Secure Sharing Practices

Secure Sharing Practices

Share files safely without creating security gaps.

What Is Secure Sharing Practices?

Every file you send is a decision about who can reach it later. This exercise runs the sharing cases that carry more risk than they look: a contract with financial terms going to outside counsel, customer data crossing offices, a document shared with a vendor on a different platform, a file too big for email. You choose a method each time and see the consequences, including why a password-protected expiring link is not the same as an unencrypted attachment.

What You'll Learn in Secure Sharing Practices

Secure Sharing Practices — Training Steps

  1. A Busy Week at Catalyst Ventures

    Today is particularly hectic — the Q3 audit window closes at 5 PM and the external auditor still hasn't received the financial report.

  2. The Urgent Request

    Alice receives an urgent message from her manager Marcus Chen on Telegram.

  3. Accessing SecureShare

    Under pressure to meet the 5 PM deadline, Alice opens the Catalyst SecureShare portal to send the report as quickly as possible.

  4. Selecting the File

    The SecureShare portal displays Alice's files. She needs to select the Q3 Financial Report to share with the auditor.

  5. Setting the Recipient

    Alice needs to enter the auditor's email address from Marcus's message.

  6. Quick Share Settings

    The sharing configuration page appears. Alice is in a rush — she picks the most permissive options without thinking: 'Full Control' access, 'Anyone with the link' visibility, 'Never' for expiration, and hits Share Now.

  7. Confirmation

    Steve confirms he got the report. Deadline met, crisis averted. Or so Alice thinks.

  8. Something Is Wrong

    Three weeks later, Alice arrives at work to find an urgent email from the IT Security team. Her stomach drops as she reads the subject line.

  9. The Audit Log

    Alice clicks the link to the audit log, dreading what she'll find.

  10. What Went Wrong

    Three critical failures turned a routine file share into a catastrophic data exposure: 1. Full Control access. The auditor only needed to view the report, but Alice gave Full Control — allowing anyone with the link to download, edit, or redistribute the file. 2. No access controls. 'Anyone with the link' means anyone who obtains the URL can access the file — no authentication required. The link was forwarded, shared, and eventually posted publicly. 3. No expiration or password. A link that never expires and requires no password is a permanent, unprotected gateway to sensitive data. Once it's out, there's no way to contain it.

Security Framework Coverage

CWE

  • CWE-732 Incorrect Permission Assignment for Critical Resource
  • CWE-668 Exposure of Resource to Wrong Sphere

CIS Controls

  • CIS 3 Data Protection
  • CIS 14.4 Train Workforce on Data Handling Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.DS Data Security