Understanding and Controlling Sensitive Data

Falx deployed Data Loss Prevention and Microsoft Purview sensitivity labels across Microsoft 365, achieving 100% label coverage and blocking Confidential content from Microsoft Copilot.

Read

Understanding and Controlling Sensitive Data

Understanding and Controlling Sensitive Data

The Challenge: Sensitive Information without Controls

Because of the nature of the client’s operations, sensitive corporate and customer information was regularly stored and sent through Microsoft 365 apps. Without adequate safeguards, this unmonitored data remained vulnerable to unauthorised disclosure and leaks.

Falx implemented and reviewed scans across the environment which revealed a significant volume of high-risk sensitive data, including credit and debit card numbers (a PCI-DSS risk), National Insurance numbers, driver’s licence numbers (a GDPR UK risk), and passwords. Without structured classification, automated controls, or explicit boundaries for internal versus external sharing, the organisation faced heightened risk of unintentional data loss and regulatory non-compliance.


Falx’s Approach: Review, Protect, and Monitor

To address these vulnerabilities, Falx implemented a structured Data Loss Prevention (DLP) framework and Microsoft Purview Sensitivity Label strategy tailored to the organisation’s operational requirements.

  • Review of Sensitive Information Types (SITs): Falx conducted comprehensive environment scans to identify high-risk data patterns. Automated labelling rules were configured to detect these information types and apply the relevant label when required.
  • Design and Implementation of a ‘Base’ Label Set: Falx established four core sensitivity labels across all Microsoft 365 apps to standardise document and email classification.
  • Supplemental Labels for Differing Use Cases: To support business continuity without weakening security, targeted supplemental labels were designed for specialised external sharing use cases.
  • Monitoring and Governance: To maintain complete oversight of classification activity, Falx set up continuous auditing across all deployed sensitivity labels. Mandatory business justification is required for any label downgrade, while custom alerts track higher-risk labels and external sending.

The Results: Full Coverage and Visibility

  • Complete Label Coverage: Achieved 100% labelling across all Microsoft 365 environments, leveraging automated scanning and labelling.
  • Continuous Data Flow Oversight: Established monitoring and real-time alerts to audit outbound communication and prevent unauthorised exfiltration of sensitive data.
  • AI Control: Falx created Data Loss Prevention policies to prevent 100% of Confidential and Highly Confidential labelled content from being processed by Microsoft Copilot.

Is your sensitive data protected?

Get in touch to see how Falx can protect your business from sensitive data leaks.


Contact Falx

Discuss Technical Due Diligence and Technology Transformations