Cloud platforms, hybrid forms of collaboration and generative AI are transforming the way organisations use and share information. This necessitates adjustments: data classification and Data Loss Prevention (DLP) provide transparency regarding sensitive information and enable protective measures that are tailored to the actual risk. In the ongoing development of information security, however, various aspects must be taken into account.
Why companies should rethink their approach to information security
Customer information, contractual documents, financial data and intellectual property are processed across different locations, devices and cloud services. Staff collaborate with external partners and use applications outside traditional security perimeters.
In many organisations, business-critical information is also scattered across legacy storage systems, cloud services, emails and end devices. Security requirements, responsibilities and access rights are not consistently documented.
Organisations should therefore be able to identify which information requires particular protection, who is authorised to access it and which uses pose a security or compliance risk. To achieve this, they require transparency regarding sensitive content, clearly defined responsibilities and appropriate access rights. These decisions affect information security, data protection and compliance as well as IT and business departments.
Combining data classification and DLP in a targeted manner
Data classification categorises information according to its sensitivity and business value. A practical model combines a small number of clear protection levels with unambiguous criteria and examples drawn from relevant business processes. The specialist departments assess the value of the information. Information security, data protection and IT departments use this to derive labelling schemes, access rules and encryption requirements.
Data Loss Prevention uses this as a basis to control the use of sensitive information, for example in emails, collaboration services, cloud storage and on end devices.
Context is key: what information is being transmitted, by whom, via which channel and to which recipient? Depending on the risk, activities can be logged, employees warned, justifications requested or processes blocked.
Working together, classification and DLP enable targeted controls for sensitive information and reduce unnecessary interference with workflows.
Data protection lays the foundations for the secure use of AI
When Microsoft 365 Copilot is introduced, outdated sharing arrangements, as well as documents that are inadequately protected or inconsistently classified, can more quickly find their way into the usage context. Copilot does not create the access problem, but it does make existing weaknesses more apparent. Generative AI can find, consolidate and analyse information in a short space of time. This makes transparent authorisations, labelling and accountability all the more important.
External AI services also create new data flows. Organisations should define which content may be processed and how risky inputs are to be identified. Classification and DLP provide technical safeguards for this and support transparent AI governance.
Five challenges in implementation
A safety model that works in day-to-day working life
Too many classification levels lead to uncertainty, whilst a model that is too broad fails to capture important differences. Our experts therefore develop the protection classes in collaboration with your specialist departments, based on real documents and usage scenarios. Clear criteria and tests with selected user groups ensure that the classification model can be applied clearly and unambiguously in a variety of application scenarios.
Clear accountability for rules and exceptions
Following a technically successful roll-out, it remains unclear who decides on new confidentiality classifications, approves exceptions, assesses misclassifications or bears the residual risk. A governance and operational model clearly assigns decisions, approvals and escalations. Regular reviews ensure that the guidelines remain up to date.
Striking a balance between security and business operations
HR sends personal data; the sales department works with customers and partners; legal departments exchange confidential documents with external parties. Overly restrictive controls lead to workarounds, whilst overly lax rules increase security and compliance risks. We therefore focus on specific data flows rather than abstract prohibitions. Depending on the risk, we combine guidance, justifications, authorisations or blocks. Necessary exceptions are justified on a technical basis, assessed in terms of risk and documented in a transparent manner.
Making protective measures easy to understand
Unclear confidentiality classifications and unexpected blockages make the system difficult to use. Clear descriptions and context-sensitive guidance provide direction. Feedback from real-world use is incorporated into guidelines, support processes and the further development of the solution. This enables recurring issues to be addressed in a targeted manner.
Refining DLP rules step by step
Detection patterns that are too broad trigger false alarms, whilst rules that are too narrow fail to detect relevant incidents. New or amended policies are usually tested initially without being enforced. Only after an assessment of hits, false alarms and impacts are alerts or blocks issued.
A safety model that works in day-to-day working life
Too many classification levels lead to uncertainty, whilst a model that is too broad fails to capture important differences. Our experts therefore develop the protection classes in collaboration with your specialist departments, based on real documents and usage scenarios. Clear criteria and tests with selected user groups ensure that the classification model can be applied clearly and unambiguously in a variety of application scenarios.
Clear accountability for rules and exceptions
Following a technically successful roll-out, it remains unclear who decides on new confidentiality classifications, approves exceptions, assesses misclassifications or bears the residual risk. A governance and operational model clearly assigns decisions, approvals and escalations. Regular reviews ensure that the guidelines remain up to date.
Striking a balance between security and business operations
HR sends personal data; the sales department works with customers and partners; legal departments exchange confidential documents with external parties. Overly restrictive controls lead to workarounds, whilst overly lax rules increase security and compliance risks. We therefore focus on specific data flows rather than abstract prohibitions. Depending on the risk, we combine guidance, justifications, authorisations or blocks. Necessary exceptions are justified on a technical basis, assessed in terms of risk and documented in a transparent manner.
Making protective measures easy to understand
Unclear confidentiality classifications and unexpected blockages make the system difficult to use. Clear descriptions and context-sensitive guidance provide direction. Feedback from real-world use is incorporated into guidelines, support processes and the further development of the solution. This enables recurring issues to be addressed in a targeted manner.
Refining DLP rules step by step
Detection patterns that are too broad trigger false alarms, whilst rules that are too narrow fail to detect relevant incidents. New or amended policies are usually tested initially without being enforced. Only after an assessment of hits, false alarms and impacts are alerts or blocks issued.
Information security as an ongoing process: How we support your business
Information security is not a one-off technical implementation. Security models, controls and responsibilities must be regularly adapted to new business processes, technologies and risks. We support organisations in establishing information security as a permanent organisational capability and in aligning security and compliance requirements with the organisation’s digital evolution. To this end, we combine business requirements, clear responsibilities and technical controls into a practical approach. Based on prioritised business risks and relevant data flows, we develop protection models, DLP controls, and governance and operational processes, and support their implementation – for example, using Microsoft Purview.
More KPMG Insights
Your contacts
Markus Limbach
Partner, Consulting - Cyber Security & Resilience
KPMG AG Wirtschaftsprüfungsgesellschaft
- Item 1
- Item 2