July 25, 2026
Pillar 1 Part 2: The 10-Phase Information Protection Framework
Ten phases, one order, and the structure that turns chaos into a capability.

By Damian Hyde
7 min read
Pillar 1: Information Protection
New to this series? The Series Overview lays out all four pillars and why they fit together.
Most organisations still treat information protection as a product problem. Buy the tool, turn it on, and consider the job done, or so the thinking goes. The organisations that reduce risk in practice treat it as a capability problem instead, and the difference only becomes visible when something goes wrong. One organisation folds. The other recovers.
What follows is a deployment framework built around ten structured phases. It spans Microsoft 365, Google Workspace, SaaS, and cloud platforms on one side, and endpoints, databases, operational technology (OT) and industrial control systems (ICS), AI platforms, and third parties on the other. Each phase builds on the one before it. Skip a phase and you will feel it downstream, usually in the form of false positives, user friction, or a control that looks complete on a dashboard but gives way the moment it is tested. Follow the sequence and you end up with something that holds under real pressure, a measurable security posture executives can actually engage with.
Phase 1: Governance
Information protection has to be set up as a business resilience and operational risk capability, not an IT initiative, which means defining accountability structures, agreeing risk appetite, and settling classification policy before any technical work starts. Get this wrong and every phase that follows inherits the ambiguity.
Phase 2: Discovery
You cannot protect what you cannot see. Discovery maps where sensitive information lives, how it moves, and who has access to it. The output is an exposure report, flow maps, and a risk heatmap, and every decision from this point forward gets grounded in that picture rather than assumption.
Most organisations cannot map their own data with any confidence, and neither can most individuals. Try naming every cloud service, old phone backup, and forgotten USB stick that still has a copy of your tax file number or passport scan sitting on it somewhere. Same blind spot Part 1 named, just at enterprise scale. What a discovery gap like this costs in practice is covered in the companion case study to this piece, using the 2022 Optus breach as the example.
Phase 3: Identity
Reducing unauthorised access through Zero Trust identity controls is the single most impactful phase in this framework. Multi-factor authentication (MFA), conditional access, privileged access management, just-in-time access, and least privilege close more attack surface working together than any perimeter tool ever will on its own. If identity is weak, every layer built on top of it inherits that weakness, no matter how much is spent elsewhere.
Phase 4: Labelling
Downstream data loss prevention (DLP) only means anything if classification taxonomy, automated labelling, and encryption controls are consistent and enforceable across the entire information estate. Without a shared taxonomy and sensitivity labels applied at scale, two people enforcing the same policy end up making different calls on the same document.
Phase 5: DLP enforcement
Part 1 made the case for why DLP fails without sequencing. In practice, that means governance and discovery first, identity and labelling next, enforcement last. Turn DLP on before you have honoured that sequence and you will spend your time managing an enormous volume of false positives and user friction for very little risk reduction. Done in sequence, endpoint and cloud DLP, insider risk controls, USB restrictions, and AI controls actually reduce risk instead of generating tickets nobody has time to read.
Phase 6: SecOps integration
None of this earns its keep if it stays siloed from cyber defence. Feeding classification context into security information and event management (SIEM) and extended detection and response (XDR) telemetry sharpens breach playbooks and turns insider monitoring from noise into something analysts can act on.
Phase 7: Cloud, SaaS, and AI
The modern enterprise is distributed by default, and most of the data sprawl happens in places IT was never told about. Cloud access security broker (CASB) and security service edge (SSE) controls, AI governance frameworks, and SaaS governance extend the protection posture into the environments where sensitive data now flows.
Phase 8: OT and critical infrastructure
Operational technology has a different risk profile, and frequently no traditional security tooling anywhere near it. IT/OT segmentation, secure remote access, and historian protection address a threat surface that most information protection programmes simply ignore, often because the team building the programme has never had to operate in that environment.
Phase 9: Resilience
Resilience is the test that separates programmes that look good on paper from ones that survive contact with a real incident. Ransomware exercises, offline recovery testing, and identity recovery runbooks belong here, tested in a controlled setting long before there's a real incident to respond to.
Phase 10: Optimisation
A programme that stops evolving here starts decaying instead. Key performance indicator (KPI) and key risk indicator (KRI) reporting, tool rationalisation, ongoing risk reassessment, and an executive-facing dashboard keep leadership connected to real outcomes rather than vanity metrics. This phase is what keeps the programme honest once the initial momentum has faded.
The ten phases group naturally into five stages. Governance and Discovery are the foundation: nothing that follows is reliable without them. Identity, Labelling, and DLP Enforcement are the core controls, the layer where most programmes either hold or quietly fail. SecOps Integration and Cloud, SaaS, and AI extend that protection into the operational environments where data actually moves day to day. OT and Critical Infrastructure sits on its own as a specialised environment, a different risk profile requiring a different approach entirely, which is why it has its own phase rather than being folded into the cloud and SaaS work. Resilience and Optimisation are sustainment: the ongoing work that keeps a programme current rather than calcifying once the initial build is complete.
Seeing the Sequence Break in Practice
The phases above are easier to take seriously once you see what happens when several of them are missing at once. Two real, publicly documented breaches map cleanly against this framework. Optus appeared briefly earlier in this piece; Medibank gets the fuller treatment, a full data exfiltration attack path walked through stage by stage against the controls that would have stopped it at each point.
That walkthrough runs long enough to deserve its own space, so it lives in a companion piece to this article rather than inside it. Read it alongside this framework, not as a substitute for it.
Why the Sequence Matters
Organisations that deploy DLP before completing discovery end up managing an enormous volume of alerts while genuine risk stays exactly where it started. Organisations that skip identity controls find every subsequent layer depends on access that was never actually secured. The phases are ordered deliberately because each one creates the precondition for the next, and shortcuts here do not save time, they just move the cost downstream.
Scope matters as much as sequence. This is not a Microsoft 365 play or a cloud security play. It spans every surface the data touches: endpoints, databases, OT environments, AI platforms, and third parties. That breadth is what makes the programme meaningful at board level, where the question is never "are our laptops protected?" It is "can we operate, and can we recover?"
The strategic outcomes worth tracking split roughly into two groups. On the risk side, that's reduced risk exposure, improved resilience, regulatory alignment, and reduced recovery complexity. On the enablement side, it's executive decision-making, greater visibility and control, secure AI adoption, and improved business trust. That is boardroom language, not SOC language. A programme that can show progress against exposure, alignment, and resilience survives budget cycles more easily than one that can only point to telemetry metrics.
Executive decision-making sits on that list for a reason. The relationship runs both ways. The board needs enough visibility into the data estate to make sound calls under pressure, during a breach, during an AI rollout, during a budget cycle when something else looks more urgent. But a programme can also map every phase in this framework correctly and still stall without leadership willing to fund the unglamorous parts. User awareness training is the clearest example. No amount of DLP tuning stops someone forwarding a sensitive file because nobody ever told them not to.
Funding only gets you halfway. Someone senior also has to endorse the programme and keep backing it once the initial enthusiasm wears off, usually the Chief Information Security Officer or a dedicated Data Security Officer, the person who owns enterprise-wide risk and carries the accountability when a programme collapses under pressure. Without that endorsement sitting above the security team rather than alongside it, phases get built in isolation. Isolation is exactly what this framework exists to close.
Where to Start
If you are starting this journey, begin with governance and discovery. Resist the urge to reach for tooling first; it is the most common and most expensive mistake in the sequence.
If you are mid-programme and hitting friction, audit whether identity and labelling were genuinely completed before DLP was switched on. Most enforcement problems trace back to one of those two phases being rushed or skipped.
The organisations that build this capability properly do not just reduce their exposure to breaches. They build something that starts to look like a competitive advantage: operating securely under hostile conditions, recovering quickly, and being able to demonstrate both credibly to customers and regulators. That is what separates trusted enterprises from the ones that end up in the news.
If Part 1 made the case for why this matters, this is where you go and do something about it. Pick one phase you know your organisation hasn't done properly, and check it this week.
Further Reading
The Optus and Medibank breaches referenced above are covered in full, with sources, in the companion case study to this article: Anatomy of a Data Exfiltration Attack Path: Optus, Medibank, and the Phases That Would Have Stopped Them.
If you are trying to sequence a programme like this, or unpick one where the order has already gone wrong, you are welcome to reach out on LinkedIn. I take on freelance and advisory work across all four pillars: information protection, defence in depth, technical risk methodology, and security tooling and platform control gaps.
If this was useful, a share or comment helps others find it.