Have you setup MS Office 365? Did you start with security in mind?
Have you reviewed your Security and privacy settings? Nothing is configured out of the box. When implementing o365, start treating the platform as if you were securing your On-Prem infrastructure.
Start with the basics:
- Password Policies
- Privacy Statements
Can you add additional security to users?
Have you enabled and enrolled users to use MFA? Is it Enfored MFA?
Has access been restricted?
https://docs.microsoft.com/en-us/sharepoint/control-access-based-on-network-location
Mobile Device Management, are you applying any controls to apps accessing OneDrive?
Has logging been enabled for the Office 365 Security and Compliance reports and stats