top of page

Managed Insider Threat
& Data Loss Prevention

Protect critical data, detect insider threats, and record employee and outsourced staff activity with complete forensic evidence — purpose-built for organizations running on Microsoft 365 infrastructure, managed by Greenwill as a neutral third-party auditor.

฿49,000

Starting — Setup + 5 Licenses

฿1,600

/person/month Managed Service

M365 Ready

Integrated with Microsoft 365

On-Premise

Data stays on-premise 100%

View Services & Pricing →
Request a POC

-----Why your organization needs this service

4 Fundamental Challenges This Service Solves

In an era where outsourcing, remote access, and third-party vendors accessing

critical systems is the norm — visibility blind spots are growing every day.

Control Outsource & Remote

Ensure remote, outsourced, and third-party staff are monitored around the clock with zero blind spots.

Prevent Data Leakage

Detect and block data exfiltration via USB, email, cloud, clipboard, or printing — DLP across every channel.

Build Forensic Evidence

Every action is recorded with timestamps — usable as evidence for internal investigations and legal proceedings.

Boost Productivity 10–15%

When employees know monitoring is in place, personal browsing and non-work activities drop significantly — the deterrence effect.

-----Who benefits

Every Level of Your Organization Is Protected

Executive Management

Protect trade secrets, production formulas, customer databases, and high-value intellectual property.

Legal & Compliance

Meet PDPA, ISO 27001, and industry-specific regulatory obligations with complete audit trails.

Human Resources

Fair, transparent employee monitoring with evidence-based reporting for disciplinary matters.

Business Continuity

Prevent disruption from insider sabotage, accidental data loss, or unauthorized system access.

Productivity ROI — Example: 20 employees (avg. salary ฿40,000/month)

฿960,000

Productivity Gain 10% (Conservative)

฿1,440,000

Productivity Gain 15% (Optimistic)

฿525K–1M

Net Benefit after ฿435K/yr service cost

Productivity gains alone recover 2–3x the service cost within the first year — before counting the value of prevented data breaches and compliance.

----StaffCop Enterprise

StaffCop Capabilities — All-in-One Platform

User Activity Monitoring

Screen recording (video + screenshots), keystroke logging, application & website tracking — capturing every on-screen activity.

UAM

Data Loss Prevention

Block USB, cloud uploads, clipboard, printing, and email attachments — preventing data leakage across every channel.

DLP

Insider Threat Detection

Behavioral anomaly detection, AI risk scoring, and policy-based alerts — detecting threats in real-time.

Analytics

On-premise, endpoint-based — every feature included in a single license.

No add-ons, no hidden costs.

Forensic Evidence

OCR content scanning, session playback, immutable logs with timestamps — ready for HR, legal, or court proceedings.

Forensic

Remote Control & Admin

Remote desktop, HW/SW inventory, device control, and agent management — centralized administration.

Admin

Cross-Platform Support

Windows, Linux (Ubuntu/CentOS/Debian), macOS (Intel & Apple Silicon) — covering every OS in your organization.

Multi-OS

-----Microsoft 365 Security

Enhanced with Microsoft 365 DLP & Mobile Protection

StaffCop covers Endpoints → Microsoft 365 covers Cloud + Mobile — together

forming a complete DLP solution.

Purview DLP

Enforce DLP policies across Outlook, OneDrive, SharePoint, and Teams — on both PC and mobile.

Sensitivity Labels

Automatically classify and label documents, encrypt confidential files — labels persist across all platforms.

Intune MAM

Control corporate data on personal mobile devices — block copy/paste, prevent save to personal storage, remote wipe.

Conditional Access

Define M365 access rules — enforce MFA, restrict locations, require device compliance.

Coverage Comparison

-----Ideal for organizations on Microsoft 365

Why This Solution Is Purpose-Built
for Organizations Running on Microsoft 365

Most organizations using Microsoft 365 (Outlook, Teams, OneDrive, SharePoint) have

critical data flowing through the cloud constantly, yet lack monitoring and DLP

coverage across both endpoints and cloud — our solution is purpose-built to close this gap.

Purview DLP — Enforce policies across the entire M365 ecosystem

Set up data leakage prevention rules across Outlook, OneDrive, SharePoint, and Teams instantly. Whether employees send files, share links, or chat sensitive data, the system alerts or blocks based on defined policies — e.g., preventing files containing national ID numbers or customer data from leaving the organization.

Sensitivity Labels — Auto-classify + encrypt

Automatically classify documents as Confidential, Internal, or Public based on content. Labels follow the file everywhere — whether downloaded, forwarded, or copied. Confidential files remain encrypted and access-restricted at all times.

Purview DLP — Enforce policies across the entire M365 ecosystem

Set up data leakage prevention rules across Outlook, OneDrive, SharePoint, and Teams instantly. Whether employees send files, share links, or chat sensitive data, the system alerts or blocks based on defined policies — e.g., preventing files containing national ID numbers or customer data from leaving the organization.

Sensitivity Labels — Auto-classify + encrypt

Automatically classify documents as Confidential, Internal, or Public based on content. Labels follow the file everywhere — whether downloaded, forwarded, or copied. Confidential files remain encrypted and access-restricted at all times.

Does your organization fit this profile?

✓ Uses Outlook, Teams, and OneDrive as primary work tools

✓ Employees access corporate email and files on personal mobile devices

✓ Vendors or outsourced staff access data via SharePoint or Teams

If you answered "yes" to 3 or more — this solution is purpose-built for your organization.

✓ Confidential files are shared via OneDrive without controls

✓ Subject to PDPA and needs evidence of data protection measures

✓ Already holds M365 Business Premium, E3, E5, or EMS licenses

Layer 1: Endpoint

Screen recording, keystrokes, USB/print control, behavior analytics, forensic evidence — everything happening on PC/Notebook endpoints.

StaffCop Enterprise

Layer 2: Cloud & Mobile

DLP policies on Outlook/Teams/OneDrive, sensitivity labels, Intune MAM on mobile, conditional access — everything happening in the cloud.

Microsoft 365 Security

Layer 3: Oversight

Third-party audit, monthly executive reports, privilege separation, immutable logs — managing both endpoint + cloud for you.

Greenwill Managed Service

How StaffCop + Microsoft 365 Work Together

-----Solution Design

How We Designed This Solution
— Full Cloud + Endpoint DLP, Without Buying E5 for Everyone

For organizations already on Microsoft 365, we designed an architecture that delivers

enterprise-grade protection at a budget an SME can actually approve — built on four principles.

DESIGN 01 · TARGETED E5 LICENSING

Microsoft Purview DLP enforces server-side — once your admin team creates a policy, it applies to every mailbox and every SharePoint site automatically, regardless of each user's license level . So the organization enables E5 only for the team that creates and manages policy (DPO + IT Security + Lead Data Owner, typically 3–5 people), while everyone else stays on Business Basic/Standard — saving 68–76% versus E5 for all.

E5 licenses only for the DLP Admin team and Data Owners

DESIGN 02 · ENDPOINT DLP LAYER

The leak channels cloud DLP cannot see — copying to USB, printing, uploading to personal cloud storage, sending via Line/WeChat — are controlled by StaffCop Enterprise on every PC, laptop and file server, with screen recording and keystroke logging as forensic evidence. Nearly 10× cheaper than E5's Endpoint DLP, with more capability.

StaffCop serves as the endpoint-level DLP

DESIGN 03 · CLOUD-DEPLOYED SERVER

The StaffCop server can be deployed on the cloud, so agents on staff machines report back over the internet from anywhere — office, work-from-home, or in the field — with no gaps in coverage. This spans both company-owned devices and employees' personal devices where explicit consent has been given, according to the policy your organization adopts.

StaffCop server on the cloud — monitoring anywhere, all the time

DESIGN 04 · GREENWILL DEPLOY & SUPPORT

Greenwill installs the StaffCop server, deploys agents to every machine, configures both Purview and StaffCop policies, and provides training plus ongoing support — so your organization's admin can collect and access staff activity data at all times , with your organization as the full Data Controller. If you'd rather have Greenwill monitor as a neutral third party, see the Managed Insider Threat Service below.

Greenwill installs and supports — your admin collects the data, continuously

PDPA note: Employee monitoring requires a disclosed Acceptable Use Policy for company devices, and explicit consent for employees' personal devices. Greenwill prepares the full policy set during implementation, and we recommend HR/Legal review before go-live.

-----Solution Design

How We Designed This Solution
— Full Cloud + Endpoint DLP, Without Buying E5 for Everyone

For organizations already on Microsoft 365, we designed an architecture that delivers

enterprise-grade protection at a budget an SME can actually approve — built on four principles.

DESIGN 01 · TARGETED E5 LICENSING

Microsoft Purview DLP enforces server-side — once your admin team creates a policy, it applies to every mailbox and every SharePoint site automatically, regardless of each user's license level . So the organization enables E5 only for the team that creates and manages policy (DPO + IT Security + Lead Data Owner, typically 3–5 people), while everyone else stays on Business Basic/Standard — saving 68–76% versus E5 for all.

E5 licenses only for the DLP Admin team and Data Owners

DESIGN 02 · ENDPOINT DLP LAYER

The leak channels cloud DLP cannot see — copying to USB, printing, uploading to personal cloud storage, sending via Line/WeChat — are controlled by StaffCop Enterprise on every PC, laptop and file server, with screen recording and keystroke logging as forensic evidence. Nearly 10× cheaper than E5's Endpoint DLP, with more capability.

StaffCop serves as the endpoint-level DLP

DESIGN 03 · CLOUD-DEPLOYED SERVER

The StaffCop server can be deployed on the cloud, so agents on staff machines report back over the internet from anywhere — office, work-from-home, or in the field — with no gaps in coverage. This spans both company-owned devices and employees' personal devices where explicit consent has been given, according to the policy your organization adopts.

StaffCop server on the cloud — monitoring anywhere, all the time

DESIGN 04 · GREENWILL DEPLOY & SUPPORT

Greenwill installs the StaffCop server, deploys agents to every machine, configures both Purview and StaffCop policies, and provides training plus ongoing support — so your organization's admin can collect and access staff activity data at all times , with your organization as the full Data Controller. If you'd rather have Greenwill monitor as a neutral third party, see the Managed Insider Threat Service below.

Greenwill installs and supports — your admin collects the data, continuously

PDPA note: Employee monitoring requires a disclosed Acceptable Use Policy for company devices, and explicit consent for employees' personal devices. Greenwill prepares the full policy set during implementation, and we recommend HR/Legal review before go-live.

-----Greenwill's differentiator

Managed Insider Threat Service —
A Neutral Third-Party Auditor

When management cannot fully trust internal IT administrators — because they

themselves may be monitoring targets — Greenwill acts as a neutral, independent auditor.

Internal IT staff have no access to monitoring logs. Only the Greenwill team and designated management group can view sensitive data.

Privilege Separation

All admin actions are logged and cannot be modified. Reports go directly to senior management.

Immutable Audit Trail

Log data is stored separately and encrypted. Only authorized Greenwill analysts and designated executives have access.

External Log Isolation

Monthly summary highlighting risky behaviors, anomalies, policy violations, and actionable recommendations — delivered directly to the board or C-suite.

Monthly Executive Report

-----Greenwill's differentiator

Managed Insider Threat Service —
A Neutral Third-Party Auditor

When management cannot fully trust internal IT administrators — because they

themselves may be monitoring targets — Greenwill acts as a neutral, independent auditor.

GWMON03

StaffCop Implementation Package

Server install + agent deployment (5 endpoints) + policy configuration + training (4 days). Includes 5 licenses for Year 1.

฿49,000

One-time

GWSTCOP

StaffCop License Subscription

Annual license per pack of 5 endpoints. All features included (UAM, DLP, Analytics, Remote Control). Includes support and updates.

฿17,000

/pack of 5/year

GWSTFMON

Managed Insider Threat Service

Third-party monitoring & behavior audit by Greenwill analysts. Monthly executive summary report. Min. 5 persons, 3-month commitment.

฿1,600

/person/month

GWMS365

Microsoft 365 DLP Configuration

Configure Purview DLP policies, sensitivity labels, and classification rules across M365 tenant. Includes workshop and deployment.

Request a Quote

One-time

GWMAM

Intune MAM & Conditional Access Setup

Configure MAM policies, conditional access rules, and device compliance. Includes training and enrollment guide.

Request a Quote

One-time

GWMDLP

Managed Microsoft DLP Service

Ongoing M365 DLP management — policy tuning, incident review, monthly reporting. Min. 20 users, 3-month commitment.

Request a Quote

/user/month

-----Proven results

Success Stories — Trusted by Real Clients

CASE 1 · Japanese Manufacturing · ~200 employees

Challenge: Outsourced team accessed ERP remotely from overseas with no Thai staff oversight during off-hours.

Solution: Deployed StaffCop on Jump Host and ERP Server to record 100% of all user activity.

Result: Full audit trail restored confidence in security controls. Japan HQ now has real-time visibility.

Japanese Manufacturing Plant — Outsource Control on ERP

CASE 2 · Japanese Packaging · ~160 employees

Challenge: Concerns about unauthorized computer use and potential customer data leakage from departing employees.

Solution: StaffCop Server deployed to record all employee workstation activity with daily summary reports.

Result: Management gains full visibility — applications, start/stop times, and productivity metrics per employee per day.

Japanese Packaging Manufacturer — Customer Data Leakage Prevention

-----Frequently asked questions

FAQ — Insider Threat & DLP

---------- Start protecting your organization

Ready to Take Control of Your
Organization's Security & Transparency?

Request a free Proof of Concept (POC) —

test the real system in your organization, no obligation.

Greenwill Solution Co., Ltd. · 159 Pattanakarn 74, Prawet, Bangkok 10250, Thailand

bottom of page