In our small organisation I have tried my best at implementing DLP by:
- Making sure users access all files from the server
- Local disks are denied access (forced to work only on network drives)
- Disabling mass storage
- Implementing IPSec to block users from communicating with any other IP except the server IP and Firewall (cyberoam)
- Blocking as much sites as possible in cyberoam like file storage sites, mails etc.
But there are 3 major problems I have not been able to solve with the above methods:
- Ultrasurf
- Proxy sites
- And the biggest problem of them all, using android phones internet via USB mobile tethering to bypass cyberoam.
I have spoken to cyberoam about the above 2 problems and they are working on it. Any solutions how to prevent the 3rd problem?
Any help on how to implement a cost effective DLP solution would really be helpful.