forumNew topic

File sharing on Google Drive or OneDrive: Is it risky if we don't check who has access? How to manage it?

DDilara A***25 days ago·84 messages·3.5K viewsClosed#sharing#cloud#access
DDilara A***Member
Job title
Data Analyst
Sector
Sports and fitness
Organization type
120-person company
Joined
Aug 2023
Message
113

Doki · Infrastructure migration · 2024

#1

Our team shares files on Google Drive, but we often forget to check who can access them. Can former employees still see them? Won't client files get lost?

KKadir G***MemberCommunity member
Joined
Sep 2022
Message
44
Most Helpful#2

File permissions should be audited regularly. Check files set to 'Anyone with the link'. Do a monthly permission audit.

İİlker Ö***Expert
Job title
Store associate
Sector
Furniture manufacturing
Organization type
family business
Joined
Jul 2022
Message
9
#3

it's terrifying if a separated employee still has access to files... anyway we had this issue too we checked all the files

DDoruk G***New memberCommunity member
Joined
Jun 2026
Message
8
#4

File sharing policy: 1. Require specifying who to add 2. Monthly permission audits 3. Remove former employees 4. Set up company accounts

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#5

You can find public files using the 'Shared Drive Report' in Google Admin Console. Take precautions.

IIrmak B***Member
Job title
Customer service representative
Sector
Machinery manufacturing
Organization type
sole proprietorship
Joined
Mar 2024
Message
155

Doki · Brand identity · 2025

#6

company file policy should exist... never select 'everyone', it should be specific people

ÜÜlkü O***MemberCommunity member
Joined
Mar 2024
Message
14
#7

it's rare to find an explanation this clear.

RRamazan Y***Member
Job title
Co-founder
Sector
Food wholesale
Organization type
two-branch business
Joined
Feb 2026
Message
13
#8

Could you elaborate on that? Forgotten test environments are more often the entry point than live systems.

Good luck with that.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#9

There's a trap here, let me mention it. If 2FA is on, a stolen password alone is useless.

This is my opinion, I'm not claiming it's absolute truth.

KKübra Ö***Member
Job title
Front office accounting
Sector
Real estate
Organization type
two-branch business
Joined
Jul 2024
Message
155
#10

the discussion got scattered let me summarize.. then the real issue isnt the number, but what its based on.

MMehmet Y***Member
Job title
IT manager
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Oct 2024
Message
4
#11

Following.

HHasan E***Expert
Job title
Content Editor
Sector
Construction
Organization type
family business
Joined
Dec 2023
Message
88
#12

youre right Ive been down that road too but if the notiication path is long notifications dont arrive; missing notifications mean delayed incident detection.

AAleyna S***Member
Job title
Export manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Aug 2024
Message
3
#13

There are three things to check when doing this. When we decide without measuring, we always end up in the same place.

If permission and scope aren't in writing, don't start that test. Proven by experience.

ZZehra D***Veteran
Job title
Courier coordinator
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Jun 2023
Message
80
#14

I've been down this road, let me tell you. When you try to change everything at once, nothing settles.

Your time to detect an issue directly determines its cost. That's all, sorry if I went on too long.

IIrmak B***Expert
Job title
Finance Manager
Sector
Logistics
Organization type
a company within a holding
Joined
Jul 2023
Message
150
#15

There's a common mistake people make when doing this. An automated scan report is not the same as a penetration test.

If 2FA is on, a stolen password alone is useless.

VVolkan C***Member
Job title
Digital marketing specialist
Sector
Cleaning services
Organization type
family business
Joined
Jun 2024
Message
224

Doki · KVKK compliance consulting · 2024

#16

This is exactly what we experienced. Your time to detect an issue directly determines its cost.

Having backups accessible on the same network and with the same identity makes them part of the target. Proven by experience.

FFurkan U***MemberCommunity member
Joined
Apr 2023
Message
163
#17

Exactly, and not many people know this. If 2FA is on, a stolen password alone is useless.

The harder it is to reverse a decision, the slower you should make it. This is my opinion, I'm not claiming it's absolute truth.

KKadir E***Member
Job title
Administrative manager
Sector
Logistics
Organization type
a company within a holding
Joined
Jul 2024
Message
10
#18

I'll try it.

LLevent A***MemberCommunity member
Joined
Feb 2022
Message
7
#19

Same here.

EErcan Ç***Member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Aug 2023
Message
57
#20

The opposite happened to me, that's why I'm writing. Start with a small trial; don't commit to everything at once.

If 2FA is on, a stolen password alone is useless. like just leaving this note, it might be useful.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic