Cloud Misconfiguration: The Silent Data Leak in Your Sharing Settings

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, deep DoD infrastructure experience, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

When small business owners picture a data breach, they picture an attacker: a stolen password, a phishing email, a piece of malware that got past antivirus. Cloud misconfiguration doesn't look like any of that. It looks like nothing happening at all, because nothing has to happen. The client contract, the employee roster, the financials spreadsheet, they were shared with "anyone with the link" eleven months ago for a one-time review, and the link has been sitting there ever since, technically accessible to anyone who has it, indexable by search engines, forwardable by anyone who received it. There's no alert for this. There's no lockout, no failed login, no antivirus flag. The data was simply left where anyone could walk up to it.

Why "convenient" and "secure" pull in opposite directions

Microsoft 365 and Google Workspace both make sharing effortless by design, because effortless sharing is what most users want most of the time. The fastest way to share a file is usually the least restrictive one: a public link that anyone can open without signing in, rather than a link restricted to specific people who each have to be added by name. Under a deadline, employees pick the fast option every time, and most never circle back to tighten it once the urgency passes. Multiply that by every file shared over a year at a 20-person company, and a business can easily accumulate dozens of public or org-wide links it has completely forgotten exist. None of this requires bad intent or carelessness in the way people usually think about it; it's simply what happens when a fast default is used a few hundred times without review.

The long tail nobody remembers to close

Sharing links are only half the problem. The other half is accounts: guest accounts added for a contractor, a client portal login shared with an outside bookkeeper, an integration connected to a marketing tool that still has read access to a shared drive two years after anyone used it. Each one was reasonable when it was created. None of them get removed automatically when the project ends, the contractor moves on, or the tool falls out of use, because closing access isn't a step most businesses have built into their offboarding process for anyone other than actual employees. The result is a slowly growing list of people and services with a live door into company data, most of which the business itself couldn't name off the top of its head if asked.

  • SharePoint sites inherit permissions from their parent. A site created under a broadly shared parent site can end up more exposed than anyone intended, without a single explicit sharing action.
  • Google Drive's "anyone with the link" spans past the org. Unlike a link restricted to people inside the company domain, this setting works for literally anyone on the internet who obtains the URL.
  • Old links keep working after the reason for them is gone. Cloud platforms rarely expire a share automatically, so an old client review link is often just as live today as the day it was created.

What actually closes the gap

Fixing this starts with visibility, not new tools. Both Microsoft 365's SharePoint admin center and Google Workspace's Admin console have built-in reports that list what's shared externally and with whom; running one is a same-day task most small businesses have simply never done. From there, the fix is policy plus a recurring habit: set the organization-wide default sharing link to "specific people" instead of "anyone with the link," require expiration dates on any external share, and put a quarterly 20-minute review on the calendar to check the external sharing report and the guest account list together. Neither takes specialized tooling, and both turn a standing, invisible exposure into something that gets closed within a business quarter instead of lingering for years.

Where this fits

FAQs about cloud misconfiguration

What is cloud misconfiguration?

Cloud misconfiguration is when a cloud service like Microsoft 365, Google Workspace, or a hosted app is set up in a way that exposes data further than intended, such as a file shared with "anyone with the link," a folder that inherited public permissions from a parent site, or a guest account that was never removed. No credentials are stolen and no malware is involved; the door was simply left open by a setting.

How is a misconfiguration different from being hacked?

A hack requires an attacker to break in: guess a password, phish a login, or exploit a vulnerability. A misconfiguration requires nothing, because the data is already reachable to anyone who has the link or already has an account in the tenant. It's frequently discovered by a search engine indexing a public link, by a departed employee's leftover guest access, or by a security scan, rather than by any breach alert.

What's the most common cloud misconfiguration for small businesses?

The single most common one is an "anyone with the link" or "anyone in the organization" sharing default on OneDrive, SharePoint, or Google Drive that employees never change, combined with links that get forwarded, posted in chat, or pasted into a spreadsheet, spreading access far beyond who was ever intended to see the file.

How do I find out if my business already has exposed files?

Microsoft 365 and Google Workspace admin centers both have built-in sharing reports: Microsoft's SharePoint admin center lists sites and files shared externally, and Google's Admin console has a Drive audit log and sharing settings report. Running one of these reports and reviewing what comes back is a same-day task most small businesses have never done.

Not sure what's already exposed in your cloud tenant?

30 minutes with an engineer with DoD infrastructure experience. We'll pull your external sharing report, review guest and vendor access, and show you exactly what's been left open, no scanner install, no obligation.

Book your free security assessment
Call (831) 204-0501 Book free assessment