How do we know our business data is actually protected?
- Aug 17
- 4 min read
Most businesses would say their data is protected.
They have Microsoft 365. They use passwords and multi-factor authentication. They may have security policies, antivirus software and external certifications in place.
But there is a more difficult question:
Could you clearly show who can access your business data today?
Not who should have access according to a policy written two years ago. Not who had access when Microsoft 365 was first configured.
Who can access it now?
Business data rarely sits in one place

Client information, financial records, contracts and internal documents may be spread across:
SharePoint
OneDrive
Microsoft Teams
Email
Shared folders
Company laptops
Personal phones and tablets
External platforms and applications
This makes modern working more flexible, but it also creates more routes into company information.
A document may begin in a controlled SharePoint library, then be downloaded to a laptop, shared through Teams, opened on a personal phone or sent to an external contact.
Each step can introduce another permission, user, device or application that needs to be understood.
Permissions build up over time
Access is rarely created all at once.
It develops gradually as:
New employees join
Existing employees change roles
Contractors support specific projects
External advisers are invited into shared folders
Suppliers are given temporary access
Teams create new document libraries
Staff leave the organisation
The problem is that access is often added quickly but reviewed less frequently.
Someone may retain access that was appropriate for a previous role but is no longer required. A supplier may still be connected to a folder after its work has finished. An old account may remain active without a clear owner.
Microsoft recommends applying the principle of least privilege, meaning users and applications should only receive the access required to perform their work. The same principle applies to administrator permissions, where limited roles should be used instead of unrestricted Global Administrator access wherever possible.
The question is not whether every historic permission represents an immediate incident.
It is whether the business knows those permissions exist and has consciously decided they are still necessary.
External access needs particular attention
Sharing information with clients, consultants and suppliers is a normal part of running a professional services firm.
The risk appears when the organisation loses visibility over:
Which external users have access
What information they can see
Whether access has an expiry date
Whether files can be downloaded
Whether a shared link can be forwarded
Who is responsible for reviewing that access
External sharing should support the way the business works without creating permanent, uncontrolled routes into sensitive information.
Administrator access increases the potential impact
Administrator accounts are necessary, but they also have greater power over systems, users and data.
They may be able to:
Add or remove users
Reset passwords
Change security settings
Access important administrative information
Create new permissions
Disable existing controls
This is why administrator access should be limited, protected and reviewed regularly. Microsoft continues to recommend minimising the number of users with Global Administrator access and assigning the least privileged role needed for each task.
Businesses should understand who has privileged access, why they have it and whether it still matches their current responsibilities.
Personal devices create another layer of access
Employees may check email from a personal phone, open a document from a home laptop or respond to Teams messages while travelling.
This may be entirely reasonable, but it still needs to be managed.
The business should understand:
Which personal devices are connecting
What company information they can access
Whether appropriate authentication is being used
Whether business data is separated from personal applications
Whether access can be restricted or revoked
What happens when a device is lost or replaced
Without this visibility, leadership may know that information is stored securely within Microsoft 365 but not understand what happens once that information is opened elsewhere.

Leadership needs evidence, not assumptions
A security policy explains what should happen.
A security review checks what is actually happening.
That distinction becomes important when a client, board member, insurer or external assessor asks for evidence.
Leadership should be able to answer questions such as:
Who has access to sensitive information?
How many people have administrator permissions?
Are former users and suppliers removed promptly?
Is multi-factor authentication being applied properly?
Can personal-device access be controlled?
Are systems patched and updated?
Have known vulnerabilities been identified?
Which security issues need attention first?
A confident answer should be based on current evidence rather than assumptions about how the systems were originally configured.
Start with a clear view of the exposure
The ISUMO Security Exposure Review helps businesses understand where their existing security set-up may be creating unnecessary exposure.
The review can examine:
Microsoft 365 permissions and access
Global Administrator and other privileged roles
SharePoint and document-library permissions
Multi-factor authentication
Personal-device and remote access
BYOD policies
Vulnerability scanning
Patch and update processes
General readiness for Cyber Essentials or other security reviews
The client receives:
An executive summary
An overall security health rating
High, medium and low-priority findings
Immediate quick wins
Prioritised recommendations
A 30, 60 and 90-day improvement plan
A quote for ISUMO to help address the issues identified
The review does not issue Cyber Essentials, Cyber Essentials Plus or ISO accreditation, and it cannot guarantee that an organisation will pass an external assessment.
It gives the business something equally important: a clear view of where it stands and what needs fixing first.
If you are unsure who can access your company data or whether your existing controls are working properly, speak to ISUMO about a Security Exposure Review.



Comments