A link sent once, open forever
Someone needed to send a price list to a prospect, so they shared the folder with anyone who has the link. An accountant needed the year-end files, same again. A developer set up a storage bucket for website images and made it public, and later someone started putting customer exports in it too. A contractor was sent a SharePoint link to the HR folder to fix one document.
Each of those decisions made sense on the day. Nobody went back to close them. Now nobody knows how many files anyone on the internet could open with the right link.
Why public links pile up
- The default sharing setting in the tool allows anyone-with-the-link sharing, so it is the easiest option.
- Sharing outside the company properly (named guests, access requests) feels slower than copying a link.
- Links do not expire unless someone sets an expiry.
- Folders are shared rather than single files, so everything added later is shared too.
- Cloud storage buckets are created by developers with public access for one purpose and reused for others.
- When staff leave, the links they created stay open.
The folder point is the one that tends to surprise people. A folder shared publicly for one document keeps sharing every new document added to it, years later.
What is at risk
| Exposed item | Why it matters |
|---|---|
| Customer lists and exports | Personal data open to anyone who finds or is forwarded the link |
| Contracts, pricing and proposals | Commercially sensitive information in competitors' reach |
| HR and payroll files | Staff personal data exposed |
| Public storage buckets | Automated scanners look for open buckets and download their contents |
| Forwarded links | A link in one email can end up anywhere |
Links are not as private as they seem. They get forwarded, pasted into chats, saved in browser histories and sometimes indexed. And an exposure of personal data can carry reporting obligations under data protection law, which is a far worse way to find out about it.
How we find and close public sharing
- Inventory where files live: SharePoint and OneDrive, Google Drive, Dropbox or Box, and cloud storage such as Amazon S3 or Azure Blob Storage.
- Report on external sharing. We use the admin reporting in Microsoft 365 and Google Workspace, and the cloud provider's access analysis for buckets, to list every file and folder shared publicly or with outside accounts, with who shared it and when.
- Review with the owners. Each exposed item is checked with the person or team responsible: keep it shared, switch it to named people, or close it.
- Close what should not be public, starting with anything holding personal or sensitive data, and block public access at the account level for cloud storage that never needs it.
- Change the defaults. Default sharing becomes internal or specific people, anyone-with-the-link is restricted or given an automatic expiry, and external sharing for sensitive sites and folders is switched off.
- Give people an easy safe route: guest access for regular partners, and a clear way to share one file with one person, so nobody feels the need to work around the rules.
- Keep watching. Alerts for new public links on sensitive areas, and a regular review of external sharing, so it does not build up again.
We keep this proportionate. Many public links are harmless, such as marketing brochures. The aim is to close what matters without stopping people sharing the things they need to.
After the clean-up
You know what is shared outside the business and why. Sensitive files are no longer one forwarded link away from a stranger. New sharing defaults to named people, and public links expire on their own. Storage buckets that should be private are blocked from being made public by accident. And when someone leaves, their shared links are part of the leaver checklist.
Could this be you?
- Staff routinely share files with anyone who has the link.
- Nobody has reviewed external sharing in your Microsoft 365 or Google Workspace.
- Whole folders have been shared with customers, suppliers or contractors.
- Developers have created cloud storage buckets with public access.
- Former employees' shared links have never been checked.