Module 5 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: why most data leaks are accidents rather than attacks, how to scope OneDrive and SharePoint sharing links (people you choose, view versus edit, expiry dates), the data that never leaves work systems including public AI chatbots, and the fast, honest response when a file reaches the wrong person.

    Sharing Work Files Without Leaking Them

    Module 5 · DataUnit 1 of 5 · about 2 min

    Most leaks are accidents

    Most data leaks are not break-ins at all. Nothing was hacked and nothing was forced. Most of the time, the data walked out the front door because someone helpful, busy and entirely well-meaning held it open. No malice, no drama, just a slightly rushed click ten minutes before a meeting.

    That is genuinely good news, because accidents have patterns, and patterns can be trained away. Here are the four classics. If you have worked in an office for more than a year, at least one of these will feel uncomfortably familiar.

    The wrong Sarah

    You type "Sar", autocomplete helpfully offers Sarah, and you hit send. Except it picked Sarah the former supplier, not Sarah in accounts. The payroll summary is now sitting in an inbox it was never meant to visit, and no amount of staring at your screen will bring it back.

    The link that never dies

    Back in 2023 someone shared a pricing spreadsheet with "Anyone with the link" to save time before a meeting. That link still works today. It works for the person who left last year, for whoever they forwarded it to, and for anyone who finds it in an old email thread.

    The buried reply

    A client asks a quick question, so you forward them the internal thread with the answer at the top. Five replies down, your colleague was candid about the client's budget and someone's salary got mentioned. Nobody scrolled before hitting send. The client will.

    The spreadsheet with a secret

    You send one customer their order history, neatly filtered on the first tab. The hidden tab behind it holds every customer, every price, every margin. Hidden is not deleted. Anyone curious enough to right-click gets the lot.

    This is not a niche problem

    The OAIC, Australia's privacy regulator, publishes regular reports on notifiable data breaches. In its July to December 2024 report, roughly three in ten reported breaches came down to human error, and the single most common mistake was personal information emailed to the wrong recipient. Not sophisticated attacks. The wrong Sarah, at scale, across the whole country.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?