This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.
Bunker Snapshot - Data Loss Prevention (DLP) at a glance
Estimated reading time 🕒 45 seconds
Everything you need to know about this security control in under 60 seconds.
Business impact
🔴 Security improvement
🔴 Risk reduction
🟡 Operational impact
High
Very High
Medium
Related Controls
Next Steps
Identify the types of sensitive information your charity stores, configure Data Loss Prevention policies and test how Microsoft 365 detects and protects confidential data.
Charity Insight
Many charities don’t experience data breaches because of sophisticated hackers—they occur through accidental sharing of documents, misdirected emails or incorrectly configured permissions. Data Loss Prevention helps prevent these common mistakes before sensitive information leaves your organisation.
What it does
Prevents sensitive information from being accidentally or deliberately shared outside your organisation by monitoring and controlling how data is stored, accessed and shared across Microsoft 365.
Why it matters
Protects donor information, financial records, employee data and other sensitive information, helping reduce the risk of data breaches and supporting compliance with UK data protection requirements.
Time to implement
⏱ 3–6 hours
(Depending on the number of policies and sensitivity labels required.)
Who it affects
All Microsoft 365 users who create, access or share sensitive information through Exchange Online, SharePoint, OneDrive and Microsoft Teams.
Implementation difficulty
Licensing
Basic data protection capabilities are available with selected Microsoft 365 licences. Advanced Data Loss Prevention features require Microsoft 365 Business Premium, Microsoft 365 E5 or Microsoft Purview licensing, depending on the functionality needed.
