In most SMEs, sharing sensitive information is considered the responsibility of the IT department, which consists of one or two people. These colleagues manage access, updates, permissions, the Microsoft 365 environment, and daily technical support. It’s essential work that we tend to take for granted because we don’t always see them. But between what these individuals implement and how your team shares sensitive information daily, there’s a gap that no one covers.
Protecting confidential data within a team is one of the daily challenges faced by SME managers. If you want to explore other issues that hinder your team’s performance, our comprehensive guide on optimizing Microsoft 365 for team leaders provides an overview.
According to Ponemon Institute, 56% of internal security incidents related to individuals are caused by negligence, not malicious intent. Busy colleagues, without clear rules, who do things as quickly as they know how. Before looking for how to correct the situation, it’s important to clearly see what’s happening.
Your team takes the shortest path. Often without realizing it.
When there are no clear rules on how confidential data circulates within a team, each person does what’s simplest. In an SME, protecting sensitive information is not solely an IT responsibility. It also falls to the manager who oversees how their team uses tools daily.
- A member of your team sends a submission with margins and prices via Outlook instead of sharing a SharePoint link with permissions. It’s done in 30 seconds. But once the email is sent, you no longer have any control over what happens to the file. It can be transferred, copied, opened on a personal device. And you’ll probably never know.
- Account numbers, payroll data, or client names with amounts end up in Teams channels accessible to the entire department. Not out of malice. Out of habit.
- Someone copies and pastes client data into an external artificial intelligence tool to write an email faster. The information leaves your environment without anyone knowing.
Microsoft 365 includes tools to manage all of this. SharePoint allows you to share a link with precise permissions. Microsoft Purview allows you to classify a document as confidential and automatically restrict its sharing. But no one on your team uses them because no one has told them it’s the rule. Email is faster, more familiar. And when no one says anything, the shortcut becomes the norm. M365 tools like SharePoint or Microsoft Purview only protect sensitive information if usage rules are defined. Without clear guidance, even the best security tools become ineffective.
Colleagues on your team use tools you don’t know about
According to CybSafe, 38% of employed individuals admit to sharing sensitive information in artificial intelligence tools without their employer knowing. And it’s not limited to artificial intelligence. Someone sends a file to their personal email to work from home. Another uses a free file-sharing tool because it’s simpler than going through SharePoint.
These are not irresponsible colleagues. These are colleagues who lack clear rules on what they can and cannot do with company information. So they do what is most efficient for them. And when trust between colleagues relies on the idea that everyone is careful, but no one knows exactly what to be careful about, the team dynamic silently erodes.
Errors happen when your colleagues are in a hurry
According to a study by Zivver conducted among 2,000 employed individuals, 33% have already sent the wrong attachment via email, and 32% have sent an email to the wrong person. These errors primarily occur when people are rushed (54%) or stressed (40%).
In an SME, a single error of this type can expose client data, commercial agreements, or financial information. It’s a client who loses trust. It’s a partner who sees margins they should never have seen. And it’s you, as the team leader, who has to manage the consequences of behavior that no one had regulated.
If reading this makes you think your team needs clearer rules, our article on concrete solutions explains how to implement them with your IT department.
Each new person reproduces the same habits
When someone new joins your team, they observe how others work and do the same. If they see everyone sending sensitive files via email, they will do the same. If they see client data openly discussed in a general Teams channel, they will think it’s normal.
There’s nothing written that says, “here’s how we protect confidential information on our team.” The result is that habits are passed from person to person, and the problem grows with each new arrival. The conversation about rules never happens among colleagues because no one knows it’s their responsibility to initiate it. And the longer this conversation is delayed, the harder it becomes to change what has become the norm.
It’s not just the IT department’s job
The IT department does its part. Access is configured, permissions are in place, and protection tools are available in the environment. But it cannot know how each person in each team shares sensitive information daily. It cannot see that a team leader sends margins via email or that a Teams channel contains payroll data. These are behaviors that occur in your department’s daily routine, not in the administration console.

Part of the responsibility falls to the team manager. Not to become a security expert, but to define clear rules within their team and work with the IT department to ensure everyone knows what can be shared, with whom, and through which channel. When both do their part, information is protected. When only one does, there’s a gap. In SMEs, sensitive information security only works when technology and team management collaborate. One never replaces the other.
No one told you it was your responsibility too
If you recognize yourself in the above, that’s normal. Most department directors and team leaders have never explicitly been given this responsibility. They were given tools, access to Microsoft 365, and it was assumed someone else would take care of the rest.
Your team is not negligent. It’s not about blame. What’s missing are clear rules on how confidential information circulates, and a person responsible for upholding them daily.
Seeing the problem is already the beginning
Now that you see what’s happening, the question becomes concrete. How do you regain control over how your team protects its confidential data, working with your IT department instead of leaving everything on their shoulders?
In our next article, we explain how to observe how your team shares sensitive information, how to define clear rules with your IT department, and how to ensure these rules endure over time.
If you want to explore other daily challenges faced by team leaders, our comprehensive guide on optimizing Microsoft 365 for leaders provides a global overview.
.