Your Data Is Already Moving

Every day, employees send emails with attachments, copy files to USB drives, upload documents to cloud storage, print sensitive reports, and paste data into AI tools. Most of it is legitimate work. But without visibility, you can't tell the difference between business as usual and a data breach in progress.

532

data breaches notified to the OAIC in the first half of 2025

Health (18%), finance (14%), and government (13%) were the most affected sectors.

$4.4M

average cost of a malicious insider breach

The costliest breach type. Shadow AI adds another $670K on average.

37%

of Australian data breaches caused by human error

Wrong recipients, accidental uploads, and misconfigured sharing. Not hackers.

Data Leaves Through Channels You're Not Watching

Traditional DLP tools focus on network perimeter and email gateways. But data walks out the door on USB drives, through personal cloud accounts, via print jobs, and increasingly through AI prompts. ActivityPulse watches every exit point.

Physical Media

USB drives, external hard drives, and SD cards remain the most common exfiltration vector for insider theft. Most organisations have no visibility into what files are copied to removable media.

Cloud & AI Services

Personal Dropbox, Google Drive, and AI tools like ChatGPT are the new blind spots. Employees upload sensitive files without realising they’re creating data loss events.

Human Error

37% of Australian data breaches are caused by human error, not malicious intent. Wrong recipients, accidental uploads, and misconfigured sharing permissions.

“In the first half of 2025, the OAIC received 532 data breach notifications. Human error accounted for 37% of all breaches, with health, finance, and government the most affected sectors.”

“Average reported financial losses, the frequency of ransomware attacks, and the number of reported data breaches all increased throughout FY2024-25.”

“The global average cost of a data breach is USD $4.4 million. Organisations with shadow AI saw an additional $670,000 in breach costs. Malicious insiders remain the costliest attack vector.”

“A former Slater Gordon employee sent malicious emails disclosing staff salaries, performance ratings, and strategic discussions. The emails deliberately excluded IT and senior leadership.”

How ActivityPulse Detects Data Loss

Six data channels monitored in real time, with rules-based detection and automated response when policies are breached.

Complete Coverage Across Every Exit Point

USB & Removable Media

Device connections, file copies, file reads, device serial numbers, and storage capacity. USB drives, phones, SD cards, optical drives. 3 DLP rules: large transfers, sensitive file types, standard transfers.

Downloads

File name, path, size, source URL, and browser. Detects executable downloads, incognito downloads, and large archive files. 3 DLP rules with severity classification.

Web & Cloud Storage

Browsing activity to file hosting sites (WeTransfer, Mega) and personal cloud storage (Dropbox, Google Drive, OneDrive). 2 DLP rules for upload detection.

Email & Attachments

Sender, all recipients including BCC, subject, attachment names, count, and total size. Mass email detection by recipient count. 1 DLP rule for outbound attachments.

Print Jobs

Document name, printer, page count, colour and duplex settings. 2 DLP rules: large jobs (>20 pages) and standard print monitoring.

Clipboard

Content type, text preview, file paths, source application, and data size. 1 DLP rule for file clipboard operations between applications.

Rules-Based Data Movement Monitoring

Configure rules to detect suspicious data movement patterns across all six channels. Respond automatically with alerts, notifications, and retention holds.

Fri 4:42 PM
USB drive connected (Kingston DataTraveler, 64GB)
Fri 4:43 PM
23 files copied from \\server\finance\ to E:\backup
Fri 4:51 PM
Emailed client-contracts-2026.zip to personal Gmail (BCC)
Fri 4:55 PM
Uploaded employee-salaries.xlsx to personal Google Drive
Fri 4:58 PM
Printed “Board Strategy Q2 2026.docx” (14 pages, colour)
Fri 5:01 PM
USB drive disconnected
Fri 5:03 PM
Submitted resignation via email

The Investigation Timeline shows every data movement in chronological order across all six channels. Filter by module, user, or date range. Export as branded PDF or DOCX for legal and compliance records.

Instant Alerts with Automated Protection

41 Pre-built Templates

DLP-specific scenarios: large USB transfers, external email with attachments, cloud uploads, AI file uploads, after-hours printing

Automatic Retention Hold

When a rule fires, automatically preserve all data for the matched user, preventing routine data purge from destroying evidence

Slack, Teams & Email Alerts

Formatted evidence cards delivered to your security team’s channels within seconds of the event occurring

“Average reported financial losses, the frequency of ransomware attacks, and the number of reported data breaches all increased throughout FY2024-25. Credential theft and identity fraud remain the top reported cybercrime types.”

Australian Signals Directorate

Annual Cyber Threat Report, 2024-25 (Australia)