Your sensitive data has moved.
Do you know where it is?
Sensitive information spreads as organisations grow across Microsoft 365, AI Platforms, collaboration tools, business systems, SaaS, external partners and changing teams.
Wentland helps organisations understand what information they hold, establish responsibility for it and implement proportionate controls around access, sharing, retention and data loss.
Where To Start:
Information governance can become an enormous programme very quickly.
Microsoft 365 and Sharepoint. Shared drives and servers. Business applications. Historic project data. External collaboration. Retention. Access. Classification. And now AI.
Trying to address everything at once can become difficult to define, expensive to deliver and almost impossible to finish.
Fortuntately, you do not need to start there.
A more useful question is:
Which information creates the greatest concern today, and what decisions need to be made about it?
That might be
- Confidential information shared too widely.
- Former employees or external partners retaining access.
- Sensitive records with no clear owner.
- An acquired business with different information practices.
- Uncertainty over what AI tools should be allowed to access.
We help define that starting point, establish who needs to be involved and determine the controls that matter first, because the objective in not to govern everything. It is to identify the information that matters most and govern it appropriately.
OWNERSHIP THROUGH THE LIFECYCLE
Information Without Ownership Becomes Organisational Risk
Information rarely becomes difficult to govern overnight.
Projects finish. Teams change. Employees leave. Departments grow. Businesses merge. New collaboration platforms are introduced.
Permissions accumulate. Files are copied, shared, archived, and sometimes forgotten.
When a project ends, its shared workspace may remain. Staff change roles, external collaborators finish their work and information moves elsewhere. The information still exists, but responsibility for it may no longer be obvious.
We help establish who owns each information category and how decisions about access, sharing and retention are made.
Those responsibilities need to remain understandable after the original project team has moved on.
Then apparently simple questions become harder to answer:
- Who owns this information?
- Who still needs access?
- Why does this folder contain many confidential documents?
- Why are sensitive files accessible to external users?
GOVERNANCE IN PRACTICE
Governance That People Will Actually Follow
Information Governance Strategy
Define responsibilities, decision-making and priorities around the organisation's information and operating requirements.
Data Classification & Sensitivity Models
Establish information categories and handling requirements that reflect sensitivity, business impact and relevant obligations.
Microsoft 365 Information Protection
Translate those requirements into protection settings across the collaboration services in scope.
Data Loss Prevention (DLP)
Design and implement proportionate rules for detecting and controlling sensitive information transfers, with legitimate workflows considered.
Sensitivity Labels
Configure labels that express the agreed classification and apply protection appropriate to their intended use.
Information Lifecycle Management
Connect retention, archiving and deletion requirements to technical controls and defined responsibility for exceptions.
Access Governance
Align information access with roles, approvals and review processes, including staff changes and external users.
Secure Collaboration
Establish sharing arrangements, guest access and link controls that support approved work with colleagues and third parties.
Executive Governance Reporting
Provide leadership with a usable view of material gaps, responsibilities and improvement priorities.
The Right Level of Protection
Not bolted shut. Not left wide open.
The objective is not to put so many controls around information that people struggle to do their jobs. Nor is it to remove controls simply because they get in the way.
It is to make the right information available to the right people, under the right conditions.
FROM POLICY TO CONFIGURATION
Governance Has To Become Practice
Once the handling requirements are clear, we translate them into appropriate technical controls across the systems where information is stored, accessed and shared.
That might involve classification, access and sharing controls, content inspection, DLP, retention or other protection mechanisms. The right approach depends on the information, the risk and how people need to work with it.
Where Microsoft 365 is in use, Microsoft Purview can form part of that implementation. Our Microsoft Defender and Zscaler expertise allows controls to extend across endpoints, cloud applications and secure access where required.
Controls are tested against legitimate working practices and refined before wider enforcement.
We first establish what needs protecting and why, then determine the technology and controls required.
When To Review Information Governance
Confidential information is spread across multiple platforms.
Ownership of sensitive information is unclear as teams, roles and systems change.
AI adoption is raising questions about what information stays within the enterprise and what can leave it.
Collaboration environments have grown without consistent governance.
External collaboration needs clearer sharing rules.
Confidential information is spread across multiple platforms.
You Don't Need to Govern Everything.
Start With What Matters Most.
You do not need to begin with an organisation-wide governance programme.
Start with the information, platform or working practice that concerns you most.
We can help establish what needs governing, who needs to be involved, which controls are appropriate and how to introduce them without making everyday work unnecessarily difficult.