Who Else Can See Your Files? The Cloud Sharing Mistake Small Businesses Keep Making
Most owners I talk to picture a break-in when they think about a data leak. Someone in a hoodie, cracking a password, forcing their way in. That’s the movie version. The version I actually see in Southern Arizona is quieter and a lot more embarrassing: nobody broke in at all. A file was shared with “anyone with the link” three years ago, and it’s been sitting open on the internet ever since.
New research out this month makes the point better than I can. A security firm reviewed cloud misconfiguration data from 3,000 organizations across Amazon, Microsoft, and Google’s cloud platforms. Weak access controls showed up in 80% to 98% of accounts, depending on the provider. That is not a handful of careless companies. That is nearly everybody.
The problem isn’t hackers. It’s settings.
“Misconfiguration” is a technical word for something very ordinary: a switch that got flipped for convenience and never got flipped back. Your team needed to send a big proposal to a client, so somebody turned on public sharing. It worked. Everyone moved on. The switch stayed on.
The reason this matters more than it used to is that criminals have stopped guessing passwords and started looking for open doors. It is cheaper to scan the internet for exposed files than it is to attack a business head-on. If your quotes, payroll records, or client contracts are reachable without a login, you never get an alert. There is no alarm for a door you left unlocked on purpose.
Three ways files leak without anyone breaking in
The link that never expires
In Microsoft 365, Google Drive, and Dropbox, the fastest way to share something is a public link. It’s one click, and by default that link usually has no expiration date. The project ends, the client relationship ends, the employee who created it leaves — and the link keeps working.
The account that outlived the employee
When someone leaves, most small businesses remember to turn off email. Far fewer remember the shared drive, the accounting portal, the file-sync app still installed on a personal laptop. I have audited businesses where a person who left two years earlier could still open the company’s financial folder from home.
Everybody is an administrator
This one is almost always accidental. It’s faster to give a new hire full access than to figure out what they actually need. Multiply that by five years of hiring, and now a single stolen password opens every file you own instead of one folder.

Why this is worth an hour of your week
Ransomware crews changed their business model. They used to just lock your files and demand payment. Now they copy your data first, then lock it, then threaten to publish what they took. Good backups still get you running again — and you should absolutely have tested, off-site backups — but backups don’t un-publish your client list.
That changes the math. A leaked folder isn’t just an IT headache. It’s a phone call to every customer in that folder. And it rarely starts with anything dramatic: in most of these cases the attackers simply used credentials that were already exposed. It’s the same pattern I wrote about when a vendor breach put client data at risk — the weak point was access nobody was watching.
What you can do this week
- Pull your sharing report. Microsoft 365 and Google Workspace both let an admin list every file shared publicly. Run it once. Most owners are genuinely surprised by what comes back.
- Kill the public links you don’t need. Anything older than a finished project should be switched to named-people-only. Set new links to expire in 30 days by default.
- Write a five-line offboarding checklist. Email, shared drive, accounting software, password manager, company device returned. Five lines beats a perfect policy nobody follows.
- Count your administrators. A business with ten employees does not need six admins. It needs two, and everyone else gets what their job requires.
- Spend fifteen minutes with your team. Show them the difference between “share with Maria” and “share with anyone.” Short, practical security awareness training prevents more leaks than any product I can sell you.
The bottom line
You do not need a bigger security budget to fix this. You need an afternoon and someone willing to look. The businesses that get hurt aren’t the ones with weak technology — they’re the ones where nobody ever checked who still has the keys. Layer in endpoint protection and email filtering on top of clean permissions, and you’ve closed the doors attackers actually use.
If you’d rather not go digging through admin menus yourself, that’s fair. It’s what we do. More plain-English guidance is on our blog.
Not sure who can see your files?
We’ll review your cloud sharing settings, user accounts, and admin rights, then hand you a plain-English list of what to fix. No jargon, no pressure.
Want the bigger picture on protecting your company? Start with our small business cyber security solutions.
Send us a message
Have a question about your cloud setup, or want a second opinion on who has access to what? Send it over and I’ll answer personally.
— Nemuel Cruz, Incognito Cyber Security


