Used to scan 7BN+ unstructured data items Check out the insights
Case Study Financial Services — Credit Union

15 Users.
21,500 Members
at Risk.

A Canadian credit union with a small administrative team discovered that their Microsoft 365 environment contained sensitive member identity data at a scale — and in locations — that nobody had mapped before.

Sector
Financial Services
Region
Canada
Environment
Microsoft 365
Assessment
Partial (pilot scope)

This example features a smaller organization. Data & More serves customers of all sizes — from small teams to enterprises with hundreds or thousands of users across multiple environments.

Estimated Risk Exposure
Based on IBM Cost of a Data Breach methodology
$2.25M
From pilot scope (15 users assessed)
Risk per assessed user$150,049
Items containing privacy data13,010
Data subjects at risk21,500 (19.4K + 2.1K external)
Super-toxic documents (25+ subjects)235
Monthly risk increase+$16,579 / month

This was a partial pilot assessment covering approximately 2.9% of the Exchange environment. Risk extrapolated to the full environment reaches ~$68M.

Limited Scope Example
497GB
Data Assessed
Across Exchange, OneDrive & SharePoint
2.24M
Items Scanned
Pilot scope — partial environment
235
Super-Toxic Docs
Each containing 25+ member data subjects
-3%
Annual Data Growth
Privacy data volume is declining — a positive sign
The Challenge

Member identity data doesn’t stay where it starts.

For a credit union, the intake process for every new member involves collecting government-issued IDs, financial records, and personal information. The challenge is that this data doesn’t disappear after onboarding — it accumulates in email inboxes, team SharePoint sites, and personal OneDrive folders for years.

With only 15 administrative users, it might seem like a manageable problem. But each of those users is a custodian for thousands of member records — making the per-user exposure extremely high, and the stakes of a breach correspondingly significant.

National ID data is everywhere

61% of all sensitive items discovered contain national identification numbers — government-issued IDs collected through standard member onboarding and identity verification processes, left unmanaged long after initial collection.

SharePoint is the primary risk surface

Unlike most organizations where email is the primary exposure point, 55.1% of financial risk here originates in SharePoint Online — where member files and verification documents are stored in team sites with broad internal access.

Member data, not just staff data

19,400 internal and 2,100 external data subjects are at risk — far exceeding the 15-person team. This is member data, collected through normal financial services workflows, sitting unmanaged in the M365 environment.

235 documents with 25+ individuals each

For a 15-user team, 235 “super-toxic” documents — each containing personal data of 25 or more individuals — is an extraordinary concentration. These represent the highest-priority items for immediate attention.

Assessment Findings

What a partial scan of 15 users revealed

Even at pilot scope — covering less than 3% of the Exchange environment — the assessment surfaced thousands of sensitive member records across three storage systems.

Items with Privacy Data
13,010
Identified in a partial scan — 0.58% occurrence rate, concentrated across SharePoint, Exchange, and OneDrive
Super-Toxic Documents
235
Documents each containing 25+ individual data subjects — an unusually high count for 15 users, driven by member file storage in SharePoint
Data Subjects at Risk
21.5K
19,400 internal + 2,100 external individuals — predominantly members whose personal data was found in unmanaged storage
Security Data (Passwords & Secrets)
2,272
Including a critical finding: a single default password template reused across all new employee onboarding — stored in plain text in SharePoint, accessible to all staff
Externally Shared Privacy Data
0 items externally shared
No privacy data was found externally shared from drives. Outgoing privacy data via email was identified at 3,456 items — a workflow pattern to address, but not an external leakage event.
Risk by Data Category

National ID numbers account for 61% of all privacy risk

This distribution is characteristic of financial services: member onboarding and identity verification generates a massive volume of government-issued ID data that tends to stay in the environment indefinitely after initial collection.

National ID Number (Government ID)61%
Recruitment Information10%
Health Information10%
Driver’s License4%
Travel, Employment & Insurance Info9%
Passport, Salary/Financial & Other6%
Risk by Storage Location

SharePoint is the dominant risk — not email

55.1% of financial exposure originates in SharePoint Online — suggesting that member files are stored in team sites or document libraries where access is broad and retention is indefinite. This is a notable departure from most assessments.

SharePoint Online
6 site collections requiring remediation
$1,240,583
55.1% of total risk
Exchange Online
All 15 mailboxes requiring remediation
$977,796
43.4% of total risk
OneDrive for Business
7 locations requiring remediation
$32,351
1.4% of total risk

Key insight: SharePoint-focused remediation policies are the highest-leverage starting point here — and they also create an opportunity to establish proper information architecture for member documents going forward.

Remediation Opportunities

Five policies. $2M immediate.
~$68M extrapolated.

These quick wins were identified from the pilot scope only. The extrapolated column shows the estimated impact if these policies were applied across the full user environment.

~$68M
Extrapolated Risk Reduction
Data Description
Items
Users
Complexity
Risk Reduction
Extrapolated
01
Privacy data in Deleted Items older than 6 months
1,293
11 users
$223,689
~$7.71M
02
Travel information older than 1 year
251
11 users
$43,423
~$1.5M
03
Recruiting information older than 1 year
1,034
12 users
$178,882
~$6.17M
04
ID verification documents older than 1 year
8,686
16 users
$1,502,678
~$51.82M
05
Duplicate email attachments also saved to OneDrive or SharePoint, older than 1 year
290
7 users
$50,171
~$1.73M
Pilot scope risk reduction
$1,998,842
Extrapolated to full environment
~$68M

The extrapolated figures apply the same risk density found in the pilot scope across the full M365 environment. A complete assessment would refine these numbers — but even at a fraction of the extrapolated total, the remediation case is compelling. ID verification alone accounts for ~$51.82M of the extrapolated exposure.

What This Enables

From scattered member records to governed, defensible storage.

Financial institutions face some of the highest regulatory obligations for personal data. This assessment gives the organization the foundation to meet those obligations — not just reactively, but systematically.

A complete picture of member data in M365

For the first time, the organization has a precise inventory of where member identity data lives — enabling targeted remediation rather than broad, disruptive data sweeps.

Regulatory defensibility

With documented discovery, review, and retention policies in place, the organization can demonstrate active data stewardship to regulators — a requirement that’s increasingly scrutinized in financial services.

AI readiness across the full team

100% of users require remediation before member data can be safely consumed by AI tools like Microsoft 365 Copilot. This assessment defines the remediation path — not just the problem.

Credential security remediation

The plain-text password template in SharePoint — used for all new employee onboarding — is an immediate security priority that, once addressed, closes a significant vector for credential-based compromise.

The Forward View
~89% risk reduction
achievable through five targeted quick-win policies
Starting risk (pilot scope)$2,250,730
After quick wins~$251,888
Extrapolated full-environment impact~$68M
New sensitive items added / month95 items
Monthly risk increase$16,579
Annual data growth trend↓3% (declining)
Users requiring AI readiness review100% of team
Privacy items to review13,010
Security items to review2,272

A small team. Thousands of members. One assessment — and a clear, prioritized path to significantly lower risk.

Ready to See Your Numbers?

Every organization’s data tells a story.
Find out what yours says.

A Data & More assessment takes weeks, not months — and gives your team the complete picture needed to act with confidence.