30+ Reviews

5 star reviews.png - We Do Your IT Support Bristol

AI Security Pack

Copilot Can See Everything Your Staff Can See

Microsoft 365 Copilot accesses everything your users can see… every SharePoint site, Teams channel, and OneDrive folder. In most tenants, that includes sensitive files shared too broadly years ago. Our AI Security Pack runs your Copilot readiness assessment and closes the governance gaps before Copilot exposes them.

At a glance...

Provided on a three-year term, added per user on top of your existing IT support plan. Available to clients on Core or Complete Unlimited IT Support.

AI Security Pack pricing

One price per user. No tiers to weigh up, and no need to have it all worked out before you start.

Business price

£29.68

per user, per month

Not-for-profit price

£26.98

per user, per month

Year one includes hands-on training, so nobody has to work it out on their own.

Excluding VAT, on a three-year term. Available to clients on Core or Complete Unlimited IT Support.

National Cyber Security Centre logo Cyber essentials plus certified.png - We Do Your IT Support Bristol

How this is sold

Two things worth knowing before you get to a quote, so neither is a surprise later.

It sits on top of your IT support plan

The pack is not sold on its own. The governance it puts in place depends on us managing the estate underneath it: identity, devices and Microsoft 365 itself. Without that, the controls have nothing to hold on to.

Every quote therefore starts with your IT support plan, Core or Complete Unlimited, with the pack added per user on top.

There is one pack, not a range

Core AI is the full pack. It is not an entry tier and there is no upgrade to weigh up later, so the only decision is whether you want it.

Before You Start Using AI, Your Data Needs to Be Ready

Microsoft 365 Copilot is genuinely impressive. It drafts emails, summarises meetings, pulls insights from files you’d forgotten existed, and gives your team back hours every week. Most SME decision-makers we talk to are either already planning their Copilot rollout or actively being pushed toward one by Microsoft or their licence reseller.

 

But here’s what often doesn’t come up in those conversations: Copilot doesn’t check whether someone should see a file before it surfaces it. It works with whatever Microsoft 365 already has access to, which means if your permissions aren’t right, your sensitive data isn’t safe. HR documents, board papers, client contracts, salary information. If the wrong people can technically access those files today, Copilot will happily surface them tomorrow. Erroneous access permissions that have sat quietly in the background for years become a live data leakage risk the moment you enable Copilot at scale.

 

This isn’t a reason to avoid Copilot. It’s a reason to deploy it properly. The Core AI Security Pack puts the data classification, access controls, and governance layer in place before Copilot goes live, so your organisation gets all the productivity gains without the security risks. It’s not a blocker. It’s the foundation.

Is your data ready for Copilot?

Ten questions, under three minutes. You will get an honest answer, not a sales pitch, and it is free.

Step 1 of 12

Do you know which of your files and sites hold genuinely sensitive information?(Required)

Who It's For

The Core AI Security Pack is built for SMEs running Microsoft 365 who are planning to deploy Copilot, have already purchased Copilot licences, or are being asked by their board or leadership team to have a clear AI strategy in place. It is designed for teams of roughly five to fifty.

 

Copilot does not treat a 15-person business any differently to a 500-person one. It will access what it can access, regardless of your size. Responsible AI adoption starts with making sure the right people have access to the right data, and nothing more.

You don’t need a dedicated IT department or enterprise security teams to need this. This pack is particularly relevant if any of the following applies to your organisation:

Business, people and explain with computer at night for training, finance report and budget. Staff, pc and coaching for audit

Who Is It Not For

What the AI Security Pack actually does

The pack is not a bundle of licences. It is the set of guardrails that make it safe to turn AI on inside your Microsoft 365 environment. Everything below needs to be in place before Copilot is switched on, not after.

It finds and labels your sensitive data

Most businesses do not know where their sensitive information actually lives. The pack scans your environment, identifies personal data, financial records, contracts and anything else that matters, and applies sensitivity labels so every file carries its own classification. That labelling is what everything else then acts on.

It stops confidential information leaving

Data loss prevention policies sit across email, documents and chat. If someone tries to send a labelled file to a personal address, share it outside the business or paste it somewhere it should not go, the policy catches it. The rules are yours, set against how your business actually works.

It controls who can reach what

Microsoft 365 environments accumulate sprawl. Project sites nobody closed, folders with permissions nobody remembers setting, groups still
containing people who left. The pack brings that back under control, because Copilot surfaces everything a person can already reach. Tightening access is what stops one over-shared folder becoming a company-wide search result.

It gives you an audit trail

You can see what AI is being used for, by whom, and against which data. That matters for your own oversight, and it matters when a client, an insurer or a regulator asks you to evidence it.

It blocks unapproved AI tools

Your staff are almost certainly already using AI tools you have not approved. The pack blocks access to the ones you have not sanctioned, so company data does not end up in a consumer service with no agreement behind it.

Where Claude fits

Claude is one of the AI assistants we support, not part of the pack. We do not supply Claude licences. Support for assistant-level AI use, Claude included, sits in our AI Support service alongside the ongoing maintenance of the controls above.

Most teams start out unsure, and that is normal. Year one includes hands-on training, so your people learn what AI is genuinely useful for and where the lines are, with someone alongside them. From year two the pack continues as ongoing governance.

Explaining Microsoft Purview

Microsoft Purview is the engine behind the data protection layer in the Core AI Security Pack. This guide explains what Purview does in plain language, how sensitivity labels and DLP policies work together to protect confidential information, and why data classification is the single most important step any organisation can take before enabling Copilot across their Microsoft 365 environment.

Microsoft Copilot Data Governance

Copilot governance is about making sure your AI tools only access what they should. This guide covers how Microsoft 365 Copilot interacts with your organisational data, what good permission models look like, how to identify and fix access controls that put business sensitive data at risk, and what complete visibility over your data environment looks like before and after a Copilot rollout.

Our AI Security Pack sorts out the foundation first, so by the time Copilot or Claude goes live, you know the right people are seeing the right things and nothing else.

Adam Gillett - Director
Staff photo adam.png - We Do Your IT Support Bristol

The AI Security Pack is an add-on rather than a tier. It sits on top of Core or Complete Unlimited IT Support, so the full support service comes underneath it.

We’re here to discuss your AI data security through a collaborative consultation, offering genuine guidance with no pressure or strings attached.

AI Policy for Business

Before you deploy Copilot, your organisation needs a clear position on how AI tools should be used, by whom, and under what conditions. This guide helps SME decision-makers build a practical AI policy that covers responsible AI adoption, shadow AI risks, regulatory requirements, and how to give your team confidence to use Copilot well without creating new security or compliance risks.

Data Loss Prevention for SMEs

DLP policies are one of the most effective ways to prevent sensitive data from leaving your organisation through Copilot or any other channel. This guide explains how Microsoft 365 DLP works for smaller businesses, what compliance violations it can prevent, and how it fits into a broader data protection strategy ahead of your Copilot deployment.

Claude Guide for SMEs

Claude is Anthropic’s AI assistant and one of the most capable tools available for business use today. Unlike consumer AI tools, Claude is built with safety and reliability at its core, making it a practical choice for teams handling sensitive work. This guide covers what Claude can do for your business, how it compares to Microsoft Copilot, and how to deploy it securely alongside your existing Microsoft 365 environment.

Read the detail before you decide

The guides behind this pack, if you want to understand the problem before you talk to anyone.

AI data security

The full guide to Copilot and Claude for UK SMEs, and where the risk actually sits.

Read the guide

Microsoft Copilot security

What Copilot can reach, how over-sharing happens, and what to fix first.

Read the guide

Microsoft Purview explained

Classification, sensitivity labelling and DLP, in plain language.

Read the guide

AI policy for business

What a workable AI policy covers, plus the free template.

Read the guide

Teams and SharePoint governance

Why sprawl is the root of most over-sharing, and how to get it back.

Read the guide

Claude for business

If your staff are using Claude as well as Copilot, start here.

Read the guide

FAQs

What Microsoft 365 licence do we need?

The Core AI Security Pack is built around Microsoft 365 Business Premium, which is the standard licence we recommend for SMEs. You will also need Microsoft Copilot licences for the users you want to enable. If you are on a different licence tier or channel, including monthly enterprise channel or current channel arrangements, we will review that as part of the onboarding conversation and make sure everything is aligned before deployment begins.

Microsoft states that Microsoft 365 Copilot does not use your organisation’s content to train its foundation models, and that your data stays inside your tenant. That is Microsoft’s commitment about their own service. The half of the question we can affect is different: what Copilot can see inside your tenant on the day it is switched on. That depends entirely on your permissions, and that is what this pack addresses.

The licences are part of it, not the point of it. Purview and AvePoint do very little out of the box. The value is in the configuration: deciding what counts as sensitive in your business, building the classification and labelling rules, finding and closing the over-shared sites, and setting policies that keep it that way as people come and go. Buying the licences without that work leaves you paying for tooling nobody has switched on.

You can. It needs someone who knows Purview and SharePoint permissions properly, and it needs them to keep at it, because permissions drift every time a project starts or someone changes role. Most teams of five to fifty do not have that person spare. If you do have them, we would rather say so than sell you something you do not need.

The Let’s Copilot adoption programme runs through year one, while people are working out what to use AI for. From year two the pack continues as data governance: classification, sensitivity labelling, data loss prevention, workspace governance and filtering. Those are ongoing jobs rather than one-off ones, which is why they do not stop.

Because the risk is per person. Every user is a set of permissions, and every new starter is a new set. Pricing per user keeps what you pay in step with what actually has to be governed, rather than a flat fee that stops reflecting your business the moment you hire.

Next Steps: Book Your AI Security Review

Most businesses get to Copilot and realise they should have sorted their data governance six months earlier. We would rather help you get ahead of that.

 

The Core AI Security Pack gives your organisation the data classification, access controls, and governance foundation that Microsoft 365 Copilot needs to work safely and effectively. No rushed deployments. No data leakage surprises. No compliance violations after the fact.

 

Talk to us and we will give you a clear picture of where your Microsoft 365 environment stands and exactly what getting it Copilot-ready looks like for your organisation.

Senior, happy man and call center with headphones in customer service, support or telemarketing at office. Mature businessman