Protecting Today's Information and Enabling Tomorrow's Technology
DLP can help prevent sensitive information being shared or transferred inappropriately. More importantly, it can establish the data ownership, classification and controls required for AI, automation and connected business systems.
A governed protection layer between information and every destination
Most organisations hold more sensitive information than their leadership teams realise. It is distributed across SharePoint, Teams, OneDrive, email, CRM systems, finance platforms, HR applications, departmental tools, shared folders, employee laptops, downloaded documents, personal spreadsheets, mobile devices and cloud applications. In many cases, no single person has a complete picture of where important data lives or who can access it.
Data can be lost or mishandled in ways that are rarely dramatic. An email is sent to the wrong recipient. A confidential document is placed in an externally shared Teams channel. An employee downloads data to a personal device. A supplier retains access after a project ends. Information is uploaded into an unapproved AI service. A departing employee copies customer or commercial information. A compromised account uses legitimate permissions to collect files. Many of these incidents are accidental rather than malicious.
"The greatest data risk is not always a cybercriminal. It may be an employee making a reasonable decision without understanding where the information can go."
The strategic question for every organisation is: how can it allow employees, applications and AI to use information productively while maintaining control over it? Data Loss Prevention is one of the most important tools available to answer that question.
Data Loss Prevention is a combination of policies, business rules, information classification, employee education, monitoring, technical controls, investigation and governance. It does not operate as a single blocking rule. It is a governed set of responses designed around information, context and risk.
Depending on licensing and architecture, DLP may monitor or control information across Exchange and email, SharePoint, OneDrive, Microsoft Teams, Office applications, managed Windows devices, web browsers, cloud applications, on-premises repositories and removable storage.
When sensitive information is identified and a user attempts an action, the policy evaluates the context and responds accordingly:
The action is permitted because it matches policy. The employee can proceed without interruption.
The employee is informed of the risk before proceeding. They can continue but are made aware.
The employee may continue but must provide a business justification. The reason is recorded.
The activity is recorded for review. No immediate restriction is applied.
The action is prevented. The employee cannot proceed without an approved exception.
An alert is reviewed by an authorised team. Context is gathered and a decision is made.
"DLP is not one blocking rule. It is a governed set of responses designed around information, context and risk."
Understanding how data loss occurs is essential before designing controls. The causes are rarely limited to malicious actors. Most incidents involve employees making reasonable decisions without sufficient guidance or clear information structures.
"Technology can detect risky activity, but it cannot compensate fully for unclear ownership and badly organised information."
Traditional security controls focus on preventing unauthorised access. They protect identities, secure devices, block malware and monitor external threats. DLP adds a complementary layer of controls around what an authorised user or application may do with information after access has been granted.
DLP may support the organisation's wider security, privacy and compliance measures, but is not evidence of compliance by itself. Organisations should involve their legal, privacy and compliance advisers when assessing their regulatory obligations.
Organisations are increasingly introducing Microsoft Copilot, AI assistants, AI agents, automated reporting, workflow automation, connected applications, business intelligence, knowledge assistants, customer portals and automated document processing. Each of these technologies raises the same fundamental question: which information should the technology be permitted to access, and what should it be allowed to do with it?
An employee may previously have needed to search through several SharePoint sites to locate information they should not routinely access. An AI assistant can potentially surface that information through a natural-language question if the existing permissions allow it. The AI did not create the access problem. It made the consequences of that problem easier to experience.
"Before connecting AI to company information, leadership should understand what the AI will be able to find."
For organisations planning to adopt Microsoft Copilot or other AI tools, improving data governance is not a separate project. It is a prerequisite. The AI Structure Every Business Should Adopt explores the governance layers required before AI tools are connected to company information.
AI readiness begins with understanding and controlling the information environment.
DLP is a business project, not an IT configuration. The technology can identify and control sensitive information, but the business must decide what its important data is, where it should live and how employees are permitted to use it.
Consider a category called"customer information". It may include public contact details, commercial discussions, bank details, contracts, service records, complaints, health or personal information and sales opportunities. Different controls may be appropriate for each. Only the business can make those distinctions.
Data governance should also form part of the organisation's wider technology roadmap. The IT Strategy Supporting Your Business Strategy guide explores how to align technology decisions with commercial goals.
Sets objectives, approves scope, removes blockers, owns accountability.
Configures Microsoft Purview, manages technical implementation and testing.
Defines risk appetite, reviews alerts, leads incident response.
Advises on personal data, UK GDPR implications and privacy impact.
Reviews policy for contractual obligations, privilege and regulatory risk.
Owns employee data, advises on communications, supports disciplinary process.
Owns financial information, approves controls on commercial data.
Owns customer and pipeline information, advises on legitimate sharing needs.
Owns process documentation, supplier data and operational repositories.
Identify important data, review access, tag folders, approve classifications.
Apply labels, respond to warnings, provide justifications, report mistakes.
"The business must define appropriate use. IT translates those decisions into technical controls."
Before any DLP policy is designed, the organisation should understand what important information it holds, where it is stored, who owns it, who can access it, who needs access, how it is shared, which applications use it, how long it should be retained, and the impact of disclosure or unavailability.
Employee, customer, supplier or beneficiary information. Often subject to UK GDPR obligations.
Bank details, management accounts, forecasts, payroll and payment records.
Pricing, proposals, contracts, customer lists and pipelines.
Designs, source code, research, methodologies and product plans.
Board papers, legal advice, disputes, acquisition information and regulatory records.
Processes, supplier information, system details and service documentation.
Before DLP policies are deployed, the existing SharePoint, Teams and OneDrive environment should be reviewed. Common weaknesses include duplicate SharePoint sites, multiple Teams spaces for the same purpose, unclear ownership, excessive internal access, historic external guests, confidential data in general collaboration areas, project sites retained indefinitely, departmental information stored in personal OneDrive, files copied into several locations and inconsistent folder naming.
"Applying strict DLP policies to a disorganised information structure can make the disorder more disruptive, rather than solving it."
| Site or workspace | Business owner | Sensitivity | Guest access | Current issues | Required action |
|---|---|---|---|---|---|
| HR Policies and Procedures | HR Director | Confidential | None | Broad internal access | Restrict to HR team |
| Client Project - Acme 2023 | Account Manager | Confidential | 3 external guests | Project ended, guests retained | Archive and remove guests |
| Finance Team | CFO | Highly Confidential | None | No formal owner assigned | Assign owner, review access |
| General Company Updates | IT | Internal | None | Confidential docs mixed in | Move sensitive files |
| Board Papers | CEO | Highly Confidential | None | Stored in personal OneDrive | Move to governed repository |
Wavex can provide a structured departmental template or workshop process. For each important folder, library, repository or data set, the department should be asked a consistent set of questions. Departments should not be given unrestricted responsibility to invent classifications. The organisation should define a small, consistent classification model first, and departments should work within it.
When assessing new applications and platforms, it is also worth reviewing how they handle company data. The guide on Why Software Selection Fails and How to Get It Right covers the questions to ask about unapproved applications and shadow IT.
The following four levels are illustrative. The final labels and terminology should reflect the organisation's needs, culture and regulatory context. The key principle is consistency: a model that employees can understand and apply reliably is more valuable than a complex taxonomy that is inconsistently used.
Approved for unrestricted external use.
Examples:
Controls: No restriction on sharing or distribution.
Routine company information intended primarily for employees.
Examples:
Controls: Warning before external sharing. Not for public distribution.
Information requiring controlled access and careful external sharing.
Examples:
Controls: Monitor, restrict or require justification for external sharing.
Information where disclosure could create serious personal, legal, financial or strategic harm.
Examples:
Controls: Strong restrictions, encryption and alerting. Named and approved access only.
Too many classifications create uncertainty. Too few may fail to distinguish genuinely different risks.
Once the classification model is agreed, the organisation should define what each label means in practice. The policy should distinguish between routine legitimate activity, unusual but justifiable activity, high-risk activity and prohibited activity.
| Classification | Typical use | External sharing | Example response |
|---|---|---|---|
| Public | Approved external content | Permitted | No restriction |
| Internal | Routine employee information | Usually discouraged | Warning before external sharing |
| Confidential | Customer, commercial and financial information | Controlled | Monitor, restrict or require justification |
| Highly Confidential | Board, legal, acquisition and highly sensitive personal information | Named and approved access only | Strong restrictions, encryption and alerting |
A policy that blocks legitimate work will encourage employees to search for another route. The recommended approach is to introduce controls gradually, beginning with audit or simulation mode to understand real-world activity before any restrictions are applied.
Agree the intended outcome and policy scope.
Run the policy in audit or simulation mode.
Review how often it triggers and who is affected.
Identify false positives and legitimate practices.
Explain classifications, warnings and safe alternatives.
Introduce policy tips and user notifications.
Allow controlled override where business use requires it.
Block actions where the risk supports stronger control.
Review significant alerts and repeated exceptions.
Refine the rules as the business changes.
"A policy that blocks legitimate work will encourage employees to search for another route."
The objective is not to stop employees using information. It is to allow people and technology to use it productively without losing control over where it goes. Employee communication is therefore a critical part of any DLP programme.
"The best warning tells the employee what is wrong and how to complete the task safely."
The governance structure around DLP is as important as the technical configuration. The organisation should define who reviews alerts, which alerts are urgent, how business context is obtained, when security, HR, legal or compliance becomes involved, how false positives are recorded, how policy changes are approved, how repeated exceptions are escalated and how leadership receives reporting.
The goal is not necessarily zero DLP events. Some legitimate business processes require sensitive information to be used and shared. The objective is visibility and appropriate control.
A structured approach to planning, implementing and governing Data Loss Prevention across the organisation.
Wavex helps clients connect the technical controls with the business decisions, information ownership and employee processes required for DLP to work effectively. DLP is a project Wavex can help clients plan, implement and operate, providing technology, security and governance support throughout.
Wavex does not provide legal advice or make final regulatory interpretations. Where required, clients should involve their legal, privacy and compliance advisers to assess their specific obligations.
Understand data, systems, risks and objectives. Review the Microsoft 365 environment, licensing, information landscape and AI-readiness risks.
Agree classification model, ownership structure and policy behaviour. Define what should be allowed, warned, justified, monitored or blocked.
Configure Microsoft Purview, test in simulation, pilot with selected teams and introduce controls gradually.
Review alerts, refine policies, assess new applications and adapt governance to changing business needs and technology.
Discuss how DLP, information classification and Microsoft Purview could support your security, compliance and AI strategy.
Talk to Wavex About Data Loss PreventionData is becoming more important to customer service, reporting, decision-making, automation, AI, business growth and employee productivity. The more valuable data becomes, the more important it is to understand what it contains, where it lives, who owns it, who can access it, where it can be shared, how it should be protected and how long it should be retained.
The strongest DLP programmes do not begin with widespread blocking. They begin with understanding the data, assigning ownership, improving information structures, defining clear classifications, testing policies, educating employees, introducing controls gradually and maintaining ongoing governance. How technology can support this kind of structured, governed growth is explored further in the guide on How Technology Can Improve Revenue and Profitability.
"Can we confidently allow our people, applications and future AI systems to use company information without losing control over where that information goes?"
Wavex helps organisations assess, design, implement and govern Data Loss Prevention across Microsoft 365, Microsoft Purview and the wider technology environment.
Speak with a Wavex specialist about DLP, information classification and Microsoft Purview. No sales pitch - just an honest conversation about your data governance challenges.