What the service covers

The sequence never changes: locate the data, restrict access, close the exits, watch for breaches. Skip the first step and the rest loses its point.

Talk it through with us

Classification

Information is labelled by value, for instance public, internal and confidential. Otherwise you end up guarding everything equally, which does not work.

Device encryption

BitLocker on laptops and encrypted USB sticks. A lost encrypted laptop is a nuisance, an unencrypted one is a breach that may have to be reported.

Removable media

Approved USB devices only, a log of connections and a complete block in teams handling sensitive information.

Email and sharing

Rules for attachments leaving the company, external sharing in OneDrive and SharePoint, and automatic encryption of emails containing CPR numbers.

DLP rules

Sensitivity labels and DLP policies in Microsoft Purview or an equivalent, written around your classification.

Incidents

A procedure and reporting on what was caught and how it was handled.

How we deliver it

We start with rules and permissions and bring in the specialist tooling afterwards.

01

Shortlist

We identify the small share of your data that is truly critical: customer lists, pricing agreements, drawings and HR records.

02

Cheap measures

Laptop encryption, USB limits in sensitive departments and a clear-out of old sharing links.

03

Observation

DLP rules run for a month without blocking, so we can see how data really moves.

04

Enforcement

Blocking is switched on only once false positives are down to a sensible level.

An unencrypted laptop left on a train is still the most common way data goes missing. Yet BitLocker is built into Windows and can be enforced centrally through Intune at no extra cost, with the recovery key stored in Entra ID. Security does not come cheaper than that.

Common questions

Turn the question round: what would hurt you if it reached a competitor or appeared online? The list is usually short: customer data, contract terms, product development and HR information.

Not necessarily. With Microsoft 365 Business Premium or E3/E5 you already have a good share of DLP and sensitivity labelling in the licence. A separate product makes sense when the data is highly valuable and you need detailed evidence.

Keep work and private apart. Allow mail and business systems only from managed devices or through Intune app protection, which stops copying into personal apps. A blanket ban on private devices is rarely respected.

DLP looks for patterns such as CPR or card numbers, not at the content of individual conversations. Staff must still be told about the controls, and that forms part of the documentation we help you prepare.

Protect the data that matters

Tell us which information is critical to you. We will suggest measures from simple to advanced, with a cost estimate.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.