TL;DR: Outbound email remains a leading source of data loss in Microsoft 365, with Knowbe4 citing that 91% of organisations experienced outbound email data breaches in the last year and arguing that static DLP rules are too rigid to catch human error before damage occurs. The real governance problem is not email volume alone, but the mismatch between fixed controls and contextual communication risk.
NHIMG editorial — based on content published by Knowbe4: CISO Guide Preventing Human Error On Email and Solving Misdirected Emails and Files in Microsoft 365
By the numbers:
- 91% of organizations experienced outbound email data breaches in their Microsoft 365 environment in the last year.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes - and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: How should security teams reduce misdirected email risk in enterprise environments?
A: Security teams should add recipient-aware controls, behavioural detection, and sensitive-thread checks before send.
Q: Why do static DLP rules fail to stop human email mistakes?
A: Static rules are built for known patterns, but misdirected email usually happens when a legitimate user sends valid content to the wrong place.
Q: What breaks when email security ignores identity context?
A: The organisation loses the ability to connect authenticated access with actual disclosure risk.
Practitioner guidance
- Implement send-time risk scoring Assess recipient novelty, external domain exposure, message sensitivity, and attachment type before delivery is allowed.
- Tie email controls to identity risk signals Correlate sender role, account status, unusual sending patterns, and session context with outbound message decisions so that authenticated users are still governed when their behaviour changes.
- Segment high-risk communication workflows Apply stricter controls to finance, legal, HR, and executive mail flows where a single misdirected message can create regulatory or reputational exposure.
What's in the full article
Knowbe4's full guide covers the operational detail this post intentionally leaves for the source:
- Practical examples of the four human-error patterns that lead to email data loss in Microsoft 365.
- The hidden cost categories behind misdirected emails, including financial penalties and reputational damage.
- Why static rule-based DLP fails in real send-time scenarios and where AI-native email security is meant to intervene.
- Implementation detail on how to identify risky communications before damage occurs.
👉 Read Knowbe4's CISO guide on preventing misdirected email and file loss in Microsoft 365 →
Misdirected emails in Microsoft 365: are static DLP controls enough?
Explore further
Static DLP is a control mismatch for human error in email. The problem is not that organisations lack policy language, but that fixed rules cannot reliably interpret recipient context, user intent, or last-mile communication mistakes. In Microsoft 365, that creates a governance gap between approved access and safe disclosure. Practitioners should treat outbound email as a contextual risk decision, not a pure compliance filter.
A question worth separating out:
Q: Who is accountable when a misdirected email exposes sensitive data?
A: Accountability usually spans the business owner, the data security team, and the control owner for email governance. Regulators and auditors will care less about intent than about whether the organisation had preventive controls, training, and monitoring appropriate to the sensitivity of the data. The key question is whether the control design was proportionate to the risk.
👉 Read our full editorial: Misdirected email risk exposes the limits of static DLP in Microsoft 365