TL;DR: Enterprises face wider leakage risk because sensitive data moves across SaaS, cloud, contractors, and employee devices, while the article notes a $4.5M average breach cost, 22 days of disruption, and $15.4M insider-attack losses. Data leakage control is therefore as much an identity and access problem as a data-protection problem, especially where access is temporary, shared, or poorly audited.
NHIMG editorial — based on content published by Island: Data Leakage and Loss Prevention: Best Practices for Enterprises
By the numbers:
- Data breaches also cause an average disruption in business operations of 22 days.
- Insider threats cost companies an average of $15.4M, three times as much as average data breaches.
- Human error accounted for 68% of data breaches in 2023.
Questions worth separating out
Q: How should teams reduce risk from secrets hidden in SaaS data?
A: Teams should search business systems such as tickets, attachments, and chat exports for embedded credentials, then remove or rotate anything sensitive.
Q: Why do contractors and third-party vendors increase data leakage risk?
A: They expand the number of identities that can reach sensitive data while sitting outside the organisation’s direct operational control.
Q: What breaks when data classification does not follow the workflow?
A: When classification stops at the repository, security teams lose track of how sensitive data is transformed, copied, and reused in SaaS or AI systems.
Practitioner guidance
- Discover and classify sensitive data continuously Scan endpoints, file systems, cloud services, and SaaS applications on a recurring basis, then add manual reviews for data stored in unconventional locations such as shared drives or personal devices.
- Tighten RBAC around restricted datasets Map roles to only the minimum data required for the job, then pair those roles with time-based access for task-specific use cases and formal request, approval, and revocation steps.
- Require MFA before sensitive-data access Apply multi-factor authentication to users reaching confidential or restricted information, especially where contractors, partners, and remote workers access the same systems as employees.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- Practical step-by-step guidance for building a data discovery and classification process across endpoints, SaaS, and cloud systems
- Detailed examples of access control, MFA, monitoring, and audit practices applied to enterprise data protection
- Operational guidance on patch management, employee training, and policy automation for DLP programmes
- Browser and endpoint workflow examples for controlling data use on unmanaged devices
👉 Read Island's guide to enterprise data leakage prevention and access control →
Data leakage control and identity governance: are your controls keeping up?
Explore further
Identity controls are the first DLP boundary, not an adjacent control layer. The article presents data leakage as a content and transport problem, but the operational failure usually starts earlier: access was too broad, too persistent, or too poorly audited. When contractors, partners, and employees all reach the same data estate, IAM becomes the deciding control plane for leakage reduction.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when leakage happens despite training and monitoring?
A: Accountability sits with the organisation that failed to align identity controls, data classification, and operational monitoring. Training helps, but it does not replace governable access decisions, auditable reviews, or containment controls that can prove who touched the data and when.
👉 Read our full editorial: Enterprise data leakage control depends on identity governance