By: Mbulelo Nyosi
Implementing information protection in an organisation can be a daunting task. It requires a clear understanding of privacy, security, and usability concerns across the board, and this can often delay data security projects or, worse, frustrate user adoption.
Nedscaper recommends employing a proactive yet secure method of self-service labels, where they view the Information Protection Sensitivity Labels as more than just technology that runs it, but for the visual identification it provides and the ease at which it allows users to take accountability and drives a culture of good governance around sensitive information sharing. Sensitivity labels are best utilised when the organisation understands them as a feature that is owned by business, and supported and kept up-to-date by the IT Security Admins.
Clear Visual Cues & Security Awareness
Sensitivity Labels provide a visible indicator at both the file, email, and workspace level, helping users recognize the sensitivity of the data they’re handling. Beyond classification, this fosters a culture of accountability and ensures security measures align with privacy and regulatory requirements.
Designed for Self-Service, Without Overburdening Users
Labels should be descriptive yet self-explanatory, reducing reliance on IT administrators for clarification. A well-structured and clear framework follows the recommended four-label approach for M365 files, emails, and containers:
- Highly Confidential: Most critical information that should only be shared with named recipients.
- Confidential: Information that is core to organisational goals – on a need-to-know context.
- General: Primarily internal communications and way-of-work, information we should keep within the organisation.
- Public / Private*: (depending on use case) – This is information that has minimal to no impact on the business, and used for Public-focused communications.
In some cases, there’s a benefit of adding a “Private” classification when users share their personal information, depending on fair usage.
These labels are not just names—they come with clear descriptions that support technological and compliance policy implementations, ensuring a consistent approach beyond security settings. Users understand what’s expected, and IT teams know exactly how to enforce the right security controls.
Enabling Governance & Secure Collaboration for Workspaces
Sensitivity Labels don’t just protect individual files; they extend to workspaces like Teams and SharePoint sites, enabling:
- Privacy Levels that are clear and intuitive
- External Sharing Policies that prevent unintended access
- Guidance on when and how data can be shared outside the organization
- Conditional Access enforcement for identity and device security
With automated enforcement, Sensitivity Labels provide governance-by-default, enhancing compliance and security while keeping productivity intact.
Conclusion
In conclusion, implementing Sensitivity Labels within an organisation is a strategic move towards fostering a culture of accountability and enhancing data security. By providing clear visual cues and enabling self-service labelling, organisations can ensure that their data protection measures are both effective and user-friendly. This approach not only supports compliance with privacy and regulatory requirements but also empowers users to take ownership of their data, ultimately driving better governance and secure collaboration.
To follow more of Mbulelo’s blogs, reach out to him on LinkedIn.