Understand risky internal activity
Proportionate signals and a fair investigation path — not an unread case queue.

Microsoft Purview Insider Risk Management can surface patterns that may point to data theft, inappropriate access or careless handling. Enabling every indicator is not a programme. The work is deciding which scenarios matter, who reviews alerts, and how a case moves to HR or legal without becoming a fishing expedition.
Ghani Governance configures the product and the governance around it. The DPO / privacy-counsel overlay is part of the design, not a slide at the end. Product reference: Microsoft’s Insider Risk documentation.
Departure-window data movement, unusual downloads, repeated access to a protected store — each policy has a written purpose.
Scope, indicators, triggering events and thresholds aimed at usable cases, not volume.
Who opens a case, what they may see, and how it escalates or closes.
Fairness, retention of investigative material, and a path that can be explained if challenged.
Alert quality reviewed before the population grows.
| Service | Planning range | Typical mid-point |
|---|---|---|
| Insider Risk readiness review | £1,500–£3,000 | £2,250 |
| Pilot policy implementation | £3,000–£6,000 | £4,500 |
| Multi-scenario implementation | £6,000–£12,000 | £9,000 |
Indicative only. Scope, licensing, stakeholders and existing controls change the figure. Not a quote.
Behaviours and data types that justify monitoring.
Licensing, audit, permissions, related Purview controls.
A controlled group or one scenario first.
Case quality and false positives before expansion.
Ownership, review cadence, change control.
No. DLP looks at content leaving a channel. Insider Risk looks at patterns of user activity that may indicate theft, leakage or policy abuse. They share data; they are not substitutes.
We define the scenarios that justify monitoring, set indicators against those scenarios, and agree who may open a case. HR and the DPO are in that conversation. Broad “watch everyone” configurations are how these programmes lose legitimacy.
A scoping conversation about what you need to protect, what is already configured, and what must not break.