Skip to main content
  • 5 minutes of reading

In most SMEs, sharing sensitive information is considered the responsibility of the IT department, which consists of one or two people. These colleagues manage access, updates, permissions, the Microsoft 365 environment, and daily technical support. It’s essential work that we tend to take for granted because we don’t always see them. But between what these individuals implement and how your team shares sensitive information daily, there’s a gap that no one covers.

Protecting confidential data within a team is one of the daily challenges faced by SME managers. If you want to explore other issues that hinder your team’s performance, our comprehensive guide on optimizing Microsoft 365 for team leaders provides an overview.

According to Ponemon Institute, 56% of internal security incidents related to individuals are caused by negligence, not malicious intent. Busy colleagues, without clear rules, who do things as quickly as they know how. Before looking for how to correct the situation, it’s important to clearly see what’s happening.

Your team takes the shortest path. Often without realizing it.

When there are no clear rules on how confidential data circulates within a team, each person does what’s simplest. In an SME, protecting sensitive information is not solely an IT responsibility. It also falls to the manager who oversees how their team uses tools daily.

  • A member of your team sends a submission with margins and prices via Outlook instead of sharing a SharePoint link with permissions. It’s done in 30 seconds. But once the email is sent, you no longer have any control over what happens to the file. It can be transferred, copied, opened on a personal device. And you’ll probably never know.
  • Account numbers, payroll data, or client names with amounts end up in Teams channels accessible to the entire department. Not out of malice. Out of habit.
  • Someone copies and pastes client data into an external artificial intelligence tool to write an email faster. The information leaves your environment without anyone knowing.

Microsoft 365 includes tools to manage all of this. SharePoint allows you to share a link with precise permissions. Microsoft Purview allows you to classify a document as confidential and automatically restrict its sharing. But no one on your team uses them because no one has told them it’s the rule. Email is faster, more familiar. And when no one says anything, the shortcut becomes the norm. M365 tools like SharePoint or Microsoft Purview only protect sensitive information if usage rules are defined. Without clear guidance, even the best security tools become ineffective.

Colleagues on your team use tools you don’t know about

According to CybSafe, 38% of employed individuals admit to sharing sensitive information in artificial intelligence tools without their employer knowing. And it’s not limited to artificial intelligence. Someone sends a file to their personal email to work from home. Another uses a free file-sharing tool because it’s simpler than going through SharePoint.

These are not irresponsible colleagues. These are colleagues who lack clear rules on what they can and cannot do with company information. So they do what is most efficient for them. And when trust between colleagues relies on the idea that everyone is careful, but no one knows exactly what to be careful about, the team dynamic silently erodes.

Errors happen when your colleagues are in a hurry

According to a study by Zivver conducted among 2,000 employed individuals, 33% have already sent the wrong attachment via email, and 32% have sent an email to the wrong person. These errors primarily occur when people are rushed (54%) or stressed (40%).

In an SME, a single error of this type can expose client data, commercial agreements, or financial information. It’s a client who loses trust. It’s a partner who sees margins they should never have seen. And it’s you, as the team leader, who has to manage the consequences of behavior that no one had regulated.

If reading this makes you think your team needs clearer rules, our article on concrete solutions explains how to implement them with your IT department.

Each new person reproduces the same habits

When someone new joins your team, they observe how others work and do the same. If they see everyone sending sensitive files via email, they will do the same. If they see client data openly discussed in a general Teams channel, they will think it’s normal.

There’s nothing written that says, “here’s how we protect confidential information on our team.” The result is that habits are passed from person to person, and the problem grows with each new arrival. The conversation about rules never happens among colleagues because no one knows it’s their responsibility to initiate it. And the longer this conversation is delayed, the harder it becomes to change what has become the norm.

It’s not just the IT department’s job

The IT department does its part. Access is configured, permissions are in place, and protection tools are available in the environment. But it cannot know how each person in each team shares sensitive information daily. It cannot see that a team leader sends margins via email or that a Teams channel contains payroll data. These are behaviors that occur in your department’s daily routine, not in the administration console.

Manager hesitating between their team and the IT department regarding responsibility for sharing sensitive information in Microsoft 365

Part of the responsibility falls to the team manager. Not to become a security expert, but to define clear rules within their team and work with the IT department to ensure everyone knows what can be shared, with whom, and through which channel. When both do their part, information is protected. When only one does, there’s a gap. In SMEs, sensitive information security only works when technology and team management collaborate. One never replaces the other.

No one told you it was your responsibility too

If you recognize yourself in the above, that’s normal. Most department directors and team leaders have never explicitly been given this responsibility. They were given tools, access to Microsoft 365, and it was assumed someone else would take care of the rest.

Your team is not negligent. It’s not about blame. What’s missing are clear rules on how confidential information circulates, and a person responsible for upholding them daily.

Seeing the problem is already the beginning

Now that you see what’s happening, the question becomes concrete. How do you regain control over how your team protects its confidential data, working with your IT department instead of leaving everything on their shoulders?

In our next article, we explain how to observe how your team shares sensitive information, how to define clear rules with your IT department, and how to ensure these rules endure over time.

If you want to explore other daily challenges faced by team leaders, our comprehensive guide on optimizing Microsoft 365 for leaders provides a global overview.

.

Newsletter

Recevez des conseils adaptés aux PME pour naviguer avec confiance dans un monde numérique en évolution.

This field is for validation purposes and should be left unchanged.
Terms of acceptance(Required)

Similar posts

Illustration of a multi-layered IT protection, represented by a central sphere surrounded by several interconnected layers, symbolizing multi-level defense.
Blog

Strengthen your SME’s cybersecurity with a multi-layered approach

Cyber threats are a reality that evolves faster than we do. If you’re here, you already know that ignoring this problem means leaving the door...

An SME team actively collaborates on optimizing Microsoft 365 usage around an informal and warm work table. A manager plans the digital transition on her tablet while a colleague presents a structured flow diagram on his computer screen to maximize efficiency. The atmosphere is engaged and focused on collective performance thanks to digital tools that are finally mastered and profitable.
Blog

How to turn Microsoft 365 usage into a business priority?

You know your team isn’t using Microsoft 365 to its full potential and everything that entails. If you haven’t yet read the article Adopting Microsoft...

Interconnected digital infrastructure illustrating the complexity of modern IT environments and the importance of multi-layered cybersecurity to protect critical SME data.
Blog

Improve critical data security with these cybersecurity essentials

Data security is part of a cybersecurity strategy. It is a top priority for businesses worldwide. Business leaders want to ensure they are taking the...