Data Exfiltration
Data exfiltration is the unauthorised transfer of data out of an organisation, whether by malware, by an insider, or by an attacker using an account they have taken over.
What is Data Exfiltration?
Definition
Data Exfiltration is the unauthorised movement of data out of an organisation — by malware, by an insider, or by an attacker using an account they have taken over. It is the stage at which a quiet intrusion becomes a reportable breach, which is why detection focuses on the shape of the traffic rather than its content: unusual volumes, unusual destinations, unusual hours, or data leaving through a channel that has no business carrying it. Encryption and ordinary cloud storage make the traffic itself unremarkable, so in cybersecurity practice the useful signals are almost always about context.
Role in cybersecurity
Data Exfiltration plays an important role in building organizational resilience against cyber threats. Implementing appropriate mechanisms in this area is required by regulations such as NIS2, DORA and ISO 27001.