Skip to content
The Cyber Security Place

Expert Articles

6 Security Tips for Cloud File Sharing

Reported by digitaltrends.com

By Devin Partida, writer, blogger and Editor-in-Chief at ReHack.com

Cybersecurity should be a major concern for everyone. Whether someone is uploading family photos or sensitive enterprise documents, people must know how to safeguard their digital information and data.

One of the best ways to accomplish that goal is to trust a reliable cloud storage service . For working with collaborative documents, cloud file-sharing services are an excellent solution, too. They’re always updating software, upgrading hardware and staying on the bleeding edge of what’s possible for cyber-defenses.

However, just because something is more secure, that doesn’t mean there are no vulnerabilities. When dealing with cloud solutions and data storage, everyone should be aware of these cybersecurity issues.

There are two layers to understanding cybercrime and digital attacks. The first involves identifying and learning how those attackers gain access to sensitive information and systems. The second is what hackers are looking for and how they might use it.

For example, a database full of emails and basic contact info may not seem all that sensitive. Still, attackers can use those details for a lot — like gaining access to additional accounts, gleaning passwords and much more.

Users should take steps to educate themselves on common attacks and how cybercriminals carry them out. Here, training is crucial to learn how to spot attack vectors and understand how to minimize damage if and when events happen. The Department of Homeland Security offers some excellent training opportunities .

A social-engineering tactic called phishing involves preying upon people’s sensibilities. Someone might pretend to be a fellow employee to gain access to a building, for example. Another might contact a customer support team with their victims’ private details, using information like birthdates and Social Security numbers to gain access. Hackers might set up a clone website specifically designed to collect sensitive information from unsuspecting people, like accounts, passwords and credit card details.

Phishing attacks can happen through channels like email, websites and social media platforms. Gullible people may inadvertently provide sensitive information or even direct access to cloud accounts and platforms.

To avoid potential attacks, internet users must learn how to spot phishing and put an anti-malware tool in place. That includes vetting emails to ensure they are coming from trusted and reliable addresses.

Phishing attacks are one of the most common cybersecurity events U.S. health care providers experience. If hackers are targeting the health care industry, it’s likely they’re also going after sectors like retail and finance.

Complex, hard-to-guess passwords are critical to maintaining account security.

All passwords should contain the following:

The need to create complicated, unique passwords for each online account also makes them challenging to remember. Secure password managers like LastPass or Enpass can create and save unique codes.

From smartphones to workplace terminals, it’s essential to lock down access and only allow authorized users and devices. In a bring-your-own-device environment, this task is challenging, but not impossible.

No users should be accessing cloud files from unauthorized apps, services, portals or devices. Logging and monitoring all access can identify potential security concerns. That way, an IT department will have ample time to react if unauthorized parties somehow gain access. It affords plenty of time to lock out users and terminals, stopping data breaches or worse.

While it may seem like this is a cloud provider issue only, that’s not the case. The reality is likely the opposite, where unauthorized people access data from the client side, instead of the host side. Employees sharing work computers with outside users is also a risk.

This security tip also covers tools and third-party apps, aka plugins. Many cloud services allow synchronization with other apps and services. File-sharing services like Egnyte or OneDrive for Business are enthusiastic proponents of external apps and authorization.

Users upload content to the cloud for a reason, whether it’s collaborative or not, so those files should remain in the cloud and secure. Employees and partners should not be able to download content, nor should they be moving it to removable USB drives, external drives or various outside accounts. When acquiring a local file is necessary, only authorized users should carry out the process.

Avoiding local files and the connection of USB drives will vastly improve security. With this approach, there won’t be any copies of sensitive content floating around. Even encrypted drives can pose a risk.

Sharing files via email creates a cascade of vulnerabilities. That’s especially true of financial or personally sensitive documents that require a signature or verification. Email has never aimed to be secure . The way the technology works — or, rather, how email clients transfer data — makes it easy for resourceful hackers to access emailed information.

Users should take steps to encrypt files before uploading them to the cloud. Moreover, employees should be sharing access to content hosted through secure sharing services, not the files themselves.

In addition to these six tips, organizations and employees can take a few extra steps to avoid security issues when using cloud file-sharing services.

Luckily, many of these solutions are already available through various cloud services because providers must bolster and maintain security. Even when a feature is not available, it’s possible to work with a cloud provider to improve or establish the necessary precautions.

Read the full article at digitaltrends.com