Case study · Data Centre / Financial Services clients · Stavanger, Norway
A Stavanger data centre operator serving regulated clients asked a simple question: where could data leak, and in what order should we fix it? ITSECOPS delivered a full DLP gap analysis and a prioritized Microsoft Purview roadmap.
The client
A Norwegian data centre and hosting operator whose financial-services and public-sector tenants were tightening contractual security demands.
The challenge
Data left the organization through email, endpoints, cloud storage and admin tooling — but nobody could say which channels were controlled, monitored, or wide open.
What we did
- Inventoried every egress channel: email, endpoints and removable media, SaaS and cloud storage, remote-access paths and privileged admin sessions.
- Assessed existing controls against a DLP maturity model and the operator’s client-contract obligations.
- Designed a Microsoft Purview implementation roadmap: sensitivity labels first, then policy-in-audit-mode, then enforcement — sequenced to avoid breaking legitimate workflows.
- Flagged insider-risk scenarios for privileged staff and proposed monitoring proportionate to Norwegian employment law.
Results
- Board-ready gap report with heat-mapped egress channels.
- A 12-month, three-phase DLP roadmap the operator could resource realistically.
- Immediate quick wins shipped during the engagement: external-sharing defaults and mail-flow rules.
FAQ
What does a DLP gap analysis include?
Egress-channel inventory, control assessment, data classification review and a sequenced remediation roadmap — typically 2–4 weeks of work.
Is Microsoft Purview enough, or do we need a third-party DLP?
For Microsoft-centric estates, Purview covers most channels well. Third-party tools earn their cost mainly for non-Microsoft SaaS sprawl and network-layer inspection.
Why start DLP in audit mode?
Enforcement without baseline data blocks legitimate business and burns goodwill. Audit mode shows real flows first, so enforcement lands without incident tickets.