In brief

A talk by a DLP vendor: steganography is needed not by the insider but by the security officer — "straw" laid down before the leak, so as to narrow the circle of suspects afterwards. Three ways to find the source: information-system-based, user-session-based, and labels in the file plus encryption. The value — an honest list of unsolved problems and the refusal to sell; but the topic as a method was not covered, and the scheme works before the leak, not for finding the source.

Key points

Tools, artifacts, technologies

Barely came up at all: no articles of law, no agencies, no methodologies — corporate information security, not forensics. The only norm, and with no source: "24 hours to respond, 72 hours to report something to someone"; Federal Law 152-FZ and Roskomnadzor were not mentioned. The framing — "the incident lifeline" and the protected perimeter. The terminology — "leak", "incident", "personal data", "security officer".

Questions from the audience

The speaker's position

Steganography is not a panacea but a supplement to DLP/DCAP; the problem has been solved by no one, the speaker included. He argues with the belief in a universal labeling mechanism and with the idea that LLMs will sort out DLP bypasses. He admits the limitations himself: the agent is weak on macOS and in the cloud, "our watermarks" do not survive overexposure. The tone — a conversational lecture with self-irony, not a sales pitch.

Quotes