{"id":16646,"date":"2023-03-02T06:30:34","date_gmt":"2023-03-02T06:30:34","guid":{"rendered":"https:\/\/www.insentragroup.com\/au\/insights\/uncategorized\/microsoft-purview-protect-yourself-dont-become-a-data-breach-statistic\/"},"modified":"2024-10-25T03:02:42","modified_gmt":"2024-10-25T03:02:42","slug":"microsoft-purview-protect-yourself-dont-become-a-data-breach-statistic","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/fasttrack\/microsoft-purview-protect-yourself-dont-become-a-data-breach-statistic\/","title":{"rendered":"Microsoft Purview &#8211; Protect Yourself, Don&#8217;t Become a Data Breach Statistic"},"content":{"rendered":"\n<p>Hey folks! Pure Awesomeness (aka Hambik Matvosian) here and you\u2019re probably all wondering where the heck I\u2019ve been with my blogs. Well, between putting together the content for my monthly FastTrack Updates to trying to work out where the year went, I\u2019ve been busy beefing up my knowledge around Microsoft 365 Compliance\u2026wait\u2026sorry\u2026yes, they changed the name again. Let\u2019s try that again\u2026I\u2019ve been busy beefing up my knowledge around all things Microsoft Purview.&nbsp;<\/p>\n\n\n\n<p>Now, before I continue and pump a tonne of knowledge into your cerebrum, I need to ask this question\u2026have you been following my FastTrack Updates? If your answer is yes, perfect. Pass GO, collect your $200 and keep reading. If your answer was no, then we really need to talk. I mean, it\u2019s pretty much the most educational piece of content you\u2019ll find across YouTube, LinkedIn and Face\u2026Meta\u2026or whatever it\u2019s called now, so make sure you watch the videos and hit that Like and Subscribe button (do I sound like a content creator yet or what?)<\/p>\n\n\n\n<p>Now, down to business and why we\u2019re here today. But first, you know what you need to do:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Grab a cup of liquid gold (aka the Ristretto, Doppio or Mezzo Mezzo \u2013 see, this is why I\u2019ll never be a barista. I had to Google that last one)<\/li>\n\n\n\n<li>Like and share my previous blogs and FastTrack updates<\/li>\n\n\n\n<li>Subscribe to Insentra\u2019s YouTube channel (trust me, there\u2019s some great pieces of content on there)<\/li>\n<\/ul>\n\n\n\n<p>OK, formalities done, it\u2019s time to move onto discussing the topic of the day\u2026Microsoft Purview. Buckle up and here we go!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is Microsoft Purview?<\/h2>\n\n\n\n<p>Yes, Microsoft has done it again and changed the name of a product we\u2019ve been so used to for several years. Microsoft Purview combines the former Azure Purview and the Microsoft 365 Compliance Centre into one beast of a platform to provide you with a unified range of solutions around data governance and risk management.&nbsp;&nbsp;<\/p>\n\n\n\n<p>So, what does it bring to the table you ask?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Helps you gain visibility into assets across your entire data estate<\/li>\n\n\n\n<li>Enables easy access to all your data, security and risk solutions<\/li>\n\n\n\n<li>Helps safeguard and manage sensitive data across clouds, apps and endpoints<\/li>\n\n\n\n<li>Manages end-to-end data risks and regulatory compliance\u2026and finally<\/li>\n\n\n\n<li>Empowers your organisation to govern, protect and manage data in new, comprehensive ways<\/li>\n<\/ul>\n\n\n\n<p>You\u2019re probably reading this and thinking \u201cwe trust our users to do the right thing.\u201d Whilst this statement may be true, sometimes users don\u2019t even know they\u2019re putting the entire organisation at risk by sharing that one folder called Cat Memes to an external party, not realising they saved a document in that folder with passwords which they forgot to transfer to a password vault. This can very easily lead to a data breach.&nbsp;<\/p>\n\n\n\n<p>Here\u2019s a number that will rattle some bones \u2013 according to IBM\u2019s Cost of a Data Breach 2022 report, the cost of a data breach in 2022 averaged USD 4.35 million! So how can you avoid your organisation becoming a statistic in this report? Read on to find out what solutions are available!&nbsp;<\/p>\n\n\n\n<p>If you need a refill of your Mezzo Mezzo, now is the time.&nbsp;<\/p>\n\n\n\n<p>Refill done.&nbsp;<\/p>\n\n\n\n<p>Read on!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Compliance Manager<\/h2>\n\n\n\n<p>No, it\u2019s not the title of a new role that needs to open in your organisation. Although, if you already have a Compliance Manager in your team, then Compliance Manager in Microsoft Purview will most likely be their new best friend. It helps organisations manage their compliance requirements with greater ease and convenience. Compliance Manager can help take an inventory of data protection risks to managing the complexities of implementing controls, staying current with regulations and certifications and reporting to auditors. In other words, Compliance Manager will tell you what remediation steps are recommended to help reduce risk and will even provide you with an overall score across the tenant. Yep, that\u2019s right, another score to keep track of\u2026and you thought Secure Score, Identity Score and Exposure Score were enough.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Data Loss Prevention<\/h2>\n\n\n\n<p>We\u2019ll refer to this bad boy as DLP because you know, acronyms. What does DLP do I hear you ask? The policies that you create can help prevent sensitive information from leaving your organisation. So, what\u2019s classified as a sensitive information type? Oh, you know, tax file numbers, medical numbers etc so nothing too concerning if it landed in the wrong hands (said no one ever).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Information Protection<\/h2>\n\n\n\n<p>It\u2019s pretty much in the name\u2026protecting information. How is that done I hear you ask? Quite simply, using labels. Gone are the days where a simple stamp with the words \u201cConfidential\u201d marked across the printed document was enough to deter someone from passing that document onto a 3<sup>rd<\/sup> party. Now, with the evolution of the beast that is Microsoft 365 and the constant development of AI, organisations can now configure labels, assign them to policies and apply these labels to documents and emails automagically. I should make a note that the automagicness (yes, I made up a word) of applying the labels does require E5 license SKUs and the AI used is the good AI (not the one that took over Skynet and summoned Arnie to protect us all). However, manually applying the labels can be achieved with E3 licenses.&nbsp;<\/p>\n\n\n\n<p>By the way, 50 likes on this blog post and I\u2019ll submit a request to Oxford Dictionary to formally recognise the word \u201cautomagicness\u201d.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Also, check out my fellow crew member, Joe Cirillo\u2019s <a href=\"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/secure-workplace\/enhancing-microsoft-365s-information-security-governance\/?utm_source=twitter&amp;utm_medium=social-organic&amp;utm_campaign=m365-security-governance&amp;utm_content=blog&amp;utm_term=social-media\" target=\"_blank\" rel=\"noreferrer noopener\">blog<\/a> on DLP and Information Protection&nbsp;<\/p>\n\n\n\n<p>Keep reading!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Records Management<\/h2>\n\n\n\n<p>On to an important requirement for most organisations today. Cast your mind back to when retaining documents meant that organisations had cardboard boxes filled with hundred and hundreds of documents, stored in a vault\u2026in the same building! When an auditor came knocking, it meant rummaging through the boxes labelled \u201c<a href=\"https:\/\/www.canberratimes.com.au\/story\/6022018\/government-documents-containing-employee-details-found-in-sold-filing-cabinet\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">A \u2013 Box 1 of 24\u201d to try and find the documents requested.<\/a> Nowadays with the whole digital transformation idea, documents, or records, are all\u2026yes you guessed it\u2026digital. With E5 licenses, organisations can take advantage of the Records Management solution within Purview, which can provide some of the following capabilities:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Label content as a record<\/li>\n\n\n\n<li>Configure retention and deletion settings with retention labels<\/li>\n\n\n\n<li>Start different retention periods when an event occurs<\/li>\n\n\n\n<li>Export information about all disposed items&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Bonus tip just for my loyal readers and followers \u2013 you can activate a 90-day trial of Records Management from within Purview and test it out! OK, Microsoft has this tip published but what sort of blogger would I be if I didn\u2019t pass on this knowledge?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Insider Risk Management<\/h2>\n\n\n\n<p>Risks are everywhere and it\u2019s not always the external risks that organisations need to protect themselves from. Unfortunately, internal risks are also a possibility. Internal risks could refer to any of the following:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Leaks of sensitive data<\/li>\n\n\n\n<li>Confidentiality violations<\/li>\n\n\n\n<li>Intellectual property theft<\/li>\n\n\n\n<li>Fraud<\/li>\n\n\n\n<li>Insider trading&nbsp;<\/li>\n\n\n\n<li>Regulatory compliance violations&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>So how can organisations combat these risks? Insider Risk Management of course\u2026or IRM (yep more acronyms but don\u2019t get this acronym confused with Information Rights Management). Conversation for another day on why Microsoft has two different products with the same acronym.&nbsp;<\/p>\n\n\n\n<p>Insider Risk Management helps you quickly identify, triage and act on risk activity. Available with E5 licenses and hopefully a product you\u2019ll never need to use!&nbsp;<\/p>\n\n\n\n<p>For more information and helpful insights on insider threats, be sure to check out the Insider Threat Ultimate Guide.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">E-Discovery<\/h2>\n\n\n\n<p>Hopefully you\u2019ll never need to use this feature but if your organisation is dealing with a legal case and needs to produce the required data, eDiscovery is your friend, provided retention policies are turned on across the tenant. Now, don\u2019t get this confused with backups. Whilst eDiscovery is a way to gain access to data through retention policies, it\u2019s not designed to be a backup and restore solution. So, if your organisation is relying on eDiscovery and retention policies to fulfil RTO and RPO requirements, we need to talk!&nbsp;<\/p>\n\n\n\n<p>To provide you with some more information (because you know, what kind of awesome content creator\/blogger would I be if I didn\u2019t share such information), eDiscovery comes in two flavours: Standard and Premium and yep, you guessed it\u2026dependent on whether you have E3 or E5 licenses across the tenant (can\u2019t say you didn\u2019t see that one coming)&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Information Barriers<\/h2>\n\n\n\n<p>Pretty self-explanatory (kind of). Basically, information barriers <s>is<\/s>are a way to restrict two-way communication and collaboration between groups and users across Teams, SharePoint Online and OneDrive for Business. To expand on this, in the professional context, it\u2019s often used in highly regulated industries and help to avoid conflicts of interest and safeguard internal information between users and organisational areas. The simpler explanation \u2013 Information Barriers can prevent Simone in Marketing from sharing cat memes with Mark in Operations because she knows Mark doesn\u2019t like cats and can prevent Mark from responding back, causing conflict, resulting in you, the reader, referring back to the eDiscovery section of this masterpiece to determine what could be the end result.&nbsp;<\/p>\n\n\n\n<p>On to the last product! It\u2019s almost over\u2026I can hear the heartbreak\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Content Explorer<\/h2>\n\n\n\n<p>So, your organisation has a bunch of data across Exchange Online, SharePoint Online and OneDrive for Business. Now, you need to figure out whether any sensitive information resides across these platforms. Allow me to introduce you to content explorer. Content explorer shows a current snapshot of the items that have a sensitivity label, a retention label or have been classified as a sensitive information type in your organisation. Now, just want to make it clear \u2013 content explorer does not provide you a snapshot of what\u2019s being shared across the organisation, both internally and externally. That requires multiple different reports to be generated and analysed and not all from within Purview. But never fear, there is an easier way to obtain this level of information and visibility, but it does require you, my loyal reader, reaching out to me directly to discuss.&nbsp;<\/p>\n\n\n\n<p>There you have it folks! Another blog written by yours truly, all about the native capabilities that Purview can bring to the table to help stop your organisation from becoming a data breach statistic!&nbsp;<\/p>\n\n\n\n<p>Until next time, Pure Awesomeness signing off!<\/p>\n\n\n\n<p>If you&#8217;re interested in learning more about Microsoft Purview and how it can help your organisation manage data governance and risk management, <a href=\"https:\/\/www.insentragroup.com\/au\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">contact Insentra<\/a> today! Our team of experts can help you understand the capabilities of Purview and assist in implementing the solution for your business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Topics<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/fasttrack\/microsoft-purview-the-future-of-compliance-and-governance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview: The Future of Compliance and Governance<\/a><br>\n<a href=\"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/secure-workplace\/enhancing-microsoft-365s-information-security-governance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Enhancing Microsoft 365\u2019s Information Security Governance<\/a><br>\n<a href=\"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/cloud-and-modern-data-center\/why-you-need-microsoft-365-backup-solution-after-all\/\" target=\"_blank\" rel=\"noreferrer noopener\">Why You Need Microsoft 365 Backup Solution After All<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Secure your data and avoid being a data breach statistic with Microsoft Purview. Get protection and compliance features for your business today. <\/p>\n","protected":false},"author":52,"featured_media":16647,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[23],"tags":[],"class_list":["post-16646","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fasttrack","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/16646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/comments?post=16646"}],"version-history":[{"count":2,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/16646\/revisions"}],"predecessor-version":[{"id":16804,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/16646\/revisions\/16804"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media\/16647"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media?parent=16646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/categories?post=16646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/tags?post=16646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}