top of page

How do we know our business data is actually protected?

  • Aug 17
  • 4 min read

Most businesses would say their data is protected.


They have Microsoft 365. They use passwords and multi-factor authentication. They may have security policies, antivirus software and external certifications in place.


But there is a more difficult question:


Could you clearly show who can access your business data today?


Not who should have access according to a policy written two years ago. Not who had access when Microsoft 365 was first configured.


Who can access it now?


Business data rarely sits in one place



Client information, financial records, contracts and internal documents may be spread across:


  • SharePoint

  • OneDrive

  • Microsoft Teams

  • Email

  • Shared folders

  • Company laptops

  • Personal phones and tablets

  • External platforms and applications


This makes modern working more flexible, but it also creates more routes into company information.


A document may begin in a controlled SharePoint library, then be downloaded to a laptop, shared through Teams, opened on a personal phone or sent to an external contact.


Each step can introduce another permission, user, device or application that needs to be understood.


Permissions build up over time


Access is rarely created all at once.


It develops gradually as:


  • New employees join

  • Existing employees change roles

  • Contractors support specific projects

  • External advisers are invited into shared folders

  • Suppliers are given temporary access

  • Teams create new document libraries

  • Staff leave the organisation


The problem is that access is often added quickly but reviewed less frequently.

Someone may retain access that was appropriate for a previous role but is no longer required. A supplier may still be connected to a folder after its work has finished. An old account may remain active without a clear owner.


Microsoft recommends applying the principle of least privilege, meaning users and applications should only receive the access required to perform their work. The same principle applies to administrator permissions, where limited roles should be used instead of unrestricted Global Administrator access wherever possible.


The question is not whether every historic permission represents an immediate incident.

It is whether the business knows those permissions exist and has consciously decided they are still necessary.


External access needs particular attention


Sharing information with clients, consultants and suppliers is a normal part of running a professional services firm.


The risk appears when the organisation loses visibility over:


  • Which external users have access

  • What information they can see

  • Whether access has an expiry date

  • Whether files can be downloaded

  • Whether a shared link can be forwarded

  • Who is responsible for reviewing that access


External sharing should support the way the business works without creating permanent, uncontrolled routes into sensitive information.


Administrator access increases the potential impact


Administrator accounts are necessary, but they also have greater power over systems, users and data.


They may be able to:


  • Add or remove users

  • Reset passwords

  • Change security settings

  • Access important administrative information

  • Create new permissions

  • Disable existing controls


This is why administrator access should be limited, protected and reviewed regularly. Microsoft continues to recommend minimising the number of users with Global Administrator access and assigning the least privileged role needed for each task.

Businesses should understand who has privileged access, why they have it and whether it still matches their current responsibilities.


Personal devices create another layer of access


Employees may check email from a personal phone, open a document from a home laptop or respond to Teams messages while travelling.


This may be entirely reasonable, but it still needs to be managed.


The business should understand:


  • Which personal devices are connecting

  • What company information they can access

  • Whether appropriate authentication is being used

  • Whether business data is separated from personal applications

  • Whether access can be restricted or revoked

  • What happens when a device is lost or replaced


Without this visibility, leadership may know that information is stored securely within Microsoft 365 but not understand what happens once that information is opened elsewhere.



Leadership needs evidence, not assumptions


A security policy explains what should happen.


A security review checks what is actually happening.


That distinction becomes important when a client, board member, insurer or external assessor asks for evidence.


Leadership should be able to answer questions such as:


  • Who has access to sensitive information?

  • How many people have administrator permissions?

  • Are former users and suppliers removed promptly?

  • Is multi-factor authentication being applied properly?

  • Can personal-device access be controlled?

  • Are systems patched and updated?

  • Have known vulnerabilities been identified?

  • Which security issues need attention first?


A confident answer should be based on current evidence rather than assumptions about how the systems were originally configured.


Start with a clear view of the exposure


The ISUMO Security Exposure Review helps businesses understand where their existing security set-up may be creating unnecessary exposure.


The review can examine:


  • Microsoft 365 permissions and access

  • Global Administrator and other privileged roles

  • SharePoint and document-library permissions

  • Multi-factor authentication

  • Personal-device and remote access

  • BYOD policies

  • Vulnerability scanning

  • Patch and update processes

  • General readiness for Cyber Essentials or other security reviews


The client receives:


  • An executive summary

  • An overall security health rating

  • High, medium and low-priority findings

  • Immediate quick wins

  • Prioritised recommendations

  • A 30, 60 and 90-day improvement plan

  • A quote for ISUMO to help address the issues identified


The review does not issue Cyber Essentials, Cyber Essentials Plus or ISO accreditation, and it cannot guarantee that an organisation will pass an external assessment.


It gives the business something equally important: a clear view of where it stands and what needs fixing first.


If you are unsure who can access your company data or whether your existing controls are working properly, speak to ISUMO about a Security Exposure Review.


 
 
 

Comments


© 2026 ISUMO. All rights reserved 

Abstract technology background used in ISUMO page layout
27001 Accreditation Logo

Contact

20 – 22 Wenlock Road,
London, N1 7GU

We work with you to improve reliability, strengthen security and boost scalability. Your business gains better performance, lower costs and real peace of mind.
ISUMO LOGO White
phone icon
Pin Icon
Mail Icon
LinkedIn Icon

Join our mailing list

bottom of page