Data loss prevention gap analysis for [REDACTED] covering data classification maturity, Microsoft Purview DLP policy coverage across M365 and endpoint, and sensitive data exposure risks. Engagement ref. ENG-2025-0565.
Plaidnox conducted a data protection gap analysis for [REDACTED], reviewing data classification coverage, Microsoft Purview DLP policies across Exchange, SharePoint, OneDrive, Teams, and endpoint, and sensitive data inventory. Only 2 of 5 required policy sets are active, and data classification labels are applied to fewer than 12% of documents in the SharePoint environment.
The most critical finding is 22 unclassified SharePoint site collections containing personally identifiable information (PII) for clients and staff . these 22 sites have no DLP policy applied and no sensitivity label, meaning any licensed user can download or share all content without restriction.
| Workload | DLP Policy | Classification | Risk |
|---|---|---|---|
| Exchange Online (Email) | Active | N/A | Medium |
| SharePoint Sites | Missing | 12% labelled | Critical |
| OneDrive for Business | Missing | 8% labelled | Critical |
| Microsoft Teams | Active | N/A | Low |
| Endpoint (Windows) | Missing | N/A | High |
| ID | Finding | Priority |
|---|---|---|
| DLP-G01 | 22 SharePoint site collections with PII have no DLP policy or sensitivity label . full exfiltration risk | Critical |
| DLP-G02 | No SharePoint/OneDrive DLP policy . files containing SINs, DOBs, and legal case data can be shared externally undetected | Critical |
| DLP-G03 | No endpoint DLP . USB transfer and unmanaged browser upload of sensitive files not blocked or audited | High |
| DLP-G04 | 88% of documents unlabelled . auto-labelling policies not deployed, classification is manual only | High |
| DLP-G05 | No DLP alert routing . existing Exchange/Teams DLP violations not routed to security team for review | Medium |
| Action | Timeline | Owner |
|---|---|---|
| Apply Confidential sensitivity label to all 22 PII SharePoint sites; block external sharing | Wk 1 | IT / Plaidnox |
| Deploy Purview auto-labelling policies for PII, legal privilege, and financial data across SharePoint/OneDrive | Wk 1-4 | Plaidnox |
| Create DLP policies for SharePoint and OneDrive . block sharing of labelled content externally | Wk 2-5 | Plaidnox |
| Enable endpoint DLP . block USB transfer and unmanaged cloud upload of Confidential+ files | Wk 3-6 | Plaidnox / IT |
| Configure DLP alert routing to SIEM / SOC mailbox; set SLA for violation review | Wk 4-8 | Plaidnox |