Score DLP coverage across email, web, endpoint, cloud and API egress paths, weighted by enforcement mode and classification quality.
DLP is only as good as the narrowest path an insider or attacker can use, so coverage is weighted across all five egress routes and monitor-only coverage earns half credit. The critical multiplier is classification: a policy that cannot recognise your sensitive data does nothing regardless of where it is deployed. Shadow IT discounts the result because unsanctioned destinations sit outside the policy entirely. Treat the score as a prioritisation estimate of egress exposure. Most DLP deployments cover email thoroughly and APIs barely at all, which is precisely inverted — bulk data leaves through integrations, not attachments.
Data Loss Prevention Coverage
pathCoverage = 0.26×email + 0.24×web + 0.20×endpoint + 0.16×cloud + 0.14×API; effective coverage then scales by enforcement mode (0.6–1.0) and classification quality (0.5–1.0), halves the credit for shadow IT, and is trimmed by the false-positive rate.
pathCoverage = 0.26×email + 0.24×web + 0.20×endpoint + 0.16×cloud + 0.14×API; effective coverage then scales by enforcement mode (0.6–1.0) and classification quality (0.5–1.0), halves the credit for shadow IT, and is trimmed by the false-positive rate. DLP is only as good as the narrowest path an insider or attacker can use, so coverage is weighted across all five egress routes and monitor-only coverage earns half credit. The critical multiplier is classification: a policy that cannot recognise your sensitive data does nothing regardless of where it is deployed. Shadow IT discounts the result because unsanctioned destinations sit outside the policy entirely. Treat the score as a prioritisation estimate of egress exposure.
Most DLP deployments cover email thoroughly and APIs barely at all, which is precisely inverted — bulk data leaves through integrations, not attachments.
This calculator takes 9 inputs: Email egress covered, Web and SaaS upload covered, Endpoint — USB, print, clipboard, Sanctioned cloud storage covered, API and integration egress covered, Coverage in blocking rather than monitor mode, Sensitive data correctly classified, Estimated unsanctioned SaaS use, DLP alerts overturned as false positives. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because it records the loss rather than preventing it. That has genuine investigative value, which is why it is not zero, but a monitor-only estate has not stopped a single byte from leaving.
Indirectly, yes. Noisy policies get exceptions carved into them and alerts get bulk-closed, so real coverage erodes. The model applies a modest trim rather than a large one, because tuning is a fixable problem.