
Statistics show that over 80% of organisations experience more than one data security breach in their lifetime. While external attacks often grab headlines, it’s a common misconception that all risks originate from external actors. In fact, 20% of data breaches are caused by individuals who already have access to your data, sometimes maliciously, but often by mistake.
The rise of generative AI tools, while offering immense productivity gains, also introduces new layers of complexity to data security. 80% of organisations are concerned about data leaks in GenAI. If not managed carefully, AI tools can become avenues for data leakage, making it more critical than ever to have security measures in place.
We’ve all seen the recent news around cyber-attacks on major companies like Co-op, M&S and Samsung, costing millions and disrupting services. These aren’t isolated incidents, they highlight the very real impact of security breaches.
Understanding Your Data Security Vulnerabilities
Current ways of working are often dependent on cloud platforms and SaaS applications, which have caused traditional network borders like firewalls to become largely obsolete. This has led to a fragmented data landscape and many organisations struggle to pinpoint where all their sensitive or business-critical data is located.
Consider this startling statistic: over 90% of data within an organisation is “ROT” (Redundant, Obsolete, or Trivial). This data is not actively used and holds little value, yet it still needs to be managed and, more importantly, secured.
The sheer volume of data we generate daily is mind-boggling. Year over year, the amount of data available doubles. With roughly 42 million terabytes of data generated and 376 billion emails sent every single day, organisations are facing increasing data volumes. This means we need to fundamentally rethink how we manage and protect our information.
Data Security Incident Examples
Data security incidents can happen anytime and anywhere. Here are just a few examples:
- Data Compromise by External Threat, e.g. a user falls prey to a phishing attack and compromises the user credentials.
- Data theft by Malicious Insider, e.g. a user copies a file to a USB and uploads this to a personal Dropbox to take to a competitor.
- Data Leak by Negligent insider, e.g. a user negligently shares sensitive data in a consumer generative AI app.
- Data Sabotage by Disgruntled Insider, e.g. a user deletes sensitive information before leaving the organisation.
The Human Element
Data doesn’t move itself, people move data. This highlights the crucial human element in almost every data security incident. Consider these common data security scenarios:
- Inadvertent: A user receives exciting news via email and, with good intentions, shares the file through Microsoft Teams with colleagues, uploads it to personal storage, and downloads a copy. Without proper controls, this seemingly innocent action can lead to data exposure, leakage, and hoarding.
- Malicious: An employee planning to leave the organisation gradually moves sensitive data via email, personal storage, or external drives over a long period. These subtle, prolonged actions are often difficult for traditional data loss prevention solutions to detect.

Data Security Risks of Generative AI
Tools like Copilot are incredibly fast at finding information. If your data doesn’t have appropriate permission management, a malicious user could use Copilot to quickly find sensitive information that might otherwise be difficult to locate.
Another common scenario is that of a negligent user, where sensitive information gets accidentally pasted into public GenAI applications, making that data part of the public training data.
Use Microsoft Purview to Get Ahead of Data Security Challenges
Organisations need to understand the hidden risks to data wherever it lives or travels, protect and prevent data loss across your estate by implementing a defence in depth solution to control and quickly investigate and respond data security incidents. This is where Microsoft Purview comes in.
Microsoft Purview is a suite of products build on three pillars:
- Data Security: Allows security teams to implement multiple layers of protection to secure data across its lifecycle.
- Data Governance: This is a set of tools aimed at data professionals like engineers and data officers.
- Risk & Compliance: Designed to manage the critical risks and help organisations align with regulatory requirements.

The Data Security Component Within Microsoft Purview
- Data Loss Prevention: Preventing sensitive data from leaving your organisation.
- Information Protection: Classifying, labelling, and encrypting sensitive information wherever it lives.
- Insider Risk Management: Monitoring user behaviour to identify and temper potential insider threats.
It’s key to use these solutions together for optimal synergy. For example, you can use Information Protection to classify SharePoint sites and apply access controls or encryption to individual files. This layer of protection stays in place regardless of where that content lives or if it gets moved. It can also be used to find sensitive data both on-premises and in the Cloud, including third party apps.
Insider Risk Management monitors user behaviour and can automatically assign a risk level based on the rules define.
Combining these 2 solutions with the Data Loss Prevention component, you have a compelling solution that can protect data and stop it leaving the organisation, either through email, browser or external devices. Data Loss Prevention can provide different protection levels based on assigned risk levels, from a policy tip for a minor risk to outright blocking for a high-risk user.

Next Steps
The first step is to understand the unique risks and challenges your organisation is facing. The tools within Microsoft Purview are there to help, but you might need assistance getting started.
As generative AI tools proliferate and data volumes grow exponentially, robust security measures are critical to protecting sensitive information and mitigating the risk of breaches.
We currently offer a Microsoft funded Data Security Engagement. Through this engagement we can help you define your data strategy, leveraging Purview, and this includes a trial licence if needed. We will produce a report with practical recommendations and next steps to improve your security posture. If you want to find out if your organisation is eligible for the engagement, please don’t hesitate to contact us.
Last updated 6 Jan 2026
Table of contents
Related insights
Get Industry Insights
Subscribe to stay up to date with Microsoft 365 news and technology
