Microsoft 365 In-Motion

INFORMATION RISK & EXPOSURE REPORT

Securing ACME LTD's Information Assets: Visibility, Movement, and Risk.

An executive summary on Microsoft 365 data security — uncovering hidden exposures, tracking sensitive data movement, and highlighting prioritized actions to protect your business.

📅  Reporting period — June 2026 🏢  Customer — ACME LTD
3.9K
High-severity incidents
168
Top risky users flagged
104
Mass-download incidents
ACME LTD · M365 IN-MOTION · JUNE 2026

SECTION 01 — KEY FINDINGS

Critical Risk Signals Demanding Attention

Cognni's automated monitoring continuously analyzes activities across ACME LTD's Microsoft 365 environment. Cognni has isolated three critical patterns that require immediate visibility.

02 / 12
3.9K

High Severity Incidents

Policy — Justification requests sent to users who generate high-severity information risks.
168

Top Risky Users

Policy — Weekly email alerts to your organization's highest-risk users.
104

Mass Download Incidents

Policy — Triggers compliance-oriented email alerts.

High-severity incidents are deeply tied to Financial and HR records, indicating a potential vulnerability in core business operations. Meanwhile, mass-download anomalies are heavily concentrated in Business and HR, signaling a need for stricter access controls.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 2 of 12

KEY FINDING 01 — DETAIL

High-Severity Threats by Information Category

A breakdown of the 3.9K most critical security events, revealing which data categories are most exposed to high-risk activities.

03 / 12
Financial
1.0K
Legal
269
HR
1.2K
Governance
61
Business
1.3K
High Medium Low share of total flagged events, by category
Business
6,982 events
Legal
6,016 events
HR
4,749 events
Financial
2,077 events
Governance
782 events

Financial data presents the most acute risk profile for ACME LTD: over half (50.4%) of all flagged financial events are high-severity. By contrast, Legal data shows high volume but significantly lower severity (4.5%), indicating that security controls should immediately prioritize financial workflows.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 3 of 12

KEY FINDING 03 — DETAIL

Mass-Download Anomalies: Identifying Potential Data Exfiltration

Anomalous burst downloads executed by a single user within a single category during the reporting timeframe.

04 / 12
Financial
11
Legal
14
HR
33
Governance
4
Business
42
Business
42
HR
33
Legal
14
Financial
11
Governance
4

Business and HR records account for 72% of all mass-download events. This concentrated activity highlights a specific exfiltration risk to organizational and employee data, strongly suggesting a need to evaluate download thresholds in these departments.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 4 of 12

SECTION 02 — WHAT IS YOUR INFORMATION

The Landscape of ACME LTD's Sensitive Data

A comprehensive mapping of all 324.7K sensitive and regulated records actively managed across your Microsoft 365 ecosystem.

05 / 12
Personal
159.4K
HR
68.5K
Business
54.3K
Legal
24.3K
Financial
13.6K
Governance
4.6K

Personal Identifiable Information (PII) dominates the landscape, comprising 49% of all mapped records. Protecting this immense volume of personal data is critical for compliance and maintaining the trust of ACME LTD's stakeholders.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 5 of 12

SECTION 02 — DETAIL

Deep Dive: The Composition of Your Sensitive Data

A granular view of the specific document types and records driving data volume, enabling targeted data governance.

06 / 12

Financial

June 2026
  • Salaries Information4,041
  • Accounting2,894
  • Financial Reports & Planning1,732
  • Banks1,708
  • Employee Costs & Expenditure881
+8 more

Legal

June 2026
  • Legal Letters9,379
  • Agreements9,050
  • Compliance & Assessment Forms4,267
  • Consent Forms1,194
  • Incorporation Documents308
+7 more

HR

June 2026
  • Recruitment41,408
  • Employee Information11,444
  • Diplomas6,452
  • HR Forms1,384
  • Discipline679
+6 more

Governance

June 2026
  • Regulatory Compliance3,577
  • Compliance & Assessment Reports198
  • Board Meetings & Resolutions175
  • Audit Reports158
  • Committee Agendas146
+8 more

Business

June 2026
  • Customers & Suppliers28,674
  • Tenders & Bids10,214
  • Guides6,260
  • Operational Specifics2,800
  • Project Information1,593
+19 more
ACME LTD · M365 IN-MOTION · JUNE 2026
Page 6 of 12

SECTION 02 — PERSONAL INFORMATION

Regulated Data: PII, PCI, and PFI Exposure

Visibility into highly regulated personal identifiers and their severity levels, revealing where compliance risks are most concentrated.

07 / 12

Contains PFI

Out of 17 total events
H 0M 4L 13

Contains PII

Out of 6,421 total events
H 941M 577L 4,903

Contains PCI

Out of 24 total events
H 12M 0L 12

Financial

Out of 220 total events
H 200M 11L 9

HR

Out of 1,896 total events
H 1,000M 400L 496

Legal

Out of 108 total events
H 33M 20L 55

Personal

Out of 2,037 total events
H 240M 64L 1,733

When Personal Information intersects with Financial records, the risk skyrockets: 91% (200 out of 220) of these overlapping events are classified as high-severity. This represents a critical compliance flashpoint for ACME LTD.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 7 of 12

SECTION 03 — WHERE INFORMATION LIVES

Data Distribution Across Microsoft 365 Applications

Pinpointing exactly where ACME LTD's sensitive information is stored to guide effective access management and policy enforcement.

08 / 12
4 apps in scope
38.8%OneDrive
30.9%SharePoint
29.0%Exchange
1.3%Teams

With 70% of sensitive data residing in OneDrive and SharePoint, traditional email-focused security is insufficient. Securing personal drives and collaborative document libraries must be the primary focus for reducing exposure.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 8 of 12

SECTION 04 — INFORMATION IN MOTION

Information In Motion: Tracking Data Sharing and Exposure

Mapping the flow of sensitive data to identify risky sharing behaviors and external exposure points.

09 / 12
Shared by Employees 1K1K2K7682K3K
Shared to Employees 2K2K3K2K3K4K
Shared to Organizations 3427202K1112K2K
Shared to External Contacts 2K3K11K69911K16K
Fewer eventsMore events

External sharing is the most significant vector for data exposure at ACME LTD. With massive volumes of Personal (16K), HR (11K), and Business (11K) records leaving the organization, establishing strict external sharing boundaries is paramount.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 9 of 12

SECTION 04 — DETAIL

Exposure Spotlight: Tracking PDF Document Flow

A focused analysis of PDF sharing behaviors, revealing how easily readable and portable document formats are distributed.

Filtered · PDF files · June 2026
10 / 12

Shared By Employees

Financial690
Legal37
HR231
Governance21
Business510
Personal261

Shared To Employees

Financial1,315
Legal111
HR716
Governance89
Business1,755
Personal400

Shared To External Contacts

Financial1,010
Legal24
HR189
Governance19
Business537
Personal209

Shared To Organizations

Financial136
Legal10
HR48
Governance8
Business140
Personal33
ACME LTD · M365 IN-MOTION · JUNE 2026
Page 10 of 12

SECTION 05 — RECOMMENDATIONS

Strategic Recommendations for ACME LTD

Five high-impact, data-driven security actions to significantly reduce information risk and improve compliance.

11 / 12
1

Automate justification requests for high-risk users

Activate automated justification policies for high-severity activities. By prompting users in real-time, ACME LTD can immediately mitigate the 3.9K critical incidents detected during the reporting timeframe while fostering a security-conscious culture.

2

Apply Microsoft Purview labels at the source

Implement automated Microsoft Purview Information Protection (MPIP) labeling at the point of creation, prioritizing Legal and Governance data to ensure foundational data protection and compliance.

3

Review the 104 mass-download incidents

Conduct an immediate review of the 104 mass-download incidents. Focus first on Business and HR departments (72% of alerts) to rule out internal data hoarding or potential exfiltration threats.

4

Tighten sharing to external contacts

Restrict sensitive external sharing by implementing targeted Data Loss Prevention (DLP) rules. This directly addresses ACME LTD's largest exposure vulnerability: the massive outflow of Personal, HR, and Business records.

5

Check in on the 168 flagged users

Initiate a manager-level review for the 168 top risky users. Combining Cognni's weekly automated alerts with human oversight ensures targeted intervention and prevents repeated risky behaviors.

ACME LTD · M365 IN-MOTION · JUNE 2026
Page 11 of 12

SUMMARY

June 2026 Security Posture at a Glance.

Visibility brings control. With 324.7K records mapped and critical exposure points identified, ACME LTD is positioned to take decisive, data-driven action to secure its Microsoft 365 environment.

3.9K
High-severity incidents
168
Top risky users flagged
104
Mass-download incidents
Personal · 159.4KHR · 68.5KBusiness · 54.3KLegal · 24.3KFinancial · 13.6KGovernance · 4.6K
ACME LTD · M365 IN-MOTION · JUNE 2026
Page 12 of 12
01 / 12