Reviews

Part of Office suites: a clear guide with practical examples

Office suites security: risks, controls and a 2027 checklist

A practical 2027 guide to office suites security: risks, controls and a 2027 checklist with current definitions, decisions, checks, and review steps.

Almost nothing that leaks out of a document store is stolen. It is shared, correctly, by somebody who meant to, with a setting that was wider than they realized or that stayed true long after the reason for it ended.

That reframes the whole subject. Encryption is not where your risk is. Your risk is in link permissions, in what is hiding inside the files themselves, and in what happens to a departing colleague's documents. All three are within your control and none of them appear in a security feature list.

What to take away

  • Sharing is the security model. Everything else in this category is secondary to who can open a file and for how long.
  • A link granted once stays granted. Without an expiry or a review, access accumulates for as long as the organization exists.
  • Documents carry more than what is on the page. Tracked changes, comments, hidden rows, and cropped images travel with the file.
  • Synchronized storage copies damage as faithfully as it copies work. Version history, not the sync, is what gets you back.

The four kinds of access, and how long each lasts

Every suite offers roughly the same set. They differ enormously in how long they remain true.

Named people. Access granted to specific accounts. The most durable and the most manageable, because it can be reviewed and it ends when the account does.

Anyone in the organization. Convenient, and quietly means every future employee too. Fine for material that is genuinely internal and public; wrong for anything sensitive, because the population it describes grows without anyone deciding.

Anyone with the link. The link is the credential. It can be forwarded, pasted into a chat, included in a message that is later forwarded to somebody else, and indexed if it ends up anywhere public. Treat every one of these as permanent unless you set an expiry.

Anyone, publicly listed. Rare and occasionally correct. Should be a deliberate act with a named owner.

Two settings make the difference between a manageable estate and an unmanageable one: whether links can be created with an expiry date, and whether an administrator can see every link that currently exists. If your suite offers the second, use it quarterly. Most organizations have never looked, and the first look is always instructive.

None of the four is unusual, and the reason they accumulate is that granting access is somebody's job and removing it is nobody's. The guidance on identity and access management is a short statement of the habit that prevents it.

The review nobody schedules

Access accumulates in one direction. Nothing removes it, because removal is somebody's job and it is nobody's job.

A workable review is short. Once a quarter, look at:

  • Documents shared outside the organization, and whether each still needs to be.
  • Guests and external accounts with any standing access, and when each last opened anything.
  • Team spaces whose membership no longer matches the team.
  • Anything shared with a link that has no expiry.
  • Files owned by accounts that are suspended or gone.

Assign it to one person, put it in a calendar, and keep the list of what you removed. The list is what turns the next review into ten minutes instead of an afternoon, and it fits alongside the joiner and leaver process rather than being a separate exercise.

What travels inside the file

The document you send contains more than what you see when you open it.

  • Tracked changes and comments, including the ones about the recipient.
  • Hidden rows, columns, and sheets, which are hidden from view and not from anyone willing to unhide them.
  • Filtered data, where the rows outside the filter are still present in the file.
  • Cropped images, where the cropped part is often still in the file and can be restored.
  • Speaker notes in a presentation.
  • Document properties, including author names, the machine or organization that created it, and edit history.
  • Embedded objects, such as a whole workbook sitting inside a report, carrying everything its own sheets contain.
  • Links to internal locations, which tell a reader more about your structure than you intended.

The standard advice is to publish in a fixed format instead, and that only works if the conversion actually flattens the content. Some do, some carry properties and hidden material through, and some carry an embedded copy of the original. Test yours: produce a fixed format file from a document you know contains hidden material, then inspect the result rather than assuming.

Better still, build the check into the process. Anything leaving the organization gets a deliberate final step: accept or reject changes, delete comments, unhide everything and look, and inspect properties. Where the suite offers an inspection tool, run it, and where it offers a mode that strips this material on export, turn it on as described in your rollout defaults.

Sync, ransomware, and the restore path

Synchronizing storage is a replication system, not a backup. Anything that damages files on one machine is dutifully copied everywhere, and quickly. That is how these incidents usually unfold, and the plain account in ransomware guidance is a better specification for what to test than any feature list.

What actually protects you is the version history, and it protects you only if three things are true: the retention window is long enough that you notice within it, the restore can be done in bulk rather than file by file, and somebody knows how. Test all three before you need them, on a folder with several hundred files, because a restore mechanism that works on one file and not on a thousand is a mechanism that does not work.

Two related settings deserve a decision rather than a default. How much of the store syncs to each laptop, since a machine holding a complete copy of the organization's documents is a different kind of loss when it goes missing. And who may remove large numbers of files at once, since bulk deletion is usually an accident and always looks the same as an attack for the first hour.

When somebody leaves

This is where document security is either designed or improvised.

Decide in advance, and write it down: who inherits a leaver's documents, how long the account is retained before deletion, what happens to files they shared with outsiders, and who takes over any automation they built. If documents are owned by teams rather than individuals, most of this problem never arises, which is the strongest argument for that arrangement and the reason it belongs in the fit assessment rather than in an afterthought.

The failure to avoid is deleting the account promptly and correctly and losing the only copy of something. The reverse failure, keeping every leaver's account open indefinitely, is also real: it is standing access nobody is watching, and it appears on your bill.

Add ins, connections, and what they can reach

An add in installed by one person can often read documents that person can read, and sometimes more. A connection between the suite and another system holds a token that survives the password change nobody thought to pair it with.

Establish who may install what, whether an administrator can restrict the catalog, and where to see what is currently connected. Then review that list on the same schedule as your sharing review. The integration surface is the part of this category that most often grows without anyone deciding it should.

Common questions

Is document encryption worth using?

Password protecting an individual file is useful for a specific document sent by a specific route, and it introduces a key management problem you must solve before you rely on it. It is not a substitute for correct sharing, which is where the actual risk sits.

Can we stop people downloading or copying?

You can usually restrict download, printing, and copying. Understand what that achieves: it raises friction and it does not stop anyone who can see the screen from photographing it. Use those controls for the case they suit, which is reducing casual redistribution, and do not treat them as containment.

How do we know what is currently shared?

Look for an administrative report of external sharing and standing links. If your suite does not offer one, that absence belongs in your evaluation, and the feature checks are the right place to test for it.

What is the highest value change for a small team?

Team ownership of documents instead of individual ownership, an expiry on external links, and one quarterly review with a named owner. Those three remove most of what goes wrong here, and none of them cost anything.

More in Reviews

Rules

Best office suites software 2027: guide and criteria

A practical 2027 guide to best office suites software 2027: guide and criteria with current definitions, decisions, checks, and review steps.

Costs

Office suites features that matter for everyday work

A practical 2027 guide to office suites features that matter for everyday work 2027 with current definitions, decisions, checks, and review steps.

Features

Office suites pricing: plans, fees and buying questions

A practical 2027 guide to office suites pricing: plans, fees and buying questions 2027 with current definitions, decisions, checks, and review steps.

Latest from Value Desk

Maintenance

Best business email software 2027: practical details

A practical 2027 guide to best business email software 2027: practical details with current definitions, decisions, checks, and review steps.

Reviews

Business email migration: how to switch without losing data

A practical 2027 guide to business email migration: how to switch without losing data 2027 with current definitions, decisions, checks, and review steps.

Guides

Email hosting pricing: plans, fees and buying questions

A practical 2027 guide to email hosting pricing: plans, fees and buying questions 2027 with current definitions, decisions, checks, and review steps.

Maintenance

Office suites setup: a practical setup guide for 2027

A practical 2027 guide to office suites setup: a practical setup guide for 2027 with current definitions, decisions, checks, and review steps.