Data Security and AI Readiness

Data Loss Prevention

Protecting Today's Information and Enabling Tomorrow's Technology

DLP can help prevent sensitive information being shared or transferred inappropriately. More importantly, it can establish the data ownership, classification and controls required for AI, automation and connected business systems.

Most organisations hold more sensitive information than their leadership teams realise. It is distributed across SharePoint, Teams, OneDrive, email, CRM systems, finance platforms, HR applications, departmental tools, shared folders, employee laptops, downloaded documents, personal spreadsheets, mobile devices and cloud applications. In many cases, no single person has a complete picture of where important data lives or who can access it.

Data can be lost or mishandled in ways that are rarely dramatic. An email is sent to the wrong recipient. A confidential document is placed in an externally shared Teams channel. An employee downloads data to a personal device. A supplier retains access after a project ends. Information is uploaded into an unapproved AI service. A departing employee copies customer or commercial information. A compromised account uses legitimate permissions to collect files. Many of these incidents are accidental rather than malicious.

"The greatest data risk is not always a cybercriminal. It may be an employee making a reasonable decision without understanding where the information can go."

The strategic question for every organisation is: how can it allow employees, applications and AI to use information productively while maintaining control over it? Data Loss Prevention is one of the most important tools available to answer that question.

DLP helps control what happens to sensitive information

Data Loss Prevention is a combination of policies, business rules, information classification, employee education, monitoring, technical controls, investigation and governance. It does not operate as a single blocking rule. It is a governed set of responses designed around information, context and risk.

Depending on licensing and architecture, DLP may monitor or control information across Exchange and email, SharePoint, OneDrive, Microsoft Teams, Office applications, managed Windows devices, web browsers, cloud applications, on-premises repositories and removable storage.

When sensitive information is identified and a user attempts an action, the policy evaluates the context and responds accordingly:

Sensitive information identified
User attempts an action
Context evaluated
Policy response applied
Allow

The action is permitted because it matches policy. The employee can proceed without interruption.

Warn

The employee is informed of the risk before proceeding. They can continue but are made aware.

Justify

The employee may continue but must provide a business justification. The reason is recorded.

Monitor

The activity is recorded for review. No immediate restriction is applied.

Block

The action is prevented. The employee cannot proceed without an approved exception.

Investigate

An alert is reviewed by an authorised team. Context is gathered and a decision is made.

"DLP is not one blocking rule. It is a governed set of responses designed around information, context and risk."

Data loss is often caused by convenience, complexity and unclear rules

Understanding how data loss occurs is essential before designing controls. The causes are rarely limited to malicious actors. Most incidents involve employees making reasonable decisions without sufficient guidance or clear information structures.

Accidental sharing

  • Email sent to the wrong recipient
  • Wrong attachment included
  • Confidential document placed in an externally shared Teams channel
  • External sharing link sent unintentionally

"Technology can detect risky activity, but it cannot compensate fully for unclear ownership and badly organised information."

Security must follow the data beyond the network boundary

Traditional security controls focus on preventing unauthorised access. They protect identities, secure devices, block malware and monitor external threats. DLP adds a complementary layer of controls around what an authorised user or application may do with information after access has been granted.

Traditional security focus

  • Prevent unauthorised access
  • Protect identities and credentials
  • Secure devices and endpoints
  • Block malware and external threats
  • Monitor for external intrusion

DLP focus

  • Understand the information itself
  • Control what authorised users can do
  • Govern external sharing and movement
  • Monitor information wherever it travels
  • Protect content beyond the perimeter
  • Investigate inappropriate activity

DLP may support the organisation's wider security, privacy and compliance measures, but is not evidence of compliance by itself. Organisations should involve their legal, privacy and compliance advisers when assessing their regulatory obligations.

AI makes existing data-governance weaknesses easier to exploit

Organisations are increasingly introducing Microsoft Copilot, AI assistants, AI agents, automated reporting, workflow automation, connected applications, business intelligence, knowledge assistants, customer portals and automated document processing. Each of these technologies raises the same fundamental question: which information should the technology be permitted to access, and what should it be allowed to do with it?

An employee may previously have needed to search through several SharePoint sites to locate information they should not routinely access. An AI assistant can potentially surface that information through a natural-language question if the existing permissions allow it. The AI did not create the access problem. It made the consequences of that problem easier to experience.

Without data governance

Poor information structure+Excessive permissions+AI search
Faster discovery of inappropriate information

With data governance

Clear ownership+Appropriate permissions+Classification and DLP
More controlled AI adoption

"Before connecting AI to company information, leadership should understand what the AI will be able to find."

For organisations planning to adopt Microsoft Copilot or other AI tools, improving data governance is not a separate project. It is a prerequisite. The AI Structure Every Business Should Adopt explores the governance layers required before AI tools are connected to company information.

The Data Foundation for Future Technology

AI readiness begins with understanding and controlling the information environment.

Business use
EmployeesCustomersSuppliersAIAutomationReporting
Approved access
IdentityRoleDepartmentDeviceApplicationBusiness purpose
Information protection
Sensitivity labelsDLP policiesSharing controlsEncryptionRetentionAlerts
Information architecture
SharePointTeamsOneDriveCRMBusiness applicationsApproved repositories
Governance foundation
Data ownershipClassificationPolicySecurityPrivacyReviewAccountability

IT can configure the policies. It cannot decide what every department's information means.

DLP is a business project, not an IT configuration. The technology can identify and control sensitive information, but the business must decide what its important data is, where it should live and how employees are permitted to use it.

Consider a category called"customer information". It may include public contact details, commercial discussions, bank details, contracts, service records, complaints, health or personal information and sales opportunities. Different controls may be appropriate for each. Only the business can make those distinctions.

Data governance should also form part of the organisation's wider technology roadmap. The IT Strategy Supporting Your Business Strategy guide explores how to align technology decisions with commercial goals.

Executive sponsor

Sets objectives, approves scope, removes blockers, owns accountability.

IT

Configures Microsoft Purview, manages technical implementation and testing.

Cybersecurity

Defines risk appetite, reviews alerts, leads incident response.

Data protection

Advises on personal data, UK GDPR implications and privacy impact.

Legal

Reviews policy for contractual obligations, privilege and regulatory risk.

HR

Owns employee data, advises on communications, supports disciplinary process.

Finance

Owns financial information, approves controls on commercial data.

Sales

Owns customer and pipeline information, advises on legitimate sharing needs.

Operations

Owns process documentation, supplier data and operational repositories.

Departmental data owners

Identify important data, review access, tag folders, approve classifications.

Employees

Apply labels, respond to warnings, provide justifications, report mistakes.

"The business must define appropriate use. IT translates those decisions into technical controls."

Do not begin by creating blocking policies

Before any DLP policy is designed, the organisation should understand what important information it holds, where it is stored, who owns it, who can access it, who needs access, how it is shared, which applications use it, how long it should be retained, and the impact of disclosure or unavailability.

Personal information

Employee, customer, supplier or beneficiary information. Often subject to UK GDPR obligations.

  • Names and contact details
  • HR records
  • Health information
  • Financial details

Financial information

Bank details, management accounts, forecasts, payroll and payment records.

  • Bank account details
  • Management accounts
  • Payroll records
  • Forecasts and budgets

Commercial information

Pricing, proposals, contracts, customer lists and pipelines.

  • Pricing structures
  • Customer contracts
  • Sales pipeline
  • Commercial proposals

Intellectual property

Designs, source code, research, methodologies and product plans.

  • Product designs
  • Source code
  • Research findings
  • Proprietary methodologies

Legal and governance

Board papers, legal advice, disputes, acquisition information and regulatory records.

  • Board minutes
  • Legal advice
  • Acquisition documents
  • Regulatory correspondence

Operational information

Processes, supplier information, system details and service documentation.

  • System credentials
  • Supplier contracts
  • Process documentation
  • Service records

DLP often exposes problems in the existing Microsoft 365 structure

Before DLP policies are deployed, the existing SharePoint, Teams and OneDrive environment should be reviewed. Common weaknesses include duplicate SharePoint sites, multiple Teams spaces for the same purpose, unclear ownership, excessive internal access, historic external guests, confidential data in general collaboration areas, project sites retained indefinitely, departmental information stored in personal OneDrive, files copied into several locations and inconsistent folder naming.

"Applying strict DLP policies to a disorganised information structure can make the disorder more disruptive, rather than solving it."

Site or workspaceBusiness ownerSensitivityGuest accessCurrent issuesRequired action
HR Policies and ProceduresHR DirectorConfidentialNoneBroad internal accessRestrict to HR team
Client Project - Acme 2023Account ManagerConfidential3 external guestsProject ended, guests retainedArchive and remove guests
Finance TeamCFOHighly ConfidentialNoneNo formal owner assignedAssign owner, review access
General Company UpdatesITInternalNoneConfidential docs mixed inMove sensitive files
Board PapersCEOHighly ConfidentialNoneStored in personal OneDriveMove to governed repository

Recommended remediation actions

Remove obsolete sites and workspaces
Assign owners to unowned repositories
Review and tighten permissions
Remove unnecessary external guests
Archive completed project sites
Move sensitive data to governed locations
Establish standard site types
Create secure repositories for confidential data
Clarify the role of personal OneDrive

Departments must help identify the information they understand best

Wavex can provide a structured departmental template or workshop process. For each important folder, library, repository or data set, the department should be asked a consistent set of questions. Departments should not be given unrestricted responsibility to invent classifications. The organisation should define a small, consistent classification model first, and departments should work within it.

When assessing new applications and platforms, it is also worth reviewing how they handle company data. The guide on Why Software Selection Fails and How to Get It Right covers the questions to ask about unapproved applications and shadow IT.

Departmental data-tagging worksheet

1What does this folder or repository contain?
2Who owns it?
3Who uses it and who needs access?
4Does it contain personal information?
5Is it commercially sensitive?
6Can it be shared externally?
7What would happen if it were disclosed?
8What would happen if access were lost?
9How long should it be retained?
10Is it stored in the correct location?
11Is it still required?
12Can all employees access it?

A classification model must be simple enough for employees to use

The following four levels are illustrative. The final labels and terminology should reflect the organisation's needs, culture and regulatory context. The key principle is consistency: a model that employees can understand and apply reliably is more valuable than a complex taxonomy that is inconsistently used.

Public

Approved for unrestricted external use.

Examples:

  • Published marketing content
  • Public reports
  • Approved website material

Controls: No restriction on sharing or distribution.

Internal

Routine company information intended primarily for employees.

Examples:

  • General procedures
  • Internal announcements
  • Routine working documents

Controls: Warning before external sharing. Not for public distribution.

Confidential

Information requiring controlled access and careful external sharing.

Examples:

  • Customer information
  • Contracts
  • Commercial proposals
  • Management reports

Controls: Monitor, restrict or require justification for external sharing.

Highly Confidential

Information where disclosure could create serious personal, legal, financial or strategic harm.

Examples:

  • Board papers
  • Acquisition documents
  • Legal advice
  • Sensitive HR records

Controls: Strong restrictions, encryption and alerting. Named and approved access only.

Too many classifications create uncertainty. Too few may fail to distinguish genuinely different risks.

A label should lead to a clear and proportionate control

Once the classification model is agreed, the organisation should define what each label means in practice. The policy should distinguish between routine legitimate activity, unusual but justifiable activity, high-risk activity and prohibited activity.

ClassificationTypical useExternal sharingExample response
PublicApproved external contentPermittedNo restriction
InternalRoutine employee informationUsually discouragedWarning before external sharing
ConfidentialCustomer, commercial and financial informationControlledMonitor, restrict or require justification
Highly ConfidentialBoard, legal, acquisition and highly sensitive personal informationNamed and approved access onlyStrong restrictions, encryption and alerting

Additional policy decisions to agree

Can users print the document?
Can users copy content?
Can files be downloaded to devices?
Can information be pasted into websites?
Can it be uploaded into AI tools?
Can mobile devices access it?
Can the user override a warning?
Who approves exceptions?
Who investigates alerts?

Start by observing, not blocking

A policy that blocks legitimate work will encourage employees to search for another route. The recommended approach is to introduce controls gradually, beginning with audit or simulation mode to understand real-world activity before any restrictions are applied.

1

Define

Agree the intended outcome and policy scope.

2

Simulate

Run the policy in audit or simulation mode.

3

Observe

Review how often it triggers and who is affected.

4

Validate

Identify false positives and legitimate practices.

5

Educate

Explain classifications, warnings and safe alternatives.

6

Warn

Introduce policy tips and user notifications.

7

Justify

Allow controlled override where business use requires it.

8

Enforce

Block actions where the risk supports stronger control.

9

Investigate

Review significant alerts and repeated exceptions.

10

Improve

Refine the rules as the business changes.

"A policy that blocks legitimate work will encourage employees to search for another route."

DLP should guide employees, not simply surprise them

The objective is not to stop employees using information. It is to allow people and technology to use it productively without losing control over where it goes. Employee communication is therefore a critical part of any DLP programme.

Employee attempts to share information
Warning explains the concern
Safe alternative is offered
Legitimate exception can be justified
Activity is recorded
Why DLP is being introduced
What classifications mean in practice
How labels should be selected
Where information should be stored
Why a warning appeared
When an override is permitted
What justification is required
Which AI and cloud applications are approved
How to share sensitive information safely
How to report a mistake quickly
Where to get help

"The best warning tells the employee what is wrong and how to complete the task safely."

A DLP alert has no value unless somebody owns the response

The governance structure around DLP is as important as the technical configuration. The organisation should define who reviews alerts, which alerts are urgent, how business context is obtained, when security, HR, legal or compliance becomes involved, how false positives are recorded, how policy changes are approved, how repeated exceptions are escalated and how leadership receives reporting.

The goal is not necessarily zero DLP events. Some legitimate business processes require sensitive information to be used and shared. The objective is visibility and appropriate control.

DLP events by department
External sharing attempts
Overrides and justifications
Repeated policy activity
Unapproved applications involved
Sensitive data in incorrect locations
High-volume downloads
Excessive false positives
Data owners with overdue actions

The Data Loss Prevention Project Roadmap

A structured approach to planning, implementing and governing Data Loss Prevention across the organisation.

How Wavex Helps Organisations Deliver Data Loss Prevention

Wavex helps clients connect the technical controls with the business decisions, information ownership and employee processes required for DLP to work effectively. DLP is a project Wavex can help clients plan, implement and operate, providing technology, security and governance support throughout.

Initial assessment

  • Current Microsoft 365 environment
  • Licensing and capability review
  • Existing information-protection controls
  • Data and application landscape
  • AI-readiness risks
  • Current external sharing

Data and structure discovery

  • SharePoint and Teams review
  • OneDrive usage review
  • Site and workspace ownership
  • Permission and guest-access review
  • Important repository identification
  • Data-owner workshops

Classification design

  • Classification model
  • Sensitivity-label structure
  • Container labels
  • Default labels
  • Departmental guidance
  • Practical classification examples

Policy design

  • DLP use cases
  • Policy scope
  • Allow, warn, justify and block decisions
  • Approved exceptions
  • Alert routes
  • Escalation and testing criteria

Technical implementation

  • Microsoft Purview configuration
  • Sensitivity labels
  • DLP policies
  • Endpoint controls where licensed
  • Approved pilot deployment
  • Logging and alerting

Employee enablement

  • Communications
  • Training
  • Policy-tip guidance
  • Safe-sharing instructions
  • Departmental support
  • Frequently asked questions

Governance and operation

  • Alert-review process
  • Reporting
  • Policy refinement
  • Periodic access reviews
  • New application assessment
  • AI governance integration

Wavex does not provide legal advice or make final regulatory interpretations. Where required, clients should involve their legal, privacy and compliance advisers to assess their specific obligations.

A structured engagement model

1

Discover

Understand data, systems, risks and objectives. Review the Microsoft 365 environment, licensing, information landscape and AI-readiness risks.

2

Design

Agree classification model, ownership structure and policy behaviour. Define what should be allowed, warned, justified, monitored or blocked.

3

Deploy

Configure Microsoft Purview, test in simulation, pilot with selected teams and introduce controls gradually.

4

Govern

Review alerts, refine policies, assess new applications and adapt governance to changing business needs and technology.

Discuss how DLP, information classification and Microsoft Purview could support your security, compliance and AI strategy.

Talk to Wavex About Data Loss Prevention

Data Loss Prevention FAQs

Data is becoming more important to customer service, reporting, decision-making, automation, AI, business growth and employee productivity. The more valuable data becomes, the more important it is to understand what it contains, where it lives, who owns it, who can access it, where it can be shared, how it should be protected and how long it should be retained.

The strongest DLP programmes do not begin with widespread blocking. They begin with understanding the data, assigning ownership, improving information structures, defining clear classifications, testing policies, educating employees, introducing controls gradually and maintaining ongoing governance. How technology can support this kind of structured, governed growth is explored further in the guide on How Technology Can Improve Revenue and Profitability.

"Can we confidently allow our people, applications and future AI systems to use company information without losing control over where that information goes?"

Talk to Wavex About Data Loss Prevention

Wavex helps organisations assess, design, implement and govern Data Loss Prevention across Microsoft 365, Microsoft Purview and the wider technology environment.

Discuss a Data Loss Prevention Project

Speak with a Wavex specialist about DLP, information classification and Microsoft Purview. No sales pitch - just an honest conversation about your data governance challenges.

No commitment required. Your data is protected under GDPR.