are very much next. So the PRA has already cited, UK banks for poor WhatsApp retention, and can now individually hold senior staff, individually liable for these breaches. So moving into recapping why all this matters, I'm bringing back some stats to the screen. Seventy seven percent employees are pacing data into AI chatbots. Four hundred and forty three breach notifications daily across Europe, six point five billion euro GDPR fines to date, and two hundred and forty seven days to detect the shadow AI breach should have occurred to your organization. So traditional DLP, you know, it wasn't built for this year. It wasn't built to to work through all these different channels. The gaps that column showed you that at the start of this webinar, these are the consequences to noncompliance. Fundamentally, you know, your board will or are asking three questions when it comes to DLP or should be asking three questions. Do we have visibility into how data leaves our organization? Can we demonstrate compliance if a regulator asks tomorrow? What's our exposure from AI and messaging apps? And, again, it comes back to if you can confidently answer these questions, there is likely a gap. That kinda brings me to, to something that we'd like to give out to our attendees today. We've spent some time internally building up a DLP audit guide, and we'd like to offer that to you. And what it is, it's a really practical framework and will allow you will will help you benchmark, I suppose, your current resilience across the business when you're looking at DLP with the new modern channels in mind as well. So it's gonna give you some, you know, instant risk identifiers. It's gonna give you some instant remediators that you could do to help you in certain areas. And, of course, once you fill it out, if if if you need a hand in assessing any of the the areas, we'd be more than happy to continue that conversation with you. So as I mentioned, Colm, you know, showed us that threat evolution piece. I've now brought you through the regulatory and business consequences of noncompliance and of not having solution in place that covers all areas. The question now that we will leave you with today is is your DLP strategy keeping pace with the current environment and the current landscape in development? So with that in mind, I would like to thank everybody for joining today. I know that we have gone slightly over time, So I will end the session there and just like to say we will forward the DLP audit guide to everybody after today's calls. We have gotten a lot of questions in the chat box there to follow-up on, which we will take some time and reply to the individual senders. And if, of course, if there are any questions that you haven't asked, if any of this these, the comment that was covered today sparked any interest or would like you'd like to continue any conversational points, please feel free to reach out to us. We'll be up to to continue that conversation with you guys directly. So thank you all very much, and we'll catch you again soon. Thanks.