You cannot secure the data you cannot see.
A Data Risk Assessment is a paid, one-time evaluation of your data estate. In four to six weeks it discovers what sensitive information you hold, classifies it, scores the risk around it, and hands your leadership an evidenced picture of exposure with a roadmap to act on. It is deliberately an evaluation, not a remediation program: the point is to replace an estimate with a number your board can act on.
Why organisations run one
Every new privacy and AI obligation starts with a question most organisations cannot answer with evidence: where is our sensitive data, and who can reach it. The blocker is rarely will or budget. It is visibility. Assistants like Copilot have sharpened the same question, because anything an employee can open, the tools acting on their behalf can now find and summarise. An assessment answers it in weeks, with findings specific enough to fund the work that follows.
What the assessment covers
Discovery and classification
- A scan of up to ten terabytes across the sources you choose
- Cloud and on-premises, structured and unstructured alike
- Classification that reads the content in context, without a rulebook of patterns to maintain
- Priority categories agreed up front: personal, payment, health and intellectual property
Risk and exposure
- Risk scored on permissions, sharing, location and activity
- Files open to far more people than intended, and accounts that should no longer have access
- Duplicate and stale records carrying risk and cost for no benefit
- A review of what assistants such as Copilot can reach today
What you receive
- An executive report: quantified exposure, findings by category and severity, and the cost of doing nothing
- A programmatic roadmap from the scan to a governed state, phase by phase
- Baseline measures your team can report against as remediation runs
- Thirty days of access to the assessment platform after the readout
What it is not
The assessment does not remediate, enforce or monitor. It changes nothing in your estate. That separation is deliberate: you get an independent picture first, then decide what to fix, in what order, and who does it. Remediation is a separate engagement, and you are free to run it with your own team.
How it runs
Six meetings, booked up front
- Scoping: sources, categories and timeline, with every stakeholder in the room
- Kickoff: access granted, configuration done, first scan started
- Assistant readiness workshop: what Copilot and similar tools can reach
- Technical results: findings reviewed with your team, risk report shared
- Executive sync: the roadmap and the priorities, with leadership
- Handover: what happens next, and who owns it
What we need from you
- A named technical contact who can grant access to the sources
- Agreement on which sources are in scope, kept tight for the first scan
- Administrative access confirmed before kickoff, the single most common delay
- Clear ownership of the data, so findings land with the people who can act
Get the overview
Leave your details and we’ll email you the download link.
Frequently asked questions
No, and that is the point. It discovers, classifies and scores; it does not change your data. You are left with evidence and a plan, free to remediate with us, with your own team, or not at all.
Most first assessments are deliberately scoped tighter than the limit. A sprawling first scan slows the readout and blurs the story, so we start with the sources that carry the most sensitive data and expand from there.
No. The assessment is a paid engagement in its own right and ends with a report and a roadmap you own. Where continuing tooling makes sense we will say so and show you why, and you remain free to license it yourself or not at all.
A penetration test asks whether someone can get in. An audit asks whether a control exists. This asks what sensitive data you hold, where it sits, who can reach it today, and what an assistant would surface, then scores that exposure so it can be prioritised.
You do. The report is yours and is treated as confidential. We agree at scoping who inside your organisation receives it, and we brief that group directly at the executive sync.