Kode-1
Playbook

Finding and securing sensitive data

For CISOs, security architects, and the platform owners who hold the keys

24 June 2026

Every organisation believes it knows where its sensitive data lives. Almost none do. The customer records are in the CRM — and in the export someone took for a migration in 2019, the spreadsheet finance keeps for reconciliation, the test environment that was refreshed from production, and the collaboration site nobody has opened since the project ended. Security architecture built on the official map protects the official copies. This playbook is about the rest. 1. The posture discipline Sensitive-data security is a loop, not a project: discover what exists, classify what it is, right-size who can reach it, watch how it is used, and feed what you learn back into the loop. Run once, it produces a report that is stale in a quarter. Run continuously, it produces posture — the state the APPs assume when they speak of reasonable steps, and CPS 234 assumes when it asks how information assets are protected commensurate with their criticality. 2. Discovery, honestly Start where the copies breed: file shares, collaboration platforms, object storage, mailboxes, and the analytics estate. Discovery that only scans the systems of record confirms what you already knew; discovery that scans where people actually work finds the unmanaged copies — and the point is the unmanaged copies. Expect the first pass to be uncomfortable. That discomfort is the finding. 3. Classification at scale Manual labelling does not scale to the volumes discovery surfaces, so let patterns and context do the first pass — identifiers, document shapes, source systems — and spend human judgement only where the automation is unsure. Precision matters more than coverage at the start: a small set of correctly-identified crown jewels beats a large set of maybes, because everything downstream — access, monitoring, response — keys off the classification being right. 4. Access right-sizing Over-permissioning is not an accident; it is the default state of any estate more than a few years old. Access accretes — projects end, roles change, nothing is revoked. Treat least privilege as an ongoing process with an owner: entitlement reviews driven by actual usage (who has access they never use), broad-groups-by-default replaced with scoped grants, and every sensitive dataset carrying an owner who answers one question on a cadence — who can reach this, and why? 5. Watching use, not just storage A dataset at rest with correct permissions can still be misused by an authorised account. Monitor the patterns that matter: unusual volumes, unusual destinations, access outside the shape of someone's role, dormant accounts waking up. The Essential Eight hardens the paths in; use-monitoring watches what happens after — and it is also where insider risk becomes visible while it is still small. 6. The AI multiplier Every copilot and model deployment turns your access debt into an exposure engine: these tools surface whatever the requesting account can reach, at conversational speed, with none of the friction that used to make over-permissioning survivable. Before connecting an assistant to the estate, run the loop hard on whatever it will index. The question is no longer only who can open this file — it is what can retrieve it, and repeat it, on that person's behalf. 7. The first 90 days Run discovery on the three environments where copies breed fastest. Classify the top tier only — the data whose loss triggers the NDB scheme or a prudential conversation. Right-size access on the ten worst findings; they will not be subtle. Stand up use-monitoring on the crown jewels. And schedule the second discovery pass before the first one is forgotten — the loop, not the report, is the deliverable. The uncomfortable truth of sensitive-data security is that the perimeter never failed; the copies did. Find them first, or someone else does.