Used to scan 7BN+ unstructured data items1BN Insight report

Case StudyPrivacy & Security

From Invisible Risk
to Informed Action

A North American professional services organization with 1,200+ users discovered $7.2M in unmanaged data risk — concentrated in workflows they already knew about, hiding in places they didn’t.

Sector
Professional Services
Region
North America
Environment
Microsoft 365
Assessment
Data & More Assessment
Estimated Risk Exposure
Based on IBM Cost of a Data Breach methodology
$7.2M
Total estimated financial exposure
Risk per user$6,648
Items containing privacy data41,543
Data subjects at risk1,469 (1.1K internal + 369 external)
Monthly risk increase+$63,837 / month
Annual data growth9%
13.3TB
Data Assessed
Across Exchange, OneDrive & SharePoint
52.7M
Items Scanned
~99.7% completion across SharePoint
0.079%
Privacy Data Occurrence
Small percentage, outsized exposure
3.8yr
Avg. Age of Risk Data
Oldest item: April 2007
The Challenge

Sensitive data was accumulating — quietly, continuously, across every system.

Like most organizations, this client knew they had sensitive data. What they didn’t know was exactly where it lived, how much had built up over time, or which business processes were creating the greatest risk.

Privacy data had migrated far beyond controlled systems into the unstructured sprawl of email archives, shared drives, and personal OneDrive folders — accumulating for nearly two decades with no systematic review.

Privacy data living in email

94.7% of the total risk exposure ($6.8M of $7.2M) originated in Exchange Online — email was the primary vehicle for sensitive data ingestion and the primary location where it remained, indefinitely.

18 years of accumulated exposure

The oldest item at risk dated back to April 2007. With no retention policies governing unstructured data, records sat untouched for years — long past any legitimate business need.

Growing risk, month over month

369 new sensitive items were being added every month. Without intervention, every quarter of inaction added ~$192K to the exposure.

Super-toxic document concentration

14 documents contained 25+ individual data subjects each — representing disproportionate breach impact and the clearest candidates for immediate remediation.

Assessment Findings

What 52.7 million items revealed

The Data & More assessment provided a complete picture of the organization’s data risk — across every storage location, data type, and age cohort.

Items with Privacy Data
41,543
Across Exchange, OneDrive, and SharePoint Online — with Exchange carrying 94.7% of the financial exposure
Data Subjects at Risk
1,469
1,100 internal employees and 369 external individuals whose personal data was identified in unmanaged documents
Super-Toxic Documents
14
Documents containing 25+ individual data subjects each — the highest-priority items for immediate remediation
Security Data (Passwords & Secrets)
14,417
Predominantly historical credentials — evidencing a pattern of insecure password storage and distribution that creates ongoing attack surface risk
Externally Shared Privacy Data
0 items externally shared
A significant positive finding: no privacy data was identified as externally shared. The risk is internal, not external-facing — containment is achievable.
Risk by Data Category

Recruiting and travel data account for 73% of all privacy risk

These findings align directly with core business workflows — and that’s good news. The highest-risk data concentrations map precisely to the processes that can be targeted first.

Recruitment46%
Travel Information27%
Health Information10%
Salary & Financial Info4%
Employment Info3%
National ID, Payment Card, Passport & Other10%
Risk by Storage Location

Email is the primary risk surface

$6.8M of the total exposure originates in Exchange Online — characteristic of organizations that process sensitive data through email workflows without systematic migration to governed storage.

Exchange Online
592 mailboxes requiring remediation
$6,808,761
94.7% of total risk
OneDrive for Business
208 locations requiring remediation
$348,076
4.8% of total risk
SharePoint Online
24 site collections requiring remediation
$30,102
0.4% of total risk

Key insight: Because risk is concentrated in Exchange, targeted email remediation policies deliver disproportionate impact with relatively contained scope — a strong starting point for a quick-win programme.

Remediation Opportunities

Five targeted policies.
One major outcome.

These quick wins address the highest-concentration risk categories with low implementation complexity. Together, they reduce estimated exposure by ~82% — before any long-term governance programme is in place.

~$5.86M
Combined Risk Reduction
Data Description
Items
Users
Complexity
Risk Reduction
01
Recruiting information older than 12 months
17,723
371 users
$3,636,182
02
Travel information older than 12 months
9,887
329 users
$2,028,490
03
Health information older than 12 months
3,399
321 users
$697,364
04
Salary / financial information older than 12 months
1,542
180 users
$316,368
05
Duplicate copies of privacy data older than 12 months
1,327
281 users
$229,571
Combined estimated risk reduction~$5,907,975
What This Enables

Visibility creates the foundation for everything else.

Beyond the immediate risk numbers, the assessment gives the organization a set of practical capabilities they didn’t have before — and a clear, sequenced path forward.

A complete data inventory, not estimates

For the first time, the organization knows exactly what sensitive data exists, where it lives, who owns it, and how old it is — across every storage system simultaneously.

AI Copilot readiness assessment

83% of users required remediation to make their data safe for AI consumption. This assessment establishes the baseline and roadmap to Copilot enablement done right.

Sustainable, recurring governance cycles

Each remediation policy recurs automatically every 6 months. Users review, mark, and move on. The programme compounds in impact over time without compounding in effort.

Defensible compliance posture

With documented discovery, review, and remediation cycles in place, the organization can demonstrate active, auditable data stewardship to regulators, auditors, and clients.

The Forward View
~82% risk reduction
achievable through five targeted quick-win policies
Starting risk exposure$7,186,939
After quick wins~$1,279,000
New items added / month369 items
Monthly risk increase (without action)$63,837
Annual cost of inaction~$766,000 / year
Users requiring AI readiness review83% of workforce
Privacy items to review41,543
Security items to review14,425

The data is there. The risk is real. The path forward is clear — and the first steps are straightforward.

Ready to See Your Numbers?

Every organization’s data tells a story.
Find out what yours says.

A Data & More assessment takes weeks, not months — and gives your team the complete picture needed to act with confidence.