Module 5 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: why most data leaks are accidents rather than attacks, how to scope OneDrive and SharePoint sharing links (people you choose, view versus edit, expiry dates), the data that never leaves work systems including public AI chatbots, and the fast, honest response when a file reaches the wrong person.
Sharing Work Files Without Leaking Them
Most leaks are accidents
Most data leaks are not break-ins at all. Nothing was hacked and nothing was forced. Most of the time, the data walked out the front door because someone helpful, busy and entirely well-meaning held it open. No malice, no drama, just a slightly rushed click ten minutes before a meeting.
That is genuinely good news, because accidents have patterns, and patterns can be trained away. Here are the four classics. If you have worked in an office for more than a year, at least one of these will feel uncomfortably familiar.
The wrong Sarah
You type "Sar", autocomplete helpfully offers Sarah, and you hit send. Except it picked Sarah the former supplier, not Sarah in accounts. The payroll summary is now sitting in an inbox it was never meant to visit, and no amount of staring at your screen will bring it back.
The link that never dies
Back in 2023 someone shared a pricing spreadsheet with "Anyone with the link" to save time before a meeting. That link still works today. It works for the person who left last year, for whoever they forwarded it to, and for anyone who finds it in an old email thread.
The buried reply
A client asks a quick question, so you forward them the internal thread with the answer at the top. Five replies down, your colleague was candid about the client's budget and someone's salary got mentioned. Nobody scrolled before hitting send. The client will.
The spreadsheet with a secret
You send one customer their order history, neatly filtered on the first tab. The hidden tab behind it holds every customer, every price, every margin. Hidden is not deleted. Anyone curious enough to right-click gets the lot.
The OAIC, Australia's privacy regulator, publishes regular reports on notifiable data breaches. In its July to December 2024 report, roughly three in ten reported breaches came down to human error, and the single most common mistake was personal information emailed to the wrong recipient. Not sophisticated attacks. The wrong Sarah, at scale, across the whole country.
Every time you hit Share in OneDrive or SharePoint, you are answering three small questions, whether you notice them or not. Who can open this? Can they change it, or just read it? And for how long? Answer them on purpose and you are sharing safely. Let the defaults answer for you and you are rolling dice.
The big one is the first setting in the share window. "Anyone with the link" means exactly that: anyone, forever, including everyone it gets forwarded to. "People you choose" means the file checks who is knocking before it opens. For anything work-related, people you choose should be your reflex, and for external links, set an expiry date while you are in there. It takes four seconds.
- "Anyone with the link" because it was the first option offered
- Edit access for everyone, since choosing felt like effort
- No expiry date, so the link outlives the project, and possibly the business
- An attachment copy also emailed "just in case", now floating around forever
- "People you choose", with the recipient's actual email address
- View access, upgraded to edit only if they genuinely need to change it
- An expiry date on the external link, so access ends when the job does
- One live copy in OneDrive or SharePoint that you can switch off later
An email attachment is a photocopy you can never get back. It lands in their inbox, their downloads folder, their backup, and wherever they forward it next, and every copy is yours to worry about and impossible to recall. A properly scoped link is different: there is one live copy, it always shows the latest version, you can see who has access, and the moment the work is done you can switch it off. In Outlook and Teams, sharing a link to the file in OneDrive does exactly this, and it is usually the default for a reason.
Some information simply does not leave the business's own systems, ever, regardless of how convenient the shortcut looks late on a Friday afternoon. It is a short list, and it is worth knowing cold.
- Client and customer records, including names, contact details and order history
- Payroll, salaries, HR files and anything about a colleague's employment
- Passwords, keys, door codes and anything that opens something else
- Pricing, margins, contracts and anything a competitor or criminal would love
And the doors it must never leave through, even when the approved way is testing your patience:
Forwarding work files to your own Gmail to "finish at home" moves them outside every protection the business has. If your personal account is ever compromised, the work data goes with it.
Small, unencrypted, and famously good at living in pockets, glove boxes and washing machines. If a client list is on it when it goes missing, that is a data breach, not a lost stick.
The free transfer site you used because SharePoint felt slow that day is now holding your work data under someone else's terms, in someone else's country, with no way for your business to get it back.
Pasting a client contract into a free public chatbot to summarise it feels harmless, but you have just handed that contract to a service the business has no agreement with, and you cannot un-paste it. The Australian Cyber Security Centre's guidance on AI says much the same: know where your data goes before you type it in. If your business provides a protected AI tool, one that runs under a work sign-in with business data protections, use that one. If it does not, sensitive data and public chatbots simply do not mix.
Honestly, most workarounds start with a real problem: the approved tool was slow, the file was too big, the deadline was tonight. If the safe way is genuinely getting in your way, tell IT. That is a fixable problem, and a five-minute conversation. Quietly routing around it is how a slow afternoon becomes a breach report.
It will happen eventually, to you or to someone near you. The email leaves, your stomach drops, and your cursor hovers over that tempting Recall button in Outlook. Time for some honesty about what actually works.
Outlook's recall works reliably only inside your own organisation, and even then only in certain conditions. Outside it, to a client or a stranger on Gmail, the message is simply theirs now, and the recall attempt often just sends a second email announcing you made a mistake. Do not spend your first five minutes on it.
Kill the link. If you shared a link, open Manage Access on the file in OneDrive or SharePoint and remove or expire it. A dead link means the mistake ends there, no matter who the email reached.
Change what it points to. If the link has to stay alive for the right people, move or fix the file behind it. Remove the sensitive tab, replace the document, tighten who is on the access list.
Tell IT or your manager, immediately. This is the step that actually matters. IT can revoke access, check whether the file was opened, and handle any obligations that follow. None of that can start until someone knows.
A wrong-recipient email reported in five minutes is usually a non-event: link revoked, recipient asked to delete, everyone moves on. The same mistake sat on for a week out of embarrassment is a genuine incident. Nobody worth working for punishes the person who put their hand up quickly. Module 6 covers those first five minutes for every kind of "something looks off", and this is a preview of its one big rule: tell someone, fast.
- OAIC: Notifiable data breaches
- OAIC: Notifiable data breaches publications and statistics
- Australian Cyber Security Centre: Artificial intelligence
- Australian Cyber Security Centre: Report a cyber security incident
Details were current at the time of writing (July 2026). The OAIC publishes new breach statistics every six months, so check the links above for the latest figures.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. You need to send last quarter's financials to your external accountant, and only to her. What is the right way to share the file?
2. What is the actual problem with an "Anyone with the link" share?
3. You have just emailed a client's payroll file to the wrong external address. What is your first move?
4. You want a quick summary of a long client contract, but the work systems feel slow today. What is the safe move?
5. Why is a properly scoped sharing link better than sending the file as an email attachment?