Managed Insider Threat
& Data Loss Prevention
Protect critical data, detect insider threats, and record employee and outsourced staff activity with complete forensic evidence — purpose-built for organizations running on Microsoft 365 infrastructure, managed by Greenwill as a neutral third-party auditor.
฿49,000
Starting — Setup + 5 Licenses
฿1,600
/person/month Managed Service
M365 Ready
Integrated with Microsoft 365
On-Premise
Data stays on-premise 100%
-----Why your organization needs this service
4 Fundamental Challenges This Service Solves
In an era where outsourcing, remote access, and third-party vendors accessing
critical systems is the norm — visibility blind spots are growing every day.
Control Outsource & Remote
Ensure remote, outsourced, and third-party staff are monitored around the clock with zero blind spots.
Prevent Data Leakage
Detect and block data exfiltration via USB, email, cloud, clipboard, or printing — DLP across every channel.
Build Forensic Evidence
Every action is recorded with timestamps — usable as evidence for internal investigations and legal proceedings.
Boost Productivity 10–15%
When employees know monitoring is in place, personal browsing and non-work activities drop significantly — the deterrence effect.
-----Who benefits
Every Level of Your Organization Is Protected
Executive Management
Protect trade secrets, production formulas, customer databases, and high-value intellectual property.
Legal & Compliance
Meet PDPA, ISO 27001, and industry-specific regulatory obligations with complete audit trails.
Human Resources
Fair, transparent employee monitoring with evidence-based reporting for disciplinary matters.
Business Continuity
Prevent disruption from insider sabotage, accidental data loss, or unauthorized system access.
Productivity ROI — Example: 20 employees (avg. salary ฿40,000/month)
฿960,000
Productivity Gain 10% (Conservative)
฿1,440,000
Productivity Gain 15% (Optimistic)
฿525K–1M
Net Benefit after ฿435K/yr service cost
Productivity gains alone recover 2–3x the service cost within the first year — before counting the value of prevented data breaches and compliance.
----StaffCop Enterprise
StaffCop Capabilities — All-in-One Platform
User Activity Monitoring
Screen recording (video + screenshots), keystroke logging, application & website tracking — capturing every on-screen activity.
Data Loss Prevention
Block USB, cloud uploads, clipboard, printing, and email attachments — preventing data leakage across every channel.
Insider Threat Detection
Behavioral anomaly detection, AI risk scoring, and policy-based alerts — detecting threats in real-time.
On-premise, endpoint-based — every feature included in a single license.
No add-ons, no hidden costs.
Forensic Evidence
OCR content scanning, session playback, immutable logs with timestamps — ready for HR, legal, or court proceedings.
Remote Control & Admin
Remote desktop, HW/SW inventory, device control, and agent management — centralized administration.
Cross-Platform Support
Windows, Linux (Ubuntu/CentOS/Debian), macOS (Intel & Apple Silicon) — covering every OS in your organization.
-----Microsoft 365 Security
Enhanced with Microsoft 365 DLP & Mobile Protection
StaffCop covers Endpoints → Microsoft 365 covers Cloud + Mobile — together
forming a complete DLP solution.
Purview DLP
Enforce DLP policies across Outlook, OneDrive, SharePoint, and Teams — on both PC and mobile.
Sensitivity Labels
Automatically classify and label documents, encrypt confidential files — labels persist across all platforms.
Intune MAM
Control corporate data on personal mobile devices — block copy/paste, prevent save to personal storage, remote wipe.
Conditional Access
Define M365 access rules — enforce MFA, restrict locations, require device compliance.
Coverage Comparison
-----Ideal for organizations on Microsoft 365
Why This Solution Is Purpose-Built
for Organizations Running on Microsoft 365
Most organizations using Microsoft 365 (Outlook, Teams, OneDrive, SharePoint) have
critical data flowing through the cloud constantly, yet lack monitoring and DLP
coverage across both endpoints and cloud — our solution is purpose-built to close this gap.
Purview DLP — Enforce policies across the entire M365 ecosystem
Set up data leakage prevention rules across Outlook, OneDrive, SharePoint, and Teams instantly. Whether employees send files, share links, or chat sensitive data, the system alerts or blocks based on defined policies — e.g., preventing files containing national ID numbers or customer data from leaving the organization.
Sensitivity Labels — Auto-classify + encrypt
Automatically classify documents as Confidential, Internal, or Public based on content. Labels follow the file everywhere — whether downloaded, forwarded, or copied. Confidential files remain encrypted and access-restricted at all times.
Purview DLP — Enforce policies across the entire M365 ecosystem
Set up data leakage prevention rules across Outlook, OneDrive, SharePoint, and Teams instantly. Whether employees send files, share links, or chat sensitive data, the system alerts or blocks based on defined policies — e.g., preventing files containing national ID numbers or customer data from leaving the organization.
Sensitivity Labels — Auto-classify + encrypt
Automatically classify documents as Confidential, Internal, or Public based on content. Labels follow the file everywhere — whether downloaded, forwarded, or copied. Confidential files remain encrypted and access-restricted at all times.
Does your organization fit this profile?
✓ Uses Outlook, Teams, and OneDrive as primary work tools
✓ Employees access corporate email and files on personal mobile devices
✓ Vendors or outsourced staff access data via SharePoint or Teams
If you answered "yes" to 3 or more — this solution is purpose-built for your organization.
✓ Confidential files are shared via OneDrive without controls
✓ Subject to PDPA and needs evidence of data protection measures
✓ Already holds M365 Business Premium, E3, E5, or EMS licenses
Layer 1: Endpoint
Screen recording, keystrokes, USB/print control, behavior analytics, forensic evidence — everything happening on PC/Notebook endpoints.
StaffCop Enterprise
Layer 2: Cloud & Mobile
DLP policies on Outlook/Teams/OneDrive, sensitivity labels, Intune MAM on mobile, conditional access — everything happening in the cloud.
Microsoft 365 Security
Layer 3: Oversight
Third-party audit, monthly executive reports, privilege separation, immutable logs — managing both endpoint + cloud for you.
Greenwill Managed Service
How StaffCop + Microsoft 365 Work Together
-----Solution Design
How We Designed This Solution
— Full Cloud + Endpoint DLP, Without Buying E5 for Everyone
For organizations already on Microsoft 365, we designed an architecture that delivers
enterprise-grade protection at a budget an SME can actually approve — built on four principles.
DESIGN 01 · TARGETED E5 LICENSING
Microsoft Purview DLP enforces server-side — once your admin team creates a policy, it applies to every mailbox and every SharePoint site automatically, regardless of each user's license level . So the organization enables E5 only for the team that creates and manages policy (DPO + IT Security + Lead Data Owner, typically 3–5 people), while everyone else stays on Business Basic/Standard — saving 68–76% versus E5 for all.
E5 licenses only for the DLP Admin team and Data Owners
DESIGN 02 · ENDPOINT DLP LAYER
The leak channels cloud DLP cannot see — copying to USB, printing, uploading to personal cloud storage, sending via Line/WeChat — are controlled by StaffCop Enterprise on every PC, laptop and file server, with screen recording and keystroke logging as forensic evidence. Nearly 10× cheaper than E5's Endpoint DLP, with more capability.
StaffCop serves as the endpoint-level DLP
DESIGN 03 · CLOUD-DEPLOYED SERVER
The StaffCop server can be deployed on the cloud, so agents on staff machines report back over the internet from anywhere — office, work-from-home, or in the field — with no gaps in coverage. This spans both company-owned devices and employees' personal devices where explicit consent has been given, according to the policy your organization adopts.
StaffCop server on the cloud — monitoring anywhere, all the time
DESIGN 04 · GREENWILL DEPLOY & SUPPORT
Greenwill installs the StaffCop server, deploys agents to every machine, configures both Purview and StaffCop policies, and provides training plus ongoing support — so your organization's admin can collect and access staff activity data at all times , with your organization as the full Data Controller. If you'd rather have Greenwill monitor as a neutral third party, see the Managed Insider Threat Service below.
Greenwill installs and supports — your admin collects the data, continuously
PDPA note: Employee monitoring requires a disclosed Acceptable Use Policy for company devices, and explicit consent for employees' personal devices. Greenwill prepares the full policy set during implementation, and we recommend HR/Legal review before go-live.
-----Solution Design
How We Designed This Solution
— Full Cloud + Endpoint DLP, Without Buying E5 for Everyone
For organizations already on Microsoft 365, we designed an architecture that delivers
enterprise-grade protection at a budget an SME can actually approve — built on four principles.
DESIGN 01 · TARGETED E5 LICENSING
Microsoft Purview DLP enforces server-side — once your admin team creates a policy, it applies to every mailbox and every SharePoint site automatically, regardless of each user's license level . So the organization enables E5 only for the team that creates and manages policy (DPO + IT Security + Lead Data Owner, typically 3–5 people), while everyone else stays on Business Basic/Standard — saving 68–76% versus E5 for all.
E5 licenses only for the DLP Admin team and Data Owners
DESIGN 02 · ENDPOINT DLP LAYER
The leak channels cloud DLP cannot see — copying to USB, printing, uploading to personal cloud storage, sending via Line/WeChat — are controlled by StaffCop Enterprise on every PC, laptop and file server, with screen recording and keystroke logging as forensic evidence. Nearly 10× cheaper than E5's Endpoint DLP, with more capability.
StaffCop serves as the endpoint-level DLP
DESIGN 03 · CLOUD-DEPLOYED SERVER
The StaffCop server can be deployed on the cloud, so agents on staff machines report back over the internet from anywhere — office, work-from-home, or in the field — with no gaps in coverage. This spans both company-owned devices and employees' personal devices where explicit consent has been given, according to the policy your organization adopts.
StaffCop server on the cloud — monitoring anywhere, all the time
DESIGN 04 · GREENWILL DEPLOY & SUPPORT
Greenwill installs the StaffCop server, deploys agents to every machine, configures both Purview and StaffCop policies, and provides training plus ongoing support — so your organization's admin can collect and access staff activity data at all times , with your organization as the full Data Controller. If you'd rather have Greenwill monitor as a neutral third party, see the Managed Insider Threat Service below.
Greenwill installs and supports — your admin collects the data, continuously
PDPA note: Employee monitoring requires a disclosed Acceptable Use Policy for company devices, and explicit consent for employees' personal devices. Greenwill prepares the full policy set during implementation, and we recommend HR/Legal review before go-live.
-----Greenwill's differentiator
Managed Insider Threat Service —
A Neutral Third-Party Auditor
When management cannot fully trust internal IT administrators — because they
themselves may be monitoring targets — Greenwill acts as a neutral, independent auditor.
Internal IT staff have no access to monitoring logs. Only the Greenwill team and designated management group can view sensitive data.
Privilege Separation
All admin actions are logged and cannot be modified. Reports go directly to senior management.
Immutable Audit Trail
Log data is stored separately and encrypted. Only authorized Greenwill analysts and designated executives have access.
External Log Isolation
Monthly summary highlighting risky behaviors, anomalies, policy violations, and actionable recommendations — delivered directly to the board or C-suite.
Monthly Executive Report
-----Greenwill's differentiator
Managed Insider Threat Service —
A Neutral Third-Party Auditor
When management cannot fully trust internal IT administrators — because they
themselves may be monitoring targets — Greenwill acts as a neutral, independent auditor.
StaffCop Implementation Package
Server install + agent deployment (5 endpoints) + policy configuration + training (4 days). Includes 5 licenses for Year 1.
฿49,000
One-time
StaffCop License Subscription
Annual license per pack of 5 endpoints. All features included (UAM, DLP, Analytics, Remote Control). Includes support and updates.
฿17,000
/pack of 5/year
Managed Insider Threat Service
Third-party monitoring & behavior audit by Greenwill analysts. Monthly executive summary report. Min. 5 persons, 3-month commitment.
฿1,600
/person/month
Microsoft 365 DLP Configuration
Configure Purview DLP policies, sensitivity labels, and classification rules across M365 tenant. Includes workshop and deployment.
Request a Quote
One-time
Intune MAM & Conditional Access Setup
Configure MAM policies, conditional access rules, and device compliance. Includes training and enrollment guide.
Request a Quote
One-time
Managed Microsoft DLP Service
Ongoing M365 DLP management — policy tuning, incident review, monthly reporting. Min. 20 users, 3-month commitment.
Request a Quote
/user/month
-----Proven results
Success Stories — Trusted by Real Clients
CASE 1 · Japanese Manufacturing · ~200 employees
Challenge: Outsourced team accessed ERP remotely from overseas with no Thai staff oversight during off-hours.
Solution: Deployed StaffCop on Jump Host and ERP Server to record 100% of all user activity.
Result: Full audit trail restored confidence in security controls. Japan HQ now has real-time visibility.
Japanese Manufacturing Plant — Outsource Control on ERP
CASE 2 · Japanese Packaging · ~160 employees
Challenge: Concerns about unauthorized computer use and potential customer data leakage from departing employees.
Solution: StaffCop Server deployed to record all employee workstation activity with daily summary reports.
Result: Management gains full visibility — applications, start/stop times, and productivity metrics per employee per day.
Japanese Packaging Manufacturer — Customer Data Leakage Prevention
-----Frequently asked questions
