Where Your Data Actually Lives (And How to Protect It)

Your data lives in M365, SaaS, endpoints, personal accounts, and now AI tools. Map it, classify it, then protect it where it actually is.

Illustration of scattered data nodes connected by dashed lines to a central gradient vault with a padlock

Ask a leadership team where the company's data lives and you'll hear "the server" or "the cloud." Ask the network and you'll get a longer answer: Microsoft 365, a dozen SaaS platforms, laptops, phones, personal email threads, a departing employee's Dropbox, and — newest on the list — whatever AI tools people pasted it into. You can't protect data you've mislocated. So start with the map.

Draw the real map

A useful data inventory answers four questions per system: what lives there, how sensitive it is, who can reach it, and what happens if it leaks or disappears. Most companies discover the same surprises: customer data in more places than any contract anticipated, twenty years of files with permissions nobody has reviewed since migration, and former employees' accounts that still exist because offboarding meant "disabled the email."

Classify before you control

Not all data deserves the same defense, and pretending it does guarantees the important stuff is underprotected while the trivial stuff is over-locked. A workable classification for a growing company is four tiers: public, internal, confidential, and regulated/customer-owned. Every protection decision downstream — who can access it, where it may travel, whether it can enter an AI tool — keys off that tier. This is the same classification your AI policy needs, which is not a coincidence: it's one data program.

Least privilege, actually practiced

The single highest-leverage control is boring: people can only reach what their job requires. In practice that means permission reviews on your file storage (the "Everyone" group is doing more damage than any hacker), role-based access in your line-of-business systems, admin rights held by admins only, and offboarding that removes access everywhere on day one — including the SaaS platforms IT didn't buy. Identity work and data work are the same work; we've written about why.

Backups that answer the real question

The question is not "do we have backups." It's "when did we last restore from them, and how long did it take." Modern practice: the 3-2-1 pattern (three copies, two media, one off-site), immutability so ransomware can't encrypt the backups too, coverage for your SaaS data — Microsoft 365 is not backed up just because it's Microsoft's — and a scheduled restore test with the result written down. That written result, incidentally, is now a standard insurance questionnaire item.

The new leak path

Data protection in 2026 includes governing where employees paste things. Consumer AI tools with training rights over their inputs are a data-loss channel your DLP never imagined. The fix isn't prohibition — it's a sanctioned stack with clear rules per data tier, which is where data protection and AI governance converge. Our security practice runs the full sequence — map, classify, control, test — as fixed-scope work. Start with the map; it's the step everything else depends on.