
CASE STUDY
Protecting Sensitive Data in the Not-for-Profit Sector
The Challenge
When Shane Riddle joined the Y Victoria, he brought something uncommon in the not-for-profit sector: a clear-eyed view of data risk. His previous experience with GuardWare had taught him what happens when sensitive information moves unchecked and he saw the same exposure potential at the Y Victoria.
It’s a risk most people overlook. Not-for-profits compete fiercely for government grants and service contracts. Their proposals, tender responses, budgets, and partner plans represent real strategic value. If leaked, the consequences extend well beyond embarrassment, lost funding, damaged trust, and disrupted service delivery to the communities that depend on them.
The Y Victoria needed stronger governance over how documents were managed and retained. They needed to understand how sensitive data moved across the organisation and reduce the everyday mistakes that create risk: incorrect sharing, storing data beyond its useful life and files migrating to the wrong systems. They also needed to detect insider risk. Critically, any solution had to improve control without slowing down the people doing the work.
Unlike a bank or a defence contractor, organisations like the Y Victoria cannot lock their environment down like a fortress. They need the flexibility to deliver services across the community and remain attractive to the workers and volunteers they depend on. A heavy-handed security approach would work against both. What they needed was a solution that could be flexible enough to support operations while still controlling how sensitive data was handled. And because flexibility was a given, user education had to be part of the answer, ensuring people understood how to avoid putting sensitive data at risk.
The Solution
GuardWare deployed GuardWare INSIGHT to monitor the use of personal and sensitive data across the Y Victoria. For the first time, their security and IT teams had clear visibility into where sensitive files went, who accessed them, and where risks were emerging.
Rolling out user-facing security responses required particular care. If you get it wrong, people resist rather than adopt. The Y Victoria recognised this early. They secured senior leadership support through to board approval, then trialled, refined, and staged the deployment. The result was an organisation that embedded the controls rather than fought them.
With INSIGHT deployed, it exposed a new challenge. The IT team was still dealing with a volume of routine incidents, staff emailing sensitive corporate data via personal accounts, for example. These weren’t malicious acts, but they consumed time and attention the security team needed for more serious issues.
The solution for the Y Victoria was to adopt GuardWare’s SASI module, an Automated User Education capability that sends targeted, non-invasive alerts to staff at the moment they perform a risky action. The alerts were customised and branded to align with the Y Victoria’s own policies, trialled with senior leadership approval, and rolled out organisation-wide. The result, GuardWare’s SASI module immediately shaped good cyber behaviour across the organisation. Routine risky actions dropped, security awareness became part of everyday work, and the IT team was freed to focus on genuine risks like insider threats.
The Outcome
The deployment reduced incidents and enabled teams to act on issues before they escalated. The Y Victoria now has continuous visibility over data movement and the governance framework to back it up.
"The Y Victoria required a way to ensure the correct governance was in place with our document management and retention. We enlisted the help of GuardWare, which has assisted us in monitoring the use and transportation of personal and sensitive data needed to conduct our operations and serve our communities. GuardWare has been successfully used at the Y Victoria for our continual data movement monitoring, providing the greatest level of detail protecting against incorrect use of data, data breaches and data loss prevention."

Yonatan Amare
IT Manager, Y VictoriaThe Takeaway
CISOs, CIOs, and CSOs, understand all too well the risk that follows data movement. Your data doesn’t sit neatly in one system or one team. If you can’t answer “Where is our sensitive data, what is it, and who can access it?”, you need to start with visibility and governance. Map your critical data, track its movement, then tighten controls where risk is highest.
The Y Victoria story also demonstrates the value of Automated User Education. GuardWare’s SASI module allows large organisations to institutionalise cyber security and make it everyone’s responsibility. When staff receive real-time alerts at the point of risk, behaviour changes. No one wants to be the person caught doing the wrong thing. The result is a dramatically more secure organisation overall.
It also has a direct operational benefit. By reducing the volume of routine incidents, automated education frees up cyber teams to focus on what matters most. Particularly the complex issues around user error and insider threats that require human judgement and investigation.

