TL;DR: Intentional data exfiltration over email remains difficult to detect, with KnowBe4 reporting that 94% of organisations have seen data loss and exfiltration in Microsoft 365 and 91% suffered significant fallout. Static DLP and audit-log review alone are not enough when users deliberately bypass safeguards, making behaviour-aware monitoring the practical control gap.
NHIMG editorial — based on content published by KnowBe4: CISO Strategy Guide on data exfiltration over email
By the numbers:
- 94% of organisations report experiencing data loss and exfiltration within their Microsoft 365 environment.
- 91% suffering significant fallout as a result.
- 94% of organizations rely solely on static email DLP rules.
Questions worth separating out
Q: What breaks when organisations rely on static DLP for email exfiltration detection?
A: Static DLP breaks when users intentionally adapt their behaviour to avoid fixed rules.
Q: Why does email exfiltration remain difficult to stop in Microsoft 365?
A: Microsoft 365 email is a trusted business channel, so malicious or policy-breaking activity can look normal.
Q: How should security teams measure whether DLP monitoring is actually working?
A: Measure DLP by outcomes, not alert volume.
Practitioner guidance
- Implement behaviour-based email detection Baseline normal send, forward, attachment, and recipient patterns in Microsoft 365, then alert on deviations that indicate deliberate data movement rather than routine communication.
- Review mailbox rule and forwarding abuse Monitor for newly created forwarding rules, external redirects, and suspicious inbox automation that can move messages outside organisational visibility before content inspection catches them.
- Use audit logs for investigation, not primary detection Correlate message events, mailbox changes, and login activity to validate suspected exfiltration, but do not rely on audit-log review as the main control.
What's in the full article
KnowBe4's full guide covers the operational detail this post intentionally leaves for the source:
- Tactics employees use to bypass internal safeguards and route sensitive information to personal email accounts
- Detection and monitoring approaches for Microsoft 365 email exfiltration beyond static DLP rules
- The operational limitations of audit-log review when investigating intentional data loss
- Behaviour-based controls practitioners can use to improve alerting and reduce detection latency
👉 Read KnowBe4's guide on detecting data exfiltration over email in Microsoft 365 →
Email exfiltration and DLP gaps: what security teams are missing?
Explore further
Static DLP is a control boundary, not a detection model. The article shows why content matching alone cannot keep pace with intentional rule-breaking, especially when users stay inside approved platforms while changing their behaviour. That means the real problem is not the absence of policy, but the gap between policy enforcement and human decision-making. Practitioners should treat static DLP as one layer inside a broader behavioural detection programme.
A question worth separating out:
Q: Who is accountable when a misdirected email exposes sensitive data?
A: Accountability usually spans the business owner, the data security team, and the control owner for email governance. Regulators and auditors will care less about intent than about whether the organisation had preventive controls, training, and monitoring appropriate to the sensitivity of the data. The key question is whether the control design was proportionate to the risk.
👉 Read our full editorial: Data exfiltration over email is outpacing static DLP controls