As a leader, you have observed that sharing sensitive data without clear rules, such as quotes with margins attached via Outlook, is a common practice within the team. You have also noticed that some team members were placing client data in certain Teams channels that are open to the entire department. You also know that there are colleagues who copy and paste confidential information into external tools to work faster.
But there is a gap between knowing it and having management’s support to act. This is often where things get stuck. This is precisely the role of the “business case“ template we created to help you present a case to senior management to help you better govern the sharing of sensitive data in Microsoft 365.
This situation affects you directly. Every time a sensitive file circulates without oversight, you are the one carrying the risk. You spend time monitoring what should be structured, correcting errors that could have been avoided, and managing situations that prevent you from focusing on what your role as a leader truly requires. And the colleagues around you are experiencing the same thing: they work without clear guidelines and make sharing decisions without knowing if it is the right way to do things.
If you haven’t yet read What is the role of a manager in protecting sensitive information, take the time to read it before continuing with this article. It explains how to observe and analyze the information circulating within the team, define rules with the IT department, and implement effective communication until good habits take hold.
Governing the sharing of sensitive data is one of the challenges many managers face. However, this issue is often part of a broader set of problems related to the use of Microsoft 365 within teams.
Depending on the situation, these challenges may also affect:
- document management and information organization
- team communication and collaboration
- poorly defined roles and responsibilities
- lack of governance regarding AI usage
- inefficient processes and ways of working
- underutilization of Microsoft 365 and digital tools
To better understand how these issues fit together, we recommend starting with our feature on Microsoft 365 optimization for team leaders.
Management must see the risks as you see them
Management looks at overall results and, from their perspective, the situation is under control because contracts are coming in and clients are being served. What they do not measure is the risk accumulating in the sharing behaviors you have already observed daily.
According to the Ponemon Institute, 56% of security incidents related to insiders are caused by negligence, not malicious intent. And according to the IBM Cost of a Data Breach Report 2025, each piece of intellectual property data exposed during an incident costs the company an average of $245 CAD. A single quote sent to the wrong person, and a client sees the margins or a competitor obtains the pricing strategy.
For management to understand what you are observing, you must translate your findings into terms they use: financial impact, reputational risk, costs of an incident that could have been avoided. Not an emotional observation, but a factual case.
What a solid case must contain to convince management to govern sensitive data sharing
A case presented to management must answer five questions, clearly and directly.
1. Which sharing behaviors pose a risk in your team? Name concrete situations and be precise. “We aren’t careful enough” is not sufficient. “Three colleagues on the team send quotes with margins as email attachments instead of using a protected SharePoint link” is a finding that management can understand.
2. What is the current impact? Translate risks into concrete consequences. A client seeing margins they should never have seen is a lost negotiating advantage. Client data copied into an external artificial intelligence tool is information leaving the environment without any control. According to CybSafe, 38% of employees admit to sharing sensitive data in AI tools without their employer’s knowledge. This is a figure that speaks to any General Manager.
3. What is the proposed solution? The goal is to define clear rules for sharing sensitive information daily, in collaboration with the IT department. The tools are already in place in Microsoft 365: SharePoint for sharing with permissions, Teams with private channels for confidential discussions, Microsoft Purview to classify sensitive documents. No new technological investment. What is missing are usage rules and a team leader to champion them.
4. What is the recommended pilot project? A pilot project is the best way to manage a change in behavior without disrupting operations. You start small, measure what works, and adjust before expanding. It is also an ultra-effective way to convince management because concrete results over 4 to 6 weeks speak louder than a theoretical PowerPoint plan. For example, governing the sharing of quotes in the sales department, or clarifying the rules for sharing financial data in accounting. You choose the behavior that has the most visible risk and affects the most colleagues.
5. What results do you expect to observe? Be realistic and do not promise zero risk. Instead, promise a measurable improvement. For example, that 100% of quotes are shared via a protected SharePoint link instead of attachments, that no confidential data ends up in an open Teams channel, and that every new person receives the sharing rules on their first day.
If you wish to learn more about the subject, feel free to consult the article: 5 key steps to developing an IT protection strategy tailored to your SME.
These five answers are exactly what our optimization request template allows you to structure. A ready-to-fill document that organizes your case so that management can evaluate it quickly.
Start with a single behavior to prove it works
Choosing the right behavior for the pilot is crucial. Focus on something that meets three criteria.
- Frequent. It happens at least every week, ideally every day. For example, the way quotes are sent to clients.
- Visible. Several people are affected and the consequences are easy to observe. For example, pricing data in a Teams channel that the entire department can see.
- Measurable. You can note where you are before starting and compare after 4 to 6 weeks. For example, the number of sensitive files sent by email per week.
To strengthen the case before presenting it, a Microsoft 365 audit like the one offered by Grav-ITI can provide an external perspective on the diagnosis. The audit evaluates data governance, access management, and sharing practices, and generates a clear indicator called the Grav-ITI Secure Score, which allows you to see the environment’s security level at a glance. The report is delivered in one week with a prioritized action plan. This is the kind of supporting evidence that adds weight to a case presented to management.
Once the pilot is launched, measure what changes: the number of files sent as attachments instead of protected links, confidential discussions that still end up in open channels. This data will fuel the next case, because a successful first pilot is the best argument for what follows.
Obtaining your boss’s support to better govern the sharing of sensitive data
Management needs facts, a plan, and a clear request. Here is the type of phrasing that works.
“We have identified that sensitive information is circulating in our team without clear rules. Quotes with margins are being sent by email instead of protected links. Client data is ending up in Microsoft Teams channels accessible to the entire department. According to IBM, each piece of intellectual property data exposed during an incident costs the company an average of $245. I propose defining clear sharing rules with the IT department, using the tools we already have in Microsoft 365. We will start with a single type of information over 4 to 6 weeks. No new investment. At the end of the pilot, we will measure the results and decide whether to expand the approach.”
It is direct, factual, and it is a case that any General Manager can evaluate in five minutes.
To govern the sharing of sensitive data in Microsoft 365 and turn it into a true asset for the company, the first step is to clearly understand the current situation.
That is why we have prepared a self-diagnostic that allows you to identify where your team stands today, what the main risks related to sharing sensitive information are, and what initial improvements can be considered.
Once this profile is established, you can use our “business case” template to organize your findings and present management with a structured approach, including a realistic pilot project to structure AI usage.
👉 Start with the self-diagnostic, then use the business case template
Structuring this approach with Grav-ITI
Observing that certain data is circulating without clear governance is often the starting point. But transforming these findings into concrete rules that last over time requires more than just good intentions.
In an SME, this type of change affects both the team’s work habits and how the Microsoft 365 environment is used daily.
Grav-ITI supports team leaders and management who wish to clarify these practices and implement a simple framework that colleagues can apply in their work.
Concretely, the approach consists of:
- identifying sharing behaviors that pose a real risk
- defining simple rules for using Microsoft 365 tools
- clarifying how certain information should circulate within the team
- testing these rules with a pilot project before expanding them
In many situations, a Microsoft 365 audit also helps to objectify what you are already observing. The audit analyzes data governance, access management, and sharing practices to produce a clear indicator called the Grav-ITI Secure Score, accompanied by a prioritized action plan.
If you would like to discuss this, let’s schedule a 30-minute call to discuss your situation. The conversation is without obligation and can help you identify the next steps to better govern the sharing of sensitive data in your Microsoft 365 environment.
The inefficiency of work processes in Microsoft 365 is one of the major issues faced by
Protecting confidential data within a team is one of the daily challenges faced by SME managers. If you want to explore other issues hindering your team’s performance, our full article on Microsoft 365 optimization for team leaders gives you a comprehensive overview.