TL;DR: Sixty-six percent of organisations have had email information barriers breached, with outcomes including operational stoppages, client churn, and regulatory penalties, according to KnowBe4. Static DLP leaves teams reacting after data is sent rather than enforcing separation before disclosure, which makes barrier design and policy governance the real control problem.
NHIMG editorial — based on content published by KnowBe4: CISO Guide: Prevent Email Information Barrier Breaches in Microsoft 365
By the numbers:
- 66% of organizations have had their email information barriers breached, resulting in major consequences like ceasing operations, client churn and regulatory penalties.
Questions worth separating out
Q: How should security teams enforce email information barriers without relying on static DLP alone?
A: Use send-time controls that combine classification, recipient context, and group permissions before delivery.
Q: Why do email information barriers fail even when DLP is in place?
A: They fail when the policy is reactive, the classifications are stale, or the underlying identity groups are too broad.
Q: How do teams know whether their barrier controls are actually working?
A: Look for the share of sensitive messages blocked before delivery, the number of user corrections triggered at send time, and the volume of exceptions tied to specific groups or classifications.
Practitioner guidance
- Map information barriers to identity ownership Assign explicit ownership for barrier rules, group membership, and classification accuracy so the control is maintained as a governed access model rather than a mail filter.
- Move enforcement to the send event Use controls that inspect message context before delivery and interrupt risky sends with a user correction workflow.
- Audit group permissions behind barrier policies Check whether internal distribution groups, sensitivity labels, and classification mappings still reflect current organisational boundaries.
What's in the full article
KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- How intelligent email DLP evaluates message context before delivery rather than after the fact.
- The interaction between data classifications and group permissions in Microsoft 365 barrier enforcement.
- How user self-correction prompts can reduce accidental disclosure in sensitive email workflows.
- The limitations of static rule maintenance for organisations with frequent exception handling.
👉 Read KnowBe4's whitepaper on preserving email information barriers in Microsoft 365 →
Email information barriers in Microsoft 365: are your controls keeping up?
Explore further
Static DLP creates a barrier-enforcement gap: when the control only reacts after content is composed, the organisation is already depending on user behaviour to preserve separation. That model fails in environments where access rights, classifications, and recipient groups change faster than policy updates. For practitioners, the real issue is not whether DLP exists but whether it can enforce barrier intent at send time.
A question worth separating out:
Q: Who is accountable when an internal email barrier is breached?
A: Accountability should sit with the owners of the barrier policy, the data classification model, and the group permissions that define who may exchange sensitive information. The mail platform team can operate the control, but governance belongs to the business and identity owners who define the separation rules.
👉 Read our full editorial: Email information barriers in Microsoft 365 are failing static DLP