What We Found Inside a South African Public Entity’s M365 Environment — And What It Means for Yours

Modern data security dashboard showing a map of South Africa with data connection points, M365 and SharePoint visual elements, navy and blue cyber security interface

Subject line: 94% of Confidential Files Were Publicly Accessible — An Inside Look at a Real M365 Data Governance Assessment

The Data Landscape

The assessment revealed that the organisation had limited visibility into what information it held, where it was stored, and who could access it. While Microsoft 365 was broadly adopted, governance controls had not kept pace with the volume of data being created, shared, and stored across collaboration platforms.

This is not a story about a breach. No data was stolen. No system was compromised.

It is a story about something far more common — and arguably more dangerous: the quiet accumulation of invisible risk.

The Numbers That Matter

Dataproof’s Data Security Posture Assessment (DSPA), powered by Forcepoint AI-Mesh Classification Technology, scanned approximately 60 TB of data across a Schedule 3A public entity’s M365 environment. Here is what we found:

MetricFinding
Total files scanned1.8 million
Data volume60 TB
Confidential files publicly accessible94%
External sharing links created34,000+
Dormant accounts with active M365 access270+
SharePoint sites inactive 6+ months46%
Stale data untouched 3+ years693,000 files
Annual storage wasteR400,000+

The organisation could not produce an Information Register within a reasonable timeframe. In the event of a POPIA compliance review, an audit response would have been manual, incomplete, and resource-intensive — exposing the organisation to significant regulatory risk.

The Real Cost: Compliance Exposure + Operational Waste

The findings revealed governance gaps that carry both compliance risk and operational cost. Understanding the problem is only useful when you also understand the business case for fixing it.

Governance Risks Identified

  • Unstructured information sprawl — Files stored across SharePoint sites, Teams channels, and OneDrive with no classification, retention, or disposal policy
  • Stale accounts with active access — 270+ former employees, contractors, and service accounts retaining M365 access, including mailbox and SharePoint permissions
  • External sharing unmanaged — 34,000+ anonymous guest links, including documents containing personal information, financial records, and employee data
  • No data classification deployed — Zero use of Microsoft Purview sensitivity labels, retention labels, or DLP policies
  • POPIA compliance gap — No demonstrable Information Register, no lawful processing records, no data subject access request workflow

Business Impact

  • Audit readiness — Any POPIA, AGSA, or internal audit response would rely on manual data gathering
  • Storage cost waste — R400,000+ per year in avoidable storage from stale sites and orphaned data
  • Operational drag — Staff averaged 15–20 minutes per document search
  • Digital transformation risk — Leadership lacked assurance that the M365 investment was governed to standard

You Can’t Protect What You Can’t See

The bottom line: the organisation was carrying significant compliance exposure and operational cost — not because of a security incident, but simply because information governance had not kept pace with M365 adoption.

“You can’t protect what you can’t see. The platform you trust is the platform they target — and if you cannot see what data you hold, who can access it, and where it lives, you cannot protect it.”

This is a pattern we see consistently across public-sector M365 environments. The platform you trust is the platform they target — and if you cannot see what data you hold, who can access it, and where it lives, you cannot protect it.

The Remediation Roadmap

Based on the assessment, Dataproof developed a phased remediation programme:

Phase 1 — 0–30 Days (Quick Wins)

  • Disable dormant accounts
  • Remove highest-exposure anonymous sharing links
  • Deploy baseline sensitivity labels
  • Establish information asset inventory

Phase 2 — 30–90 Days (Governance Foundation)

  • Implement retention schedules and disposal policies
  • Clean up SharePoint site sprawl
  • Deploy Microsoft Purview DLP and auto-labelling
  • User awareness programme

Phase 3 — 90+ Days (Managed State)

  • Ongoing monitoring and reporting
  • Quarterly executive governance reports
  • Automated classification and policy enforcement
  • Continuous POPIA alignment
  • Managed DSPM service

See What Your Environment Looks Like

Every organisation’s data posture is different — but the patterns are surprisingly consistent.

Want to know what your M365 environment looks like? Dataproof conducts a confidential, no-obligation DSPA scan — and presents the findings in a comparable anonymised brief. Contact us to arrange your assessment.


See Your Data Posture — Before the Regulator Does

Dataproof’s DSPA Programme — powered by Forcepoint AI-Mesh Classification Technology — gives PFMA entities a complete picture of their M365 data security posture in just 15 business days. Fixed scope. Executive-ready report. POPIA-mapped. From R20,000 ex VAT.

Call us: 011 032 7700 or email sales@dataproof.co.za


This article is based on anonymised findings from a Data Security Posture Assessment conducted at a Schedule 3A public entity. All identifying details have been removed. The data is representative of real M365 governance assessments performed by Dataproof Communications.

Assessment type: Data Security Posture Assessment (DSPA) | Environment: Microsoft 365 (SharePoint Online, OneDrive, Teams, Exchange Online) | Entity type: Schedule 3A public institution, ±500 employees | Data volume: ~60 TB | Period: Q2 2026