False Confidence: The File-Sharing Habits Quietly Putting Remote Teams at Risk
Photo: Frankincense Diala, CC BY-SA 4.0, via Wikimedia Commons
There is a particular kind of organizational risk that thrives in the space between what employees believe is secure and what actually is. In the context of remote work file sharing, that space has grown considerably over the past several years—and most companies have yet to fully map its dimensions.
Since the widespread shift to distributed work that began in 2020, American businesses have invested heavily in video conferencing, project management tools, and cloud productivity suites. What many have not done is audit how their teams actually move files from one person to another. The result is a patchwork of habits—some sanctioned, many not—that collectively represent a significant and underappreciated security exposure.
The Email Attachment Problem Has Not Gone Away
Despite years of warnings from cybersecurity professionals, email remains the default file-sharing method for a substantial portion of the American workforce. A 2023 survey by Mimecast found that email attachments are still involved in the majority of data loss incidents at US companies. The reasons are cultural as much as technical—email is familiar, immediate, and requires no explanation.
But email was not designed as a secure document transfer system. Attachments sent via email create uncontrolled copies that the sender cannot revoke, cannot track, and cannot update. A contract sent to five recipients now exists in five inboxes, potentially on five personal devices, with no mechanism to ensure the recipients are viewing the current version or that the file has not been forwarded further.
When that contract contains pricing information, client data, or proprietary terms, the exposure is real. When the recipient's email account is later compromised in a credential-stuffing attack—a common occurrence—those files become accessible to whoever now controls that inbox.
Consumer Messaging Apps: Convenient, Not Compliant
The normalization of consumer messaging platforms in professional settings has introduced a category of file-sharing risk that many IT departments are still struggling to address. Applications designed for personal communication—including popular messaging platforms used on both iOS and Android—are regularly used by remote employees to share work documents because they are faster and more conversational than email.
The security architecture of these tools was not built for enterprise use. Files shared through consumer messaging apps may be stored on the provider's servers under terms of service that grant broad data usage rights, may not be encrypted in transit to enterprise standards, and are almost certainly not subject to your organization's retention or access policies. When an employee leaves the company, those files do not leave with your IT team's knowledge—they remain in private message threads that the organization cannot access or audit.
This is not a theoretical concern. The Federal Trade Commission has cited improper use of personal communication tools as a contributing factor in several enforcement actions against companies that failed to maintain adequate control over sensitive consumer data.
The Shadow IT Ecosystem
Beyond email and messaging apps lies a broader phenomenon security professionals call shadow IT—the use of tools and services that employees adopt independently, without IT approval or organizational oversight. For file sharing specifically, this often means personal accounts on consumer cloud storage platforms, personal Google Drive or Dropbox accounts used for convenience, or USB drives carried between home offices and client sites.
A 2022 report from Cybersecurity Insiders found that over 80 percent of employees admitted to using non-approved applications for work purposes. For remote teams, where the physical oversight of a shared office environment is absent, this figure is likely higher. Each unsanctioned tool represents a potential data exfiltration point, a gap in your access controls, and a liability in the event of an audit or legal proceeding.
The danger is compounded by the fact that employees using these tools are not acting maliciously. They are solving a real problem—the need to share files quickly and efficiently—with the tools they already know. The solution is not to shame individual behavior but to provide alternatives that are equally frictionless and genuinely secure.
Recent Incidents That Should Prompt a Reassessment
Several high-profile incidents in recent years illustrate what happens when remote file-sharing practices go unaudited. In one case widely reported in the US financial press, a financial services firm experienced a significant data exposure when a former contractor retained access to a shared folder on a consumer cloud platform months after their engagement ended. The firm had no process for revoking third-party access upon offboarding, and the folder contained client financial statements.
In another case involving a healthcare provider, an employee who had transitioned to remote work began routinely sending patient intake documents to a personal email address for printing at home. The practice went undetected for nearly eight months. When discovered, it triggered a HIPAA breach notification obligation affecting thousands of patients and initiated a federal investigation.
Neither of these incidents required a sophisticated attacker. Both were the direct result of workflow habits that had never been examined through a security lens.
Auditing Your Current File-Sharing Environment
The first step toward meaningful improvement is an honest assessment of how files are actually moving through your organization—not how your policies say they should move, but how they do. This requires direct engagement with employees rather than a review of IT documentation.
Ask your teams these questions:
- How do you typically send a document to a client or external partner?
- Where do you store files you are actively working on?
- How do you share large files that exceed your email size limit?
- What do you do when you need to access a work file from a personal device?
The answers will likely reveal a landscape more diverse—and more risky—than your IT team currently maps.
Establish a single approved platform for all file sharing and storage. The platform should offer end-to-end encryption, granular permission controls, link expiration capabilities, and a complete audit log of who accessed what and when. Critically, it should be easy enough to use that employees genuinely prefer it over their personal workarounds.
Build offboarding into your file governance process. Every time an employee or contractor leaves your organization, a checklist should exist that includes revoking access to shared folders, recovering any files stored in personal accounts, and confirming that no sensitive documents remain in communication threads outside your controlled environment.
Educate without lecturing. Security awareness training that focuses on consequences rather than rules tends to produce more durable behavioral change. When employees understand why a personal messaging app creates liability—not just that it violates policy—they are more likely to adopt better habits voluntarily.
Security That Keeps Pace With How People Actually Work
The goal is not to make file sharing more difficult. It is to make secure file sharing the path of least resistance. When the tools your organization provides are faster, more reliable, and more capable than the consumer alternatives employees are currently using, the compliance problem largely solves itself.
Remote work is not a temporary experiment. For millions of American professionals, it is the permanent structure of their careers. The organizations that thrive in this environment will be those that have built file-sharing infrastructure worthy of the trust their clients, partners, and regulators place in them—not those still relying on the assumption that their teams are being careful.