Call NowFree Quote
Best Practice

How to Share Files Securely in Your Perth Business

File sharing is something every Perth business does dozens of times a day - internally between staff, and externally with clients, suppliers, and partners. But the way most businesses share files creates unnecessary security risk and compliance exposure. Here's how to do it properly.

Common File Sharing Mistakes

These methods are widespread in Perth businesses but each carries specific risks:

Emailing files as attachments

Email is unencrypted in transit by default and sits permanently in both the sender's and recipient's email accounts - often in multiple devices and backups. A large contract, financial report, or client data file sent by email is a copy of that data you have permanently lost control over. If the recipient's email account is compromised in future, those files are accessible.

Email also has file size limits that lead staff to use workarounds - WeTransfer, personal Dropbox, or Google Drive - that are outside your organisation's control entirely.

Personal cloud storage (personal Dropbox, Google Drive)

When staff use personal Dropbox or Google Drive accounts to share work files, that data is now in a consumer cloud service governed by the staff member's personal account. When they leave, so does the file. You have no visibility, no access controls, and no audit trail. For businesses handling client data under the Privacy Act, this is a compliance problem.

USB drives

USB drives are physically portable, which means they are also physically losable. An unencrypted USB drive containing client financial records left in a car or cafe is a data breach. USB drives also transfer malware between computers - plugging an unknown USB into a business computer is a well-documented attack vector.

Network shares without access controls

A Windows file server with a shared drive that everyone has full access to is not file sharing with controls - it is a flat repository where any staff member (or any attacker who has compromised a staff account) can access, copy, or delete everything.

The Right Approach: Internal File Sharing

Microsoft SharePoint and OneDrive (Microsoft 365)

For businesses on Microsoft 365, SharePoint and OneDrive are the correct internal file sharing tools:

  • OneDrive - personal work files. Files a staff member works on individually, synced to their device and backed up automatically. Can be shared with specific colleagues when needed.
  • SharePoint - team files. Shared document libraries organised by department, project, or function. Access controlled by SharePoint permissions - only the right people see the right content.

Both sync locally so files are available offline and open at full speed. Both have version history so accidental overwrites are recoverable. Both integrate with Teams - files shared in a Teams channel are stored in SharePoint automatically.

SharePoint permissions should be configured by IT - not left at the default "everyone in the organisation can access everything." A law firm's client files should not be visible to reception staff; a finance team's payroll folder should not be visible to the general office.

The Right Approach: External File Sharing (With Clients and Partners)

SharePoint and OneDrive sharing links

SharePoint and OneDrive both allow secure external sharing via links. Options:

  • Anyone with the link - the link works for anyone, no sign-in required. Can be set to expire after a specific date and can be password-protected. Good for sharing non-sensitive documents with clients who don't have Microsoft 365 accounts.
  • Specific people - the recipient must sign in with their own Microsoft account (personal or work) to access the file. Provides an audit trail of who accessed the file and when. Best for sensitive documents.

Sharing links can be revoked at any time - giving you control over access even after the file has been shared.

Encrypted email for sensitive documents

For sensitive documents that must be sent by email - signed contracts, financial statements, legal documents - Microsoft 365 Message Encryption (included with Business Premium) encrypts the email and attachment. The recipient receives a link to view the document in a secure browser rather than receiving an unencrypted file.

Client portals

Professional services firms (accountants, lawyers, financial planners) benefit from a dedicated client portal - a secure, branded environment where clients access their documents. Options include Xero's client portal (for accounting firms), ShareFile, and Microsoft SharePoint with external user licences configured as a client portal.

Configuring SharePoint Sharing Settings

By default, Microsoft 365 may allow sharing with anyone externally or restrict it entirely. Your organisation's SharePoint sharing settings should be reviewed and configured explicitly:

  • Set the default sharing link to "Specific people" rather than "Anyone with the link"
  • Set link expiry - external sharing links should expire after 30 days by default
  • Restrict external sharing to specific domains if you regularly share only with specific partners (e.g. your accounting firm, your legal firm)
  • Require re-authentication for external users after a defined period
  • Enable access reports so you can see who has accessed shared files

Handling Large Files

When files exceed email attachment limits, the answer is SharePoint or OneDrive sharing links - not WeTransfer or personal cloud storage. SharePoint handles files up to 250GB per file and OneDrive handles files up to 250GB, so there is no practical file size limit that requires a workaround.

Frequently Asked Questions

Is it okay to email a file to a client if it's just a one-off?

It's best avoided where possible, even for a one-off, because that copy sits permanently in both inboxes and often in backups you don't control. For anything sensitive, a SharePoint or OneDrive sharing link with an expiry date is safer and just as quick to send, and you can revoke it later if you need to.

What's wrong with staff using their own Dropbox or Google Drive for work files?

Once a file is in someone's personal cloud account, your business has no visibility, no access controls, and no audit trail over it, and if that person leaves, the file effectively leaves with them. It can also create compliance concerns for businesses that handle client data, so it's worth checking your own obligations here rather than assuming it's fine.

Are SharePoint and OneDrive secure enough for sensitive documents?

Yes, when the sharing settings are configured properly, they're built for exactly this. Setting the default link type to "specific people" rather than "anyone with the link," adding expiry dates, and enabling access reports gives you a level of control and audit trail that email and consumer cloud storage simply can't match.

How should we send truly sensitive documents like signed contracts?

If it has to go by email, Microsoft 365 Message Encryption (included with Business Premium) encrypts the message and attachment, and the recipient opens it via a secure link rather than a plain file. Otherwise, a SharePoint or OneDrive link set to "specific people" gives you a proper audit trail of who opened it and when.

We configure SharePoint, OneDrive, and external sharing policies for Perth businesses - so your team shares files securely without workarounds.

Microsoft 365 Services →

Is your Perth business sharing files securely?

Call 0433 087 091 - we'll review how your team shares files and configure SharePoint and OneDrive so it is done correctly.

Book a Free Assessment

For related reading, see our guides to Email Security for Perth Businesses and MFA Setup for Perth Businesses.

Share this article