CASE STUDY
Monitoring and Controlling Email Traffic
The data exfiltration route hiding in plain sight.
Email remains the most common way sensitive data leaves an organisation. Not through sophisticated attacks, but through everyday use. A finance officer attaches the wrong spreadsheet. A departing employee forwards a client list to their personal Gmail. A project manager CC’s an external consultant on an internal thread.
These incidents rarely make headlines. But they trigger compliance obligations, damage client relationships, and expose organisations to regulatory penalties. The 2025 OAIC report confirms human error accounts for 37% of notifiable breaches in Australia. Email sits at the centre of that statistic.
Most organisations monitor inbound email for threats. Few have visibility over what goes out, or to whom.
How GuardWare addresses it.
GuardWare INSIGHT monitors information sent via corporate email, including attachments and content shared with external recipients. It tracks when sensitive data moves to personal email addresses, external domains, or recipients outside approved contact lists.
When a user attempts to send classified information to an unauthorised recipient, INSIGHT can flag the action, alert security teams, or enforce policy controls depending on your configuration. The system distinguishes between corporate and personal email destinations, catching the “just sending this to myself” behaviour that bypasses traditional DLP tools.
INSIGHT works with data that has already been classified by GuardWare DISCOVER. This means the system knows which attachments contain sensitive content, customer records, financial data, and intellectual property and applies appropriate controls. Without classification, email monitoring generates noise. With it, you focus on what matters.
GuardWare PROTECT adds a critical safeguard for email-borne risk. Sensitive attachments encrypted with PROTECT remain secured regardless of where the email lands. If a finance officer sends a board salary spreadsheet to the wrong recipient, the file stays encrypted, and the recipient cannot open it without authorisation. If the error is discovered after sending, access can be revoked remotely. The email was delivered; the data was not exposed.
The Outcome
Organisations see exactly what sensitive information leaves via email, to whom, and when. Accidental disclosures get caught before they reach the wrong inbox. Deliberate exfiltration, the departing employee forwarding client data, becomes visible and auditable. And when prevention fails, encrypted attachments ensure the damage stops at the inbox.
Email stops being a blind spot. It becomes a controlled channel.

