The Problem
Most organisations vastly underestimate the volume and sensitivity of data they hold. Personal data in marketing databases that should have been deleted 3 years ago. Payment card numbers in log files. Health information in unencrypted SharePoint folders. Intellectual property on personal Dropbox accounts. These are not edge cases โ they are findings from our last 50 data discovery engagements. You cannot protect what you cannot see.
Our Approach
Data Discovery & Scanning
Automated scanning across all connected repositories โ SharePoint, OneDrive, Google Drive, S3, databases, file servers, email โ identifying where sensitive data actually lives, not where you think it does.
Classification Framework Design
We design a classification framework appropriate for your industry, regulatory environment, and risk appetite โ typically 3โ5 levels from Public to Restricted โ with clear labelling rules and handling requirements for each level.
Classification Implementation
We implement classification labels in Microsoft Purview, Google Workspace, or other platforms โ with auto-classification for known sensitive data types and guided classification for human review of ambiguous content.
DLP Policy Implementation
Data Loss Prevention policies configured across email, web, endpoint, and cloud applications โ preventing sensitive data from leaving controlled environments. Tuned to minimise false positives without sacrificing protection.
Retention Schedule Implementation
We implement data retention schedules โ automated deletion of data that has exceeded its retention period, legal hold capabilities for regulatory requirements, and audit trails for compliance demonstration.
What You Receive
Data Discovery Report
Complete map of sensitive data locations across all in-scope systems with volume, type, and risk analysis.
Classification Framework
Documented classification scheme with handling requirements, labelling standards, and implementation guidelines.
Classification Implementation
Labels deployed in your environment with auto-classification rules and user training for manual classification.
DLP Policies
Configured DLP policies across your email, endpoint, cloud, and web channels with incident management workflow.
Retention Schedule
Implemented retention policies with automated deletion, legal hold, and audit trail capabilities.
Data Governance Dashboard
Ongoing view of classification coverage, DLP incidents, retention compliance, and data risk posture.
Security Maturity Model
Data governance maturity spans from complete opacity about what data you hold to comprehensive, automated governance that ensures data is used appropriately throughout its lifecycle.
Where you are
No data classification. Data stored wherever convenient. No retention policies. DLP absent. Data inventory non-existent. Sensitive data discovered reactively โ after a breach or regulator inquiry.
Where you are
Basic classification scheme defined but not implemented in tools. Manual labelling attempted but inconsistent. Some retention policies documented. DLP in basic email mode only. Data discovery limited to known systems.
Where you are
Classification implemented in productivity tools (Microsoft/Google). Auto-classification for structured data types. DLP across email and cloud storage. Retention schedule documented and partially automated. Data governance officer appointed.
Where you are
Comprehensive data discovery across all systems including shadow IT. Classification coverage >80% of data estate. DLP incidents tracked and trended. Retention compliance measured quarterly. Data risk quantified in financial terms.
Where you are
Data governance fully automated. Real-time sensitive data detection and remediation. Classification drives access control decisions automatically. Data minimisation principles embedded in product development. Data governance feeds privacy and compliance programmes seamlessly.
ACE MATES assessment โ Not sure where you sit? Our free 90-minute threat briefing includes a maturity assessment across all security domains.
How We've Helped
An internal audit found that patient records were being stored in personal OneDrive accounts and shared via personal email. The client needed to discover the full extent of the problem and implement controls within 60 days before a scheduled regulatory inspection.
ACE MATES deployed Microsoft Purview across the entire M365 tenant and connected on-premises file servers. Discovery found 2.3 million files containing patient data โ 47,000 in unapproved personal storage. We implemented classification labels, DLP policies blocking transfer of patient data to personal accounts, and mandatory retention policies. The regulatory inspection found zero findings on data governance.
Transparent Pricing
We publish indicative pricing because you deserve to know the ballpark before a single call.
- Automated discovery across in-scope systems
- Sensitive data type identification
- Risk-based findings report
- Classification framework recommendation
- DLP gap assessment
- Remediation roadmap
- Everything in Assessment
- Classification framework design
- Label implementation (Microsoft/Google)
- Auto-classification configuration
- DLP policy implementation
- Retention schedule implementation
- Staff training programme
- 3 months support
- Continuous discovery & classification
- DLP incident management
- Monthly governance report
- Policy tuning & updates
- Quarterly data risk review
- New system onboarding
- Regulatory change monitoring
Why ACE MATES
Discovery-First Philosophy
We start by finding your data where it actually is โ not where your documentation says it is. Discovery often reveals 3โ5x more sensitive data than organisations expect, changing the entire risk picture.
Platform-Agnostic Expertise
We implement governance in Microsoft Purview, Google Workspace DLP, Symantec DLP, Forcepoint, and Varonis. We recommend the right platform for your environment, not the one we are partnered with.
Regulatory Context
Our data governance programmes are designed to satisfy GDPR Article 5 (data minimisation, storage limitation), NIS2 data handling requirements, and industry-specific regulations (HIPAA, PCI DSS) simultaneously.
Business-Friendly Implementation
DLP that blocks too much destroys productivity and gets disabled. We tune policies collaboratively with business units to find controls that protect without creating frustration โ and that actually stay enabled.