The Files Ruining Your Sharing Policies

May 27, 2014 | Cloud, Data, Featured Articles, Security

Imagine your organization has taken all the right steps to protect its important files and information from outside attacks. Is that enough? Firewalls, anti-virus software and priority access protocols only cover file storage. What about file sharing?

According to Ponemon’s 2013 Cost of Data Breach Study, the majority of information leaks aren’t caused by malicious or criminal attacks. Rather, about two-thirds of data breaches are actually due to system glitches and human factors. You can’t afford to let users break important information-sharing policies. The study found the average cost of a data breach in the United States is US$188 per record, which makes the average organizational cost more than $5.4 million. In addition, breaches put businesses, users and customer integrity at risk when internal information becomes public, which can lead to even bigger problems.

We’ve covered pieces of this topic before, so let’s step back and get an overview of how your employees’ file sharing may be putting your organization at risk. Then we’ll look at some steps you can take to mitigate that risk.

Use of personal accounts to share data

Five o’clock comes, and one of your employees realizes he or she will have to take some work home. The user sends an email to a personal account and attaches the internal files. To an employee, this is no big deal. The boss would be happy the employee is putting in the extra effort.

Unfortunately, this is an all-too-common occurrence. In its Dangerous File-Sharing whitepaper, Globalscape* found in the last year, 63 percent of employees had used personal email to send sensitive work documents. Of those employees, 74 percent believe their companies approve of this type of file-sharing. The truth is, using personal accounts to share internal files is dangerous; family members may have access to personal accounts—personal devices are rarely secure—and the user can then send the data to anyone without oversight.

Use of unapproved storage methods

The whitepaper also found that 63 percent of employees have used remote storage devices like USB drives and mobile phones to transfer confidential work files. Forty-five percent of employees have also used cloud applications like Dropbox and Box. Although these storage methods may work well for the employee, they have next to no security measures in place. USB drives and cell phones are easy to misplace or for someone to steal, and require few credentials to access. As for sites like Dropbox, they provide no way for users to encrypt their files before uploading them to the site.

Reliance of convenient, easy-to-use applications and sites

According to the Cisco whitepaper Data Leaks Worldwide, approximately 70 percent of IT security professionals said that unauthorized application use accounted for at least half of their organizations’ data leaks. Modern employees have grown accustomed to using their favorite applications and websites. Problems arise when these applications and sites take no security measures and employees unknowingly risk exposing corporate data through them.

Possible solutions

The good news is that there are steps your organization can take to keep files secure against human factors. The first is education. Most employees don’t want to put the company in danger and won’t intentionally risk a security breach; they simply don’t realize the danger of their actions. It is important to take time to carefully explain to your staff the risks of using unsanctioned tools and what impact careless file sharing could have.

You should also implement technologies that give employees the ease and freedom they demand. If current processes drag on an employee’s productivity, that employee is more likely to sidestep or simply ignore your policies. Give your employees an attractive, company-approved option like Novell Filr — an on-premise offering from our sister company, Novell — which lets employees access their corporate their corporate files anywhere, on any device, but which stores data on-premises and inside your existing security.

When you keep your employees happy and productive with the technologies they want, your business is in a better position to stick to its file sharing policies and protect sensitive information.

TomS

Tom Scearce is Attachmate’s product marketing manager for managed file transfer and SSH solutions. He has 17 years of marketing, sales, product management, and consulting experience in a variety of industries including software, professional services, telecommunications, media, medical devices, and health/fitness services. Tom holds a Masters in Business Administration from the Foster School of Business at the University of Washington.

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more