AI Readiness Assessment: start with a free Snapshot checklist

Free Snapshot · ~60 minutes · Findings in 5 business days · Paid Assessment if you need the plan

✓ Free Snapshot in ~60 minutes

✓ Findings report in 5 business days (Critical / High / Medium)

✓ Paid Assessment only if you want the remediation plan

See how it works ↓

DLP is an important part of AI data protection. Microsoft Purview can restrict Copilot from processing specified sensitivity-labeled content and can apply controls to sensitive prompts in supported experiences. Effective coverage depends on licensing, rollout, policy configuration, labels, and the AI workflow. Review permissions and connector access alongside DLP, and validate how the controls work in your environment.

Identifying Exposure

35%+

of DLP implementations fail to prevent data loss

Source: CrowdStrike / Industry Research

80%+

of workers use unapproved AI tools at work

Source: UpGuard, November 2025

38%

of employees share sensitive data with AI without approval

Source: CybSafe / NCA, 2024

$650k

average cost of an AI-associated data breach

Source: IBM Cost of a Data Breach Report 2024

The DLP Reality

DLP helps. Permissions and AI-specific controls still need review.

We ask almost every prospect the same question early on: what does your DLP actually block today. The answers span the whole range. A few companies have nothing running. Most have Purview’s out-of-the-box settings, quietly doing very little. A smaller group has real policies, tuned and reviewed on a cadence.

Here’s the thing. It barely matters which one you are.

Traditional DLP watches for a person doing something deliberate. Uploading a file. Attaching a document to an email. Sending something to the printer. It was built around a human making a choice, and it applies rules to that choice. That’s the entire model, and for years it worked fine, because humans were the variable it was designed to manage.

Agents don’t make that kind of choice. They connect to your environment, inherit whatever access the person who deployed them already has, and then work continuously in the background, pulling data, summarizing it, answering questions with it. No upload. No email. No print job. Nothing your DLP was ever built to watch for.

So the real question isn’t how well your DLP is configured. It’s whether it was ever pointed at the right layer to begin with. For agents, it wasn’t, no matter how good your policies are on paper.

Side-by-side graphic comparing four actions monitored by DLP with checkmarks against four actions AI agents take marked with red X's.

Three AI Data-Exposure Risks to Validate

Permission-Based Access

Copilot operates within the initiating user's permissions. Broad access can therefore increase the data available to connected AI workflows. Purview DLP can restrict processing of specified sensitivity-labeled content in supported Copilot experiences, but it does not replace least-privilege access reviews. Validate user permissions, connector scope, and applicable DLP policies together.

Insight Extraction

AI can summarize or combine information from multiple permitted sources. Whether a sensitive result is detected or restricted depends on the applicable policies, classification, and supported workflow. Test representative prompts and responses to confirm that the controls address the information your organization needs to protect.

Context Leakage Through Conversation

Responses and citations can reveal sensitive content or information about its sources. Review which data the tool can use, the applicable sensitivity labels and DLP restrictions, and the activity records available to your team. Validate these controls against real use cases rather than assuming either complete protection or no coverage.

Why This Matters More If You're a Law Firm

Every one of the three leaks above carries a different weight for you than it does for a manufacturer or a bank. An agent that surfaces patterns from client files isn’t just exposing data. It’s touching material that may be privileged, and once a third party system has processed it, the privilege question gets harder to answer, not easier. Your confidentiality obligations under Rule 1.6 don’t pause because the disclosure happened inside an AI tool instead of an email attachment. If your DLP can’t see what the agent touched, you can’t tell opposing counsel, a regulator, or your own managing partner what actually happened. That’s the gap this Snapshot is built to find.

What this free Snapshot covers

This isn’t a sales call dressed up as a Snapshot. It’s a working session built around five areas, plus a live look at your Microsoft Secure Score.

The Snapshot covers:

The five modules:

  • Data Security Posture — Where your DLP policies stand today: classification coverage, enforcement mode, and what agents can currently reach across your data estate.
  • Data Estate & Access Reviews — Your permission model, when access was last reviewed, and how much guest access exposure is sitting inside SharePoint and M365.
  • Security Monitoring Coverage — What your EDR/XDR setup catches, whether prompts are getting logged anywhere, and what your SIEM retains.
  • Shadow AI Exposure — Your AI usage policy, what your firewall blocks, and, if you can share DNS logs, which outside AI tools your team is already using.
  • Secure Score Baseline — A live pull from security.microsoft.com, filtered down to the recommendations that matter for Copilot and agent deployment, not the full list.

 

One step before we meet:

We send a short, read-only SharePoint exposure script for your admin to run. No elevated credentials needed. They send back the CSV, we review it before the session, and we walk in already knowing your exposure map instead of guessing at it live in front of you.

After the session, you'll have:

  • A findings report with severity ratings (critical, high, medium) across all five areas
  • Your actual SharePoint site counts by risk tier, pulled straight from your tenant
  • Your live Secure Score plus the specific fixes that matter for agent deployment
  • A shadow AI exhibit, if DNS logs were provided
  • Recommendations ranked by risk, with the reasoning behind each one

 

This free session is where most people start. Whether it’s enough on its own or the first step toward something bigger comes up naturally on the walkthrough call once you’ve seen the findings.

White Cocha Technology wordmark in serif font centered on a transparent background.

How the Snapshot works

We Schedule

Submit the form and we aim to respond within 4–8 business hours, Monday–Friday, 8 AM–5 PM Central. We arrange a 60-minute session around your team's availability. Before we meet, we send a read-only SharePoint exposure script and session brief. Your administrator reviews and runs the script, then shares the agreed output securely.

We Assess

60 minutes. Five modules, plus a live Secure Score review. Since we already have your SharePoint data in hand by the time we sit down, we're not spending the session gathering the basics, we're already working from it.

We Deliver

Written findings are provided within five business days after the working session and receipt of the required inputs, followed by a 30-minute walkthrough. If deeper work is needed, we agree on a separate paid Assessment scope. You can also act on the findings with your own team.

Total time from your team: 60 minutes for the session, 30 minutes for the walkthrough. That’s it, apart from the few minutes it takes your admin to run one script.

"We thought our security posture covered agents because we had DLP. The Snapshot showed us that our DLP didn't see any of what our Copilot deployment was doing. We had a coverage gap we didn't know existed — and we fixed it before it became a problem."

What Organizations Without This Snapshot Are Discovering

  • Agent-accessible data that bypassed DLP policies for months before anyone noticed
  • Compliance gaps surfaced during audits rather than internal assessments — at the worst possible time
  • Sensitive data patterns extracted by agents and surfaced to users who shouldn’t have seen them
  • No audit trail when regulators or clients asked what the agent accessed

These scenarios are drawn from publicly documented AI governance incidents and regulatory findings.

Snapshot spots are limited.

Steven runs every session himself. No junior analysts, no templated intake handed off to someone else, no offshore review. If you’re planning to expand agent use this quarter, this is the moment to look at it, not after you’ve already deployed.

The Snapshot identifies risk. The paid AI Readiness Assessment develops the remediation plan. Other free Snapshots: Exposure Snapshot · Zero Trust Snapshot.

Get your free AI Readiness Snapshot

Tell us about your firm. Steven reaches out within 24 hours to schedule your 60-minute Snapshot. Findings report in 5 business days. Not a sales pitch.

What happens after you submit:

  • You receive a confirmation email immediately
  • Steven emails you personally
  • You schedule your 60-minute assessment session
  • You receive your findings report within 5 business days
Professional headshot of Steven R. Combs smiling in a dark suit jacket and open-collar white shirt against a soft blue background.

Steven R. Combs | Co-Founder & Principal, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers. He holds certifications in Varonis, Check Point, FinOps, and Microsoft 365 security.

View full profile | LinkedIn