cyber&
Back to Resources

How to share files and sensitive information safely

Verify the need and recipient, minimize the data, and keep control of access before and after sharing.

Start with the situation

A technically secure channel can still deliver too much information to the wrong person. Safe sharing begins before choosing encryption or a link setting.

The decision to make

Confirm the need, recipient, minimum data, approved channel, and access lifetime—then check what was actually shared.

A practical sequence

  1. Check that the recipient is authorized and needs the information for this task.
  2. Share only the required fields, pages, records, or time range. Remove credentials and secrets entirely.
  3. Re-check addresses and attachments, especially autocomplete results and external domains. Use an approved service.
  4. Prefer named, authenticated recipients; choose the least permission needed; prevent resharing and set expiry where supported.
  5. Confirm the final link or attachment, review access after the task, and remove it when no longer needed.

Real-world examples

  • Send a view-only link to named recipients instead of an unrestricted public link.
  • Share an extract containing the requested records, not the entire customer file.
  • Use an approved secret-sharing mechanism rather than placing a password or API token in chat or email.

Common mistakes

  • Assuming encryption proves the recipient or justifies the sharing.
  • Selecting “anyone with the link” because it is quicker.
  • Uploading sensitive work data to an unapproved file or AI service.
  • Ignoring accidental sharing instead of revoking access and reporting promptly.

What to do next

If the wrong person or service received access, restrict or revoke it where possible, preserve the details, and report the exposure promptly.

The safest share is specific: the right data, person, permission, channel, and duration.

Trusted official references

  • UK NCSC

    Using Software as a Service securely

    Guidance on named recipients, least access, sharing controls, revocation, and unintended disclosure.

    View official source
  • NIST

    Privacy Framework

    A framework for managing privacy risk across the collection, use, sharing, and protection of information.

    View official source