Skip to content

Reducing data exfiltration by malicious insiders - Appendix A

  • Knowledge Level: All Levels
  • Protection Stage: Operate & Detect
  • Time to read:

This table can be completed by organisations to prepare a baseline assessment of their critical assets, adding additional lines if necessary

Last Updated: 01 September 2026
Share this article:

Baseline assessment of exfiltration techniques

This table can be completed by organisations to prepare a baseline assessment of their critical assets, adding additional lines if necessary (and ignoring those that are not relevant). This process should be seen as part of the organisation’s overall security risk management process. Once completed, organisations should review relevant policies in case of necessary updates.

Columns 2 and 3 should normally be completed by technical leads to inform a subsequent conversation with business leads and risk owners (who would normally complete columns 4 and 5).

1

Method

2

Current state (prevent/monitor/audit

3

Residual risk

4

Technology to upgrade without impacting business delivery (and cost)

5

Residual risk after upgrade

Obfuscation/Steganography        
Copy and paste        
Screen grab and paste        
Save data with new name        
Save data in different file format        
Save data with protective marking removed        
Translate        
Shrink file and embed in another document        
Steganography within .jpeg        
Use of private/medical/personal filesnames        
Exfiltration        
Email        
Webmail        
External storage devices        
Secure messaging platforms        
Online conference facilities        
Social media        
Wi-Fi/Bluetooth        
Multiple accounts on single device        
Did you find this page useful?
helpfulness rating