A large healthcare organization in the Middle East needed a clearer view of how employees were handling sensitive information across its environment. In less than three weeks, the DTEX Platform uncovered data movement, from data transfers through personal applications to large volume removable media use.
The findings gave the security team evidence it could act on before a data loss incident was confirmed. With a clearer picture of where risk was developing, the team could focus its investigation and response.
Company profile
The customer is a large healthcare organization operating in the Middle East. Its distributed workforce handles sensitive information in an environment where data can move beyond approved systems and controls.
The need: identifying risky data movement across the environment
The organization needed to determine whether its existing controls could detect use behavior associated with potential data exfiltration. Of particular concern was sensitive information moving outside approved workflows without enough context for the security team to assess the risk.
Any solution also needed to provide broad behavioral coverage without affecting endpoint performance or requiring extensive configuration before analysts could begin finding relevant activity.
The solution: behavioral visibility through the DTEX Platform
The DTEX Platform was deployed across endpoints, including shared workstations and different device types. It began surfacing risky user activity without an observed impact on endpoint performance.
In a two hour analysis session, analysts used mostly out-of-the-box dashboards to connect related activity and see how sensitive information was being handled. The findings exposed areas where the organization’s policies and controls needed closer attention.
Uncovering multiple paths for data loss
DTEX identified several ways sensitive information was moving outside approved workflows:
- Seven users transferred files through FTP, including potential PKI certificates and data from corporate OneDrive storage.
- Four users used Bluetooth to transfer files.
- Two users moved large volumes of data across nine removable media devices. Some of the files may have contained clinical information.
- Additional activity involved personal Gmail accounts, file sharing services, and WhatsApp.
DTEX also connected the creation, possible transfer, and deletion of an archive into a single timeline. The activity occurred within 10 minutes, giving analysts a sequence they could investigate rather than separate events they had to interpret.
Finding risky behavior beyond file transfers
The DTEX Platform also exposed practices that could make data loss more likely. Insecure credentials storage, unapproved software, and unmanaged transfer tools pointed to gaps that required closer attention.
Employees were also using web-based AI tools outside the organization’s approved Microsoft Copilot environment, creating another possible route for sensitive information to leave corporate oversight.
Some behavioral findings required further investigation before the security team could determine whether intervention was necessary. DTEX helped narrow that review to activity that deviated from expected use.
The results
In less than three weeks, the organization turned concerns about potential data loss into evidence of how sensitive information was moving beyond approved workflows. Its security team could now direct investigations and remediation toward activity observed in its own environment.
The results didn’t depend on a length deployment or extensive manual configuration. Analysts identified the findings using mostly out-of-the-box dashboards, while the organization observed no performance impact across the monitored endpoints.
Customer highlights
- Fast time to insight: DTEX surfaced findings from less than three weeks of collected data.
- Efficient analysis: Analysts identified the findings in a two hour session using mostly out-of-the-box dashboards.
- Broad data loss visibility: The organization uncovered sensitive data movement across approved and unapproved channels.
- No observed endpoint impact: The deployment monitored included endpoints without an observed effect on performance.
Ready to Learn More?
See how the DTEX Platform helps security teams uncover hidden insider risk and stop data loss with behavioral intelligence.



