Microsoft shipped something last week that says a lot about where client data actually goes.
On September 24 they made a new protection generally available: it can recognize a sensitive file as it moves off your network and stop it before it lands in an AI tool nobody approved.
Read that again. The thing worth defending against isn't only the hacker in the hoodie. It's an advisor pasting a client's statement into a free chatbot to get a faster summary.
That's how client data leaves a wealth management firm on an ordinary Tuesday. Not a breach. An attachment forwarded to a personal email address. A folder still set to "anyone with the link" from an onboarding two years ago. A departed assistant's OneDrive nobody ever closed out.
None of it sets off an alarm. It surfaces eighteen months later, when a client asks why their account number turned up somewhere it shouldn't have. That is a call you cannot un-make.
Three things I would check this quarter: who can actually reach your client files, which sharing links are still open to anyone, and which AI tools your team is already using.
Worth doing before your next cyber renewal, when the questions get specific.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email