There's a spreadsheet with salary information sitting in the inbox of someone who no longer works at your company. There's a client contract saved in a collaborator's personal OneDrive, shared "just in case." There's a financial report downloaded on five different laptops, unencrypted, unrestricted, with no record of who opened it.
Nobody did this with bad intentions. Nobody did it with any intention at all. It simply happened, because nothing stopped it.
According to the IBM Cost of a Data Breach Report 2025 for Latin America, a data breach costs organizations in the region an average of $2.51 million, and the average time to detect and contain one is 316 days. More than ten months. By then, the file has already circulated, been printed, forwarded, and done its damage.
Microsoft Purview sensitivity labels exist to address exactly this problem. They are available today in M365. And most organizations have them misconfigured, half-implemented, or simply absent.
The Mistake That Looks Like Security But Isn't
The standard logic goes like this: if the file is in the right folder, it's protected. Restricted folder access, problem solved.
The problem is that files don't stay in folders. They get downloaded. They get attached to emails. They get copied to Teams, to a USB drive, to Gmail. And the moment they leave the folder, all protection is gone.
Sensitivity labels change that logic. Protection travels with the file, not with the location. A document encrypted by a label stays encrypted even if someone downloads it, attaches it to an external email, or uploads it to a personal cloud service.
The recipient can't open it. Can't read it. The damage is contained.
But for that to work, there has to be real encryption in the label. And that's where the first serious mistake happens.
The Sign That Protects Nothing
The most common sensitivity label implementation in M365 looks like this: labels are created, published to users, files get visually marked as "Confidential" or "Internal," and someone on the IT team marks the project as done.
What that implementation doesn't have is encryption.
A label without encryption is just metadata. It informs, but it doesn't protect. Any user with access to the file can remove it, ignore it, or share the file freely. The sign says "confidential." The file isn't.
How to fix it: every label that classifies sensitive data needs encryption activated, with explicit permissions defining who can decrypt it. That means deciding, before configuring anything, who has the right to read each level of information. That's not a technical decision. It's a business decision that IT implements afterward.
The Taxonomy Nobody Uses
The second most destructive mistake isn't in the technical configuration. It's in the number of labels.
The most common taxonomy mistake is creating eight labels that don't match how teams actually think about their data. Adoption dies before it starts. Users see too many options, none of them obvious, and pick whichever looks safest, or they skip labeling entirely.
Best practice is to use between 3 and 5 labels per scope, with short, clear names that don't require a compliance manual to understand. Public. Internal. Confidential. Highly Confidential. That's enough to start.
What's genuinely expensive to fix is the taxonomy after users have already adopted incorrect labels. Changing a label that already has thousands of files associated with it is a project, not a task. The initial design matters disproportionately more than any subsequent configuration.
How to fix it: start with business questions, not the Purview portal. What data, if leaked, causes real harm? What do teams call that information day to day? Labels need to match the organization's real vocabulary, not technical compliance language.
The Volume No Team Can Classify Manually
Most organizations that implement labels configure them for manual application. The user opens the file, selects the label, keeps working.
The problem is scale. A mid-sized organization can have hundreds of thousands of unclassified historical documents. Nobody is going to open each file and pick a label.
Advanced auto-labeling, available with E5 licenses or the Purview Information Protection add-on, inspects the content of files and emails, detects patterns like card numbers, identity documents, or financial data, and applies the corresponding label without user intervention.
Throughout 2026, Microsoft expanded label policies to include dynamic and non-mail-enabled security groups, giving more control over who receives which labels without needing to configure additional groups. Labels now also extend to Microsoft Entra security groups, applying the same M365 classification across the entire corporate identity infrastructure without separate configuration.
How to fix it: auto-labeling doesn't replace a taxonomy strategy. First, define the right labels. Then train the classification engine with the information types relevant to the organization. In that order, not the reverse.
The Cost of Doing Nothing
The common narrative is that protecting data is expensive. Additional licenses, implementation projects, training.
What rarely gets calculated is the cost of not doing it.
Breaches identified and contained in under 200 days cost an average of $2.21 million in the region. Those lasting more than 200 days reached $2.82 million. The $600,000 difference is the cost of detecting late. Encrypted labels are part of what makes earlier detection and containment possible.
The risk doesn't come only from external attacks. According to IBM, 20% of the breaches studied in 2025 were linked to unauthorized AI tools used by the organizations' own employees, and those breaches cost up to $670,000 more than average. Employees pasting confidential documents into external AI tools because nobody told them not to, and because the file had no restriction to stop them.
The Real Starting Point
Implementing sensitivity labels in M365 is not a three-month project. It's a one-week exercise if you start with the right questions.
What data, if leaked, causes real harm to the organization? Who has the right to see it? What do teams call it today?
With those three answers, the technical configuration is the simplest part of the entire process. If you'd like the macareno.net team to support that diagnostic, reach out and we'll schedule a no-commitment conversation.
Sources
- IBM Cost of a Data Breach 2025 — Latin America — IBM Newsroom LATAM
- IBM Cost of a Data Breach 2025 — Global — IBM Think
- Microsoft Purview Sensitivity Labels Deployment Guide 2026 — Decryption Digest
- Microsoft Purview: Extended scoping for sensitivity label policies — M365 Admin
- Sensitivity Labels for Microsoft Entra Security Groups — M365 Admin
