Skip to content
Back to case studies

Large conglomerate

Insider data exfiltration, found in Microsoft 365.

Sector

Large conglomerate, multiple business units

Services

Managed SOC, Microsoft 365 monitoring, proactive threat hunting

What we found

Insider data exfiltration

A conglomerate operating across several business units had moved to Microsoft 365 without extending security monitoring to cover it. The exposure was twofold: compromised accounts, and data leaving the organisation through legitimate file-sharing functionality.

We brought M365 authentication logs and file activity into the SOC, with detection tuned to the behaviours that matter in that environment. File access, modification and renaming are tracked with full user and timestamp attribution. Internal and external sharing are distinguished, so a document shared with a colleague and a document shared with an outside party are treated differently.

What we did

What we did

Monitoring identified compromised accounts through anomalous access patterns and unusual login locations. It also identified data leakage by employees, including file movement consistent with an individual preparing to leave the organisation.

Both were found before material loss occurred. Neither would have been visible without monitoring extended into the collaboration platform itself.

Bring enterprise-grade defence to your organisation.

Our team is here to answer your questions and show how a fully managed SOC keeps your organisation protected around the clock, from continuous monitoring to threat hunting and machine-speed response.