Every small business shares files: contracts to clients, invoices to vendors, drawings to a contractor, payroll to an accountant. Most do it the fastest way, which is an email attachment or a link that opens for everyone.
That convenience has a cost. Once a file leaves your control you cannot take it back. Here is why common sharing habits leak data, and three practical steps to fix them without slowing anyone down.
1. Understand why the usual methods leak
The two most common ways to share files each carry a hidden risk:
- Email attachments: the file is copied into every inbox it touches. It can be forwarded, synced to a phone, or sit in a compromised mailbox for years. Our post on hidden forwarding rules shows how attackers read old mail quietly.
- "Anyone with the link" sharing: anyone who gets the URL can open the file, with no sign-in and no record of who it was. Links get forwarded, pasted into chats, and indexed.
- Personal accounts and free tools: files in a personal Dropbox, Gmail, or consumer drive are invisible to you and stay accessible after an employee leaves. This is a form of shadow IT.
- Oversharing inside the company: broad internal permissions let tools like Copilot surface files people should never see.
The result is leaked contracts, exposed customer records, and a notification problem under California breach law.
2. Set up safe sharing in the tools you already pay for
Microsoft 365 (OneDrive and SharePoint) and Google Workspace both include secure sharing. You mostly need to change the defaults:
- Make the default link type "specific people" instead of "anyone."
- Require clients to verify with a sign-in or one-time code before opening a file.
- Set links to expire, such as 7 to 30 days, so old shares close on their own.
- Use view-only or block download when the client only needs to read the file.
- Limit who in the company is allowed to share outside the organization.
Not sure which platform fits? See OneDrive vs SharePoint vs Teams and our Google Workspace security settings guide. For the most sensitive files, add email encryption or a client portal.
3. Review sharing and clean up regularly
Safe defaults decay. People share a file for a project and forget it. Build a short routine:
- Run a report of files shared outside the company each quarter and remove anything stale.
- Audit guest accounts and remove vendors and contractors whose work is done.
- Turn on audit logs so you can see who opened or downloaded a shared file.
- Add data loss prevention rules that warn before Social Security or card numbers are shared.
- Write a one-page rule on what may be shared externally and how, and cover it in security awareness training.
When someone leaves, follow your offboarding checklist so their shares do not outlive their job.
Common mistakes to avoid
- Leaving "anyone with the link" as the default sharing option.
- Sending tax IDs, contracts, or health information as plain email attachments.
- Letting staff use personal cloud accounts for client work.
- Sharing a whole folder when only one file is needed.
- Never reviewing guest access, so former vendors keep permanent entry.
The takeaway
Sharing files is part of doing business, and it does not need to be risky. Keep files in one company-managed place, share with named people, add expiration dates, and review outside access every quarter. An hour of setup closes one of the quietest data leaks in a small office.
Frequently asked questions
What is the safest way to share files with clients?
Share a link from your business Microsoft 365 or Google Workspace account instead of attaching the file. Limit the link to specific people, require sign-in or a verification code, set an expiration date, and turn off downloading when the client only needs to view it.
Is it safe to email attachments?
Email is fine for low-risk files, but attachments are copied to every inbox and cannot be recalled or expired. For contracts, tax records, health information, or customer data, share a permissioned link and consider encrypting the message too.
What does "anyone with the link" mean?
It means anyone who has the URL can open the file, with no sign-in. If the link is forwarded, posted, or guessed, the file is exposed. Use "specific people" links for anything sensitive.
Should employees use personal Dropbox or Google Drive accounts for work?
No. Personal accounts sit outside your control, so you cannot see what is shared or shut off access when someone leaves. Require work files to live in the company-managed tenant.
How often should we review shared files?
Review external sharing at least quarterly. Both Microsoft 365 and Google Workspace can report files shared outside the company, so you can remove old links and stale guest access.
Want file sharing locked down the right way?
Ghosxt sets up secure sharing in Microsoft 365 or Google Workspace, reviews who has outside access, and trains your team. You talk directly to the owner. See current pricing or our cybersecurity services.
Book your free assessmentPrefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.