Used to scan 7BN+ unstructured data items Check out the insights
Case Study Municipal Government

19.5% of the Team.
~$4.25M in
Extrapolated Risk.

A proof-of-concept assessment covering 39 of approximately 200 staff — just 19.5% of the organisation — uncovered $827,805 in direct privacy risk. Extrapolated to the full team, that represents an estimated $4.25M in exposure. Years of HR, recruiting, and community service workflows had quietly accumulated nearly 5,000 sensitive items in Microsoft 365.

Sector
Municipal Government
Region
Canada
Environment
Microsoft 365
Assessment
Proof of Concept (39 of ~200 users)

This PoC covered 39 of approximately 200 staff (19.5% of the organisation). The findings extrapolate to an estimated $4.25M in risk across the full team. Data & More serves organisations of all sizes.

Estimated Risk Exposure
Based on IBM Cost of a Data Breach methodology
$827,805
Assessed risk — PoC scope (39 of ~200 users)
~$4.25M
Extrapolated to full ~200-user organisation
Estimated risk per user$21,226
Items containing privacy data4,785
Data subjects at risk595 (468 internal + 127 external)
Super-toxic documents (25+ subjects)12
Estimated monthly risk increase+$14,459 / month
Limited Scope Example
495GB
Data Assessed
Across Exchange, OneDrive & SharePoint
2.46M
Items Scanned
Full environment — all 39 users
12
Super-Toxic Docs
Each containing 25+ individual data subjects
2.4%
Annual Data Growth
Privacy data growing at 2.2% monthly
The Challenge

Normal workflows quietly accumulate sensitive community data.

For a municipality, routine operations — hiring staff, processing insurance, responding to community health inquiries, onboarding volunteers — all generate sensitive personal data. The challenge is that this data doesn’t disappear after the workflow ends. It accumulates in staff email inboxes, sometimes for years, long after any operational need has passed.

With 39 users, this can seem like a manageable problem. But each user acts as a custodian for community member records — residents, employees, contractors, and volunteers — making the exposure per breach event disproportionately high relative to the organization’s size.

Email holds 99.9% of the financial risk

Exchange Online accounts for $827,632 of the $827,805 in total assessed risk. Unlike most organizations where SharePoint is a significant factor, this environment’s risk is almost entirely concentrated in staff email inboxes — a pattern driven by community-facing workflows conducted by email.

HR workflows are the largest source of exposure

Recruiting, employment, and health information — including PHI (personal health information) — represent the dominant data categories. These arise from standard municipal HR processes: hiring, onboarding, benefits administration, and accommodation requests.

Community health data reached staff inboxes

Sensitive health information from community members — including cancer screening inquiries and summer camp medical disclosures — was found in staff email. This is a high-risk category because it involves residents’ personal medical details, not just employee data.

Plain-text credentials stored in Deleted Items

Administrative usernames and passwords for a third-party benefits platform (GreenShield) were found stored in plain text across multiple emails. In most cases the messages had been deleted but were retained in Deleted Items — a gap that a more granular retention policy would directly address.

Assessment Findings

What a PoC scan of 39 users revealed

A proof-of-concept scan covering 39 of approximately 200 staff in the town’s Microsoft 365 environment — all mailboxes, OneDrive locations, and SharePoint site collections — surfaced nearly 5,000 sensitive items and 642 security data items requiring review.

Items with Privacy Data
4,785
0.19% occurrence rate across 2.46M items scanned — predominantly concentrated in Exchange Online, which holds 99.9% of financial risk
Super-Toxic Documents
12
Documents each containing 25 or more individual data subjects — driven by bulk HR, recruitment, and community health records found in staff email
Data Subjects at Risk
595
468 internal + 127 external individuals — community members, employees, and contractors whose personal data was found in unmanaged storage
Security Data (Passwords & Secrets)
642
Includes plain-text credentials for a third-party benefits platform found across multiple staff mailboxes — retained in Deleted Items after employees attempted to delete the messages
Outgoing Privacy Data via Email
681 items sent externally
No privacy data was found externally shared from drives (0 items). Outgoing privacy data was identified exclusively through email — a workflow pattern to address, not an external leakage event.
Risk by Data Category

Recruitment and identity documents account for over 60% of privacy data

This distribution is characteristic of municipal operations: identity verification during hiring and onboarding, combined with community-facing services, generates a steady accumulation of government-issued ID data and HR records that tends to remain in email long after its immediate purpose is served.

National ID Number (Government ID)37%
Recruitment Information26%
Driver’s Licence20%
Travel Information6%
Passport3%
Health, Employment, Salary & Other8%
Risk by Storage Location

Exchange Online dominates — SharePoint is clean

99.9% of financial risk resides in Exchange Online, while SharePoint Online (122 site collections) and OneDrive (38 locations) show near-zero exposure. This is a notably concentrated risk profile — and a strategic advantage, since remediation efforts can focus almost entirely on email.

Exchange Online
38 of 39 mailboxes requiring remediation
$827,632
99.9% of total risk
OneDrive for Business
1 of 38 locations requiring remediation
$173
<0.1% of total risk
SharePoint Online
0 of 122 site collections requiring remediation
$0
100% AI-ready

Key insight: Because risk is so concentrated in email, even a targeted retention policy applied to two or three data categories could eliminate the majority of exposure — without touching SharePoint or OneDrive at all.

Remediation Opportunities

Three policies. $548K immediate.
~$3.74M extrapolated.

These quick wins were identified from the PoC scope. The extrapolated column projects the impact across the full ~200-user organisation at the same risk density.

~$3.74M
Extrapolated Risk Reduction
Data Description
Items
Users
Complexity
Risk Reduction
Extrapolated
01
Employment information older than 12 months
721
25 users
$124,733
~$850k
02
Recruiting information older than 12 months
626
31 users
$108,298
~$738k
03
Health information older than 12 months
1,823
36 users
$315,379
~$2.15M
Assessed risk reduction
$548,410
Extrapolated impact
~$3.74M

Health information is the single largest quick win — 1,823 items across 36 of 39 users, carrying $315,379 in risk reduction from a single medium-complexity policy. Notably, this category includes personal health information (PHI) from community members, making it both a compliance and a community trust priority. The global retention policy already in place has successfully prevented any data older than five years from accumulating — a foundation to build on.

What This Enables

From unmanaged community records to a defensible, governed environment.

Municipalities hold a broad range of sensitive personal data on behalf of their communities. This assessment gives the organization a precise foundation to manage that responsibility — proactively rather than reactively.

A complete picture of where community data lives

For the first time, the organization has a precise inventory of where sensitive personal data resides — enabling targeted remediation rather than broad, disruptive data sweeps across all 39 users.

Municipal privacy obligation compliance

With documented discovery, review, and retention policies in place, the municipality can demonstrate active data stewardship — an increasingly scrutinized obligation for public sector organizations handling community member data.

AI readiness — SharePoint already there

SharePoint Online (122 site collections) is 100% AI-ready today. Exchange Online at 3% requires the most work. With 97% of users needing to participate in the privacy data review, the path is clear and scoped.

Credential security remediation

The plain-text GreenShield credentials found in Deleted Items across multiple mailboxes represent an immediate security priority. Addressing this closes a meaningful attack surface, regardless of whether passwords have since been rotated.

The Forward View
~66% risk reduction
achievable through three targeted quick-win policies
Starting risk (PoC scope — 39 users)$827,805
After three quick wins~$279,395
Extrapolated full-environment impact~$3.74M
New sensitive items added / month83 items
Monthly risk increase$14,459
Annual data growth trend2.4% overall / 2.2% privacy
Users requiring AI readiness review97% (38 of 39)
Privacy items to review4,784
Security items to review642

A small team. Thousands of community records. One assessment — and a clear, prioritized path to significantly lower risk.

Ready to See Your Numbers?

Every organization’s data tells a story.
Find out what yours says.

A Data & More assessment takes weeks, not months — and gives your team the complete picture needed to act with confidence.