A Data Governance Approach to Microsoft Purview
Why Microsoft Purview with Bridewell?
- Implementing Microsoft Purview for Effective Data Governance and Compliance: Our approach to implementing and deploying Microsoft Purview is driven by data governance, with a focus on ensuring your organization is compliant with relevant data privacy regulations. Our Microsoft, Cloud, and Data Privacy experts will work alongside you to understand regulatory risks within your environments and remediate them through Purview’s data, compliance, and governance capabilities.
- Expertise in Cloud Security and Threat Protection with Microsoft Purview: As one of Microsoft’s leading cybersecurity partners, our team are designated solution partners for Security. We hold specialisms in Cloud Security and Threat Protection and have extensive experience in deploying Purview for some of the UK’s largest and most highly regulated organizations.
The Benefits of Purview
Our team will help you deploy Microsoft Purview quickly and effectively, so you enjoy the following benefits.
Identify Risks to Your Data
Assess your current data privacy programme for any ongoing risks.
Identify Risky User Behaviour
Identify any user behaviour that risks non-compliance or a data breach.
Achieve Best Practice for Data Protection
Meet relevant requirements for regulatory compliance and industry best practice.
Ease the Pressure on Your Security Team
Our SOC team will take on responsibilities from your in-house security team, allowing them to dedicate time and resources to other activities.
HESA Drive Digital Transformation with Bridewell’s DPO as a Service
The Challenge
As a leading HE data source and one of the largest processors of data in the UK, HESA handles ‘special category’ (highly sensitive) data for over 30 million people across England, Wales, Scotland and Northern Ireland. To ensure that this data was handled securely and in compliance with all relevant regulations, HESA needed a highly qualified and driven DPO with the skills to both manage their data privacy function and support a major transformation project. For HESA, data is a core part of every aspect of their business and ensuring the right practices are in place is essential to their operations.
The challenge for HESA was finding a suitably qualified DPO to occupy the role at an appropriate cost and within a reasonable timeframe. As with many cyber security roles, data privacy experts are in high demand and there were few candidates with the right expertise and experience to match HESA’s requirements.
"We didn’t just want our DPO to come into HESA to run the data privacy team and maintain business as usual. We needed someone who could add strategic value to our processes and the major projects that are key to our current operations and future ambitions."
Louise Morrison, General Counsel, HESA
Given the size and scope of their organisation, data protection teams and architecture, HESA recognised the importance of finding the right person for the role and concluded that using a service provider to find a suitable DPO was a good option. Rather than undergoing a timely and expensive recruitment process, outsourcing to Bridewell assured them of a highly certified data privacy expert to lead their data protection team.
The Solution
In parallel to seeking a DPO, HESA were already engaged with Bridewell in an implementation project. Given the success of the infosec project and their strong relationship with the Bridewell consultant running it, HESA decided to bring them into the business as their named DPO.
"Bridewell was our first choice for a DPO. I had only been working with [our Bridewell Consultant] for a few weeks but, given the quality of their work, it was clear that the standard they provided matched if not exceeded our requirements."
Louise Morrison, General Counsel, HESA
One of the first projects to support was a heavily technology-based business transformation, ‘Data Futures’, which was designed to wholly upgrade HESA’s existing infrastructure. The goal was to build a new technology platform within AWS that was fit for the digital age and would drive efficiencies in the higher education sector. Embedding data protection controls whilst maintaining a streamlined and agile programme of work was essential, given the scale and value of the project.
HESA’s named DPO supported across the entire programme, implementing a governance structure, offering complex technical advice in real-time throughout development, and ensuring that data protection was embedded by design. This was further supported by penetration tests from Bridewell’s offensive security team to ensure the integrity of the new platform.
Further to the Data Futures project, HESA also required their named DPO to support in a merger transaction with Jisc. In this capacity, they performed all required data protection workstreams in connection with the merger. Thinking ahead, a roadmap was created by
our DPO support to determine how the two separate data protection teams from each of the merger partners could be most effectively integrated after completion.
"Chris, our named DPO, has been a trusted senior partner throughout the merger."
Louise Morrison, General Counsel, HESAThe Results
With Bridewell’s DPO as a Service, HESA were able to rapidly bring significant data privacy expertise and experience into their organisation. With a Bridewell consultant as their named DPO, they have a highly qualified, reliable data privacy expert who singlehandedly advises the business and works with them to solve their challenges. Regularly communicating with and providing recommendations to key internal and external stakeholders, they have performed a fundamental role in major projects essential to HESA’s operations.
Leading their data privacy team, their named DPO has written the entire data privacy compliance program and provided substantial support in improving multiple data workstreams.
"With Bridewell as our named DPO, we’ve been able to hand over full responsibility to our consultant. It’s an end-to-end service and we trust in their expertise and understanding of our business to advise our board, solve our data privacy challenges, and support our business objectives."
Louise Morrison, General Counsel, HESAThey have helped manage resource levels of the existing data privacy team and brought on additional Bridewell consultants when needed for further support. This is not just true of their typical business as usual operations but of their role in Data Futures and the merger, where they have acted as a trusted, senior adviser.
"A lot of our external stakeholders have come to rely on Chris [our named DPO]. He has formed a significant part of day-to-day operations and is an ambassador of the company. His high performance has helped us establish a bestin- class team and has raised the status of HESA within our sector."Louise Morrison, General Counsel, HESA
Start your Microsoft Purview Journey with Bridewell
Speak with one of our consultants to see how we can support your organization with Microsoft Purview.
How it Works
Data governance isn’t just about technology, but how organizations use, process and secure data. Our Purview deployments prioritize understanding how your employees handle data so we can implement policies that support their ways of working.
Data Discovery
Our cloud security and data privacy teams will hold discovery workshops to understand:
- Your current approach to data classification, retention and data loss
- Any challenges with how your users access and share data
- Your goals with Purview
Our team will review your current approach against applicable data protection legislation and best practice standards.
Any areas of non-compliance or data risk will be highlighted immediately.
Design and Implementation
Based on our findings, we will recommend updates to relevant policies and provide a test deployment of our proposed labelling solution to address these shortcomings.
This test deployment ensures there is no risk to your current operations and allows our team to optimize your Purview deployment before it is moved to a live environment.
Why Us?
180+ Security Specialists
Our team have diverse experience across sectors and disciplines, and hold accreditations from numerous industry bodies.
Certifications
Our people and services are highly accredited by leading industry bodies including CREST, the NCSC, and more. Our SOC holds extensive accreditations from CREST (including for CSIR and SOC2) and works closely with our cyber consultancy services.
Partnerships
As a Microsoft Partner, we also hold advanced specialisms in Cloud Security and Threat Protection. We’ve also implemented some of the UK’s largest deployments of the Microsoft Security stack, inc. Sentinel, Defender, Purview and more.