﻿{"id":2025,"date":"2026-08-25T14:18:49","date_gmt":"2026-08-25T08:48:49","guid":{"rendered":"https:\/\/blogs.infosys.com\/engineering-services\/?p=2025"},"modified":"2026-08-25T14:18:49","modified_gmt":"2026-08-25T08:48:49","slug":"security-challenges-in-cloud-based-collaboration","status":"publish","type":"post","link":"https:\/\/blogs.infosys.com\/engineering-services\/unified-communications\/security-challenges-in-cloud-based-collaboration.html","title":{"rendered":"Security Challenges in Cloud Based Collaboration"},"content":{"rendered":"<h2>Why digital workplaces are a major attack surface<\/h2>\n<p>A few years ago (2021), <a href=\"https:\/\/edition.cnn.com\/2021\/06\/10\/tech\/electronic-arts-hack\">attackers broke into a major game studio<\/a> (EA Games) not through a firewall, but through its chat tool.<\/p>\n<p>They bought a stolen Slack cookie for about ten dollars, used it to impersonate an employee, convinced IT to reset a token, and quietly pulled hundreds of gigabytes of source code (780GB) and tools.<\/p>\n<p>Nothing \u201cspecial\u201d happened; no zero\u2011day, no exotic malware. The only thing that changed was \u201cwhere the work lived\u201d, i.e., in cloud collaboration rather than an on-premises or hosted collaboration data center.<\/p>\n<p>This is the operating landscape for modern digital workspace businesses. The projects, logs, code, credentials, and client conversations increasingly live in SaaS platforms like Webex, Teams, Slack, Zoom, Jira, and Confluence. These tools make us faster and more distributed, but they also create one of the most attractive attack surfaces we have.<\/p>\n<p>This article focuses on the \u201ctechnical\u201d security challenges of cloud\u2011based collaboration and what \u201cgood\u201d looks like in a service\u2011based business.<\/p>\n<h2>Identity is the new perimeter<\/h2>\n<p>Collaboration tools don\u2019t care whether you\u2019re on the corporate LAN or your home\/ public Wi\u2011Fi; if you can log in, you\u2019re \u201cinside\u201d. That shifts the main risk from firewalls to identity:<\/p>\n<ul>\n<li><span style=\"text-decoration: underline\">Stolen or misused credentials;<\/span> Studies of SaaS breaches consistently show that stolen passwords, tokens, and cookies are a more common root cause than platform\u2011level exploits. For example, <a href=\"https:\/\/www.businesswire.com\/news\/home\/20220309005387\/en\/Major-Security-Misconfiguration-Impacting-ServiceNow-Instances-Discovered\">BusinessWire summarizes the AppOmni findings<\/a> that nearly 70% of the ServiceNow instances they tested had a misconfiguration that could expose data, with root causes including customer-managed access control settings and overprovisioned guest permissions.<\/li>\n<li><span style=\"text-decoration: underline\">Account takeover at scale;<\/span> Once an attacker controls a collaboration account, they inherit access to chats, files, meetings, and integrated apps, often far more than the user actually needs.<\/li>\n<li><span style=\"text-decoration: underline\">Weak role design;<\/span> Over\u2011broad admin roles and \u201cpower users\u201d with legacy permissions turn every compromised account into a potential super\u2011credential.<\/li>\n<\/ul>\n<p>In this model, secure collaboration means strong MFA and SSO, conditional access, tight admin roles, and continuous monitoring for anomalous logins, not just a good VPN.<\/p>\n<h2>Guests: collaboration\u2019s hidden trust boundary<\/h2>\n<p>Modern businesses depend on inviting clients, suppliers, and partners into shared spaces, but every guest is another trust boundary \u201cinside\u201d our tenant.<\/p>\n<p>Typical pitfalls:<\/p>\n<ul>\n<li><span style=\"text-decoration: underline\">Over\u2011entitled guests;<\/span> It\u2019s easy to add an external user \u201cfor this project\u201d and accidentally give them access to entire channels, folders, or wiki\u2019s.<\/li>\n<li><span style=\"text-decoration: underline\">Stale access;<\/span> Guest accounts often outlive the projects they were created for, leaving dormant external identities with live access paths into our environments.<\/li>\n<li><span style=\"text-decoration: underline\">Indirect exposure;<\/span> Even read\u2011only guests see ticket subjects, file names, architecture diagrams, and process flows that can inform social engineering or targeting elsewhere. For example, a contractor may be granted access to review a specific deliverable, but workspace metadata such as channel names, meeting titles, ticket names, or document previews can inadvertently reveal sensitive information about confidential projects, incidents, or business initiatives, even without direct access to the underlying content.<\/li>\n<\/ul>\n<p>Modern guidance: treat guest access as a \u201ctightly scoped exception\u201d, not a default entitlement. That means purpose\u2011built guest roles, expiry dates, clear business owners, and separate logging so guest activity stands out.<\/p>\n<h2>Data sprawl, misconfiguration, and \u201csilent leaks\u201d<\/h2>\n<p>Email was comparatively simple. Today\u2019s collaboration platforms blend chat, files, screenshare, whiteboards, and apps into a continuous stream of interactions which creates several hard\u2011to\u2011see risks:<\/p>\n<ul>\n<li><span style=\"text-decoration: underline\">Data leakage by design;<\/span> Default sharing settings can expose sensitive information without anyone \u201csending it to the wrong person\u201d. A common example is a document platform where the default link type is set to \u201cAnyone with the link\u201d or to a broad internal audience instead of \u201cSpecific people\u201d. In that situation, an employee may intend to share a troubleshooting document with one supplier, but the generated link may be reusable by a wider audience, forwarded outside the original thread, or discovered later by users who were never part of the intended exchange.<\/li>\n<li><span style=\"text-decoration: underline\">Side\u2011channel leaks;<\/span> Even when content is locked down, file names, link previews, AI auto\u2011suggestions, presence indicators, and version history can reveal more than we intend; like project codenames, acquisition plans, or crisis meetings.<\/li>\n<li><span style=\"text-decoration: underline\">Misconfiguration as primary risk;<\/span> <a href=\"https:\/\/www.businesswire.com\/news\/home\/20220309005387\/en\/Major-Security-Misconfiguration-Impacting-ServiceNow-Instances-Discovered\">Numerous industry research<\/a> now lists SaaS misconfiguration and over\u2011permissive settings \u2018not vendor bugs\u2019 as the top SaaS security risks, even for experienced teams.<\/li>\n<\/ul>\n<p>Because collaboration data spans many tools and formats, traditional DLP (Data Loss Prevention) and governance often fail to see the full picture. Without a clear data model (what we store, where, and with which defaults) it\u2019s alarmingly easy to create \u201caccidental broadly accessible folders\u201d in what feels like an internal space. For example, a delivery team may create a folder for a single client engagement, but if the parent site is configured for organization-wide discovery or permissive link sharing, people outside the delivery\/ account team may still be able to browse the folder, discover file names, or access shared material they were never explicitly meant to see.<\/p>\n<h2>Integrations and non\u2011human identities<\/h2>\n<p>Collaboration works best when \u201ceverything talks to everything\u201d: ticketing, CI\/CD, monitoring, document management, AI assistants, and custom bots. But every integration brings:<\/p>\n<ul>\n<li><span style=\"text-decoration: underline\">Service accounts and tokens;<\/span> that are long\u2011lived, broadly scoped, and rarely reviewed.<\/li>\n<li><span style=\"text-decoration: underline\">Webhooks and bots;<\/span> that can read channels or post messages, and sometimes reach into connected systems like Jira, Git, or CRM.<\/li>\n<\/ul>\n<p>Research on SaaS security highlights identity sprawl (especially non\u2011human identities) as one of the most commonly missed risk areas. In collaboration, a compromised bot token can be as damaging as a compromised admin: it can quietly harvest data, inject phishing links, or modify records by calling downstream APIs.<\/p>\n<h2>Compliance and \u201ce\u2011discovery by default\u201d<\/h2>\n<p>For any modern digital organization, collaboration platforms are part of our contractual and regulatory footprint. Customers may expect:<\/p>\n<ul>\n<li>Retention of certain communications (for audits, disputes, or regulatory requirements).<\/li>\n<li>The ability to respond to access or deletion requests under privacy laws.<\/li>\n<li>Clean e\u2011discovery across chat, voice, video, and file sharing during investigations.<\/li>\n<\/ul>\n<p>Regulators and industry groups point out that unmanaged collaboration tools increase the risk of data breaches, IP loss, and regulatory penalties if communications aren\u2019t captured and governed correctly. That means retention, legal hold, search, and export must be \u201cdesigned in\u201d, not bolted on after adoption.<\/p>\n<h2>What \u201cGood\u201d looks like<\/h2>\n<p>You can think of secure cloud collaboration as four concrete outcomes:<\/p>\n<ol>\n<li>Identity\u2011centric control\n<ul>\n<li>Strong MFA, SSO, and conditional access for all collaboration tools.<\/li>\n<li>Minimal, well\u2011audited admin roles; continuous monitoring for stolen tokens or anomalous logins.<\/li>\n<\/ul>\n<\/li>\n<li>Deliberate guest and sharing model\n<ul>\n<li>Guest access is explicit, limited in scope, and time bound with clear business owners.<\/li>\n<li>External sharing and \u201canyone with the link\u201d are blocked or tightly controlled for sensitive data.<\/li>\n<\/ul>\n<\/li>\n<li>Governed data and integrations\n<ul>\n<li>DLP and classification policies tuned for collaboration traffic, not just email.<\/li>\n<li>Inventoried and reviewed app integrations, with least\u2011privilege scopes and regular token rotation.<\/li>\n<\/ul>\n<\/li>\n<li>Compliance and incident readiness\n<ul>\n<li>Clear retention and legal\u2011hold policies per tool, aligned with client and regulatory needs.<\/li>\n<li>E\u2011discovery and export paths that let us reconstruct a multitool conversation quickly during audits or incidents.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h2>Strategic Takeaways<\/h2>\n<p>Cloud collaboration isn\u2019t a side channel; it is where all the work and client interactions live. That makes it one of the most critical security platforms on par with identity, core network, and production systems.<\/p>\n<p>Now, the key question is no longer <em>\u201cWhich collaboration platform do we use?\u201d<\/em> but <em>\u201cDo we operate our collaboration stack like critical infrastructure?\u201d<\/em><\/p>\n<p>Therefore, investing in identity\u2011first security, disciplined guest and sharing models, governed integrations, and built\u2011in compliance, can keep the speed and flexibility of cloud collaboration, without turning the modern digital office into a weakest security link.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why digital workplaces are a major attack surface A few years ago (2021), attackers [&hellip;]<\/p>\n","protected":false},"author":1121,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[98],"tags":[97,178,158],"coauthors":[207],"class_list":["post-2025","post","type-post","status-publish","format-standard","hentry","category-unified-communications","tag-collaboration","tag-cybersecurity","tag-unified-communication"],"acf":[],"_links":{"self":[{"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/posts\/2025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/users\/1121"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/comments?post=2025"}],"version-history":[{"count":4,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/posts\/2025\/revisions"}],"predecessor-version":[{"id":2039,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/posts\/2025\/revisions\/2039"}],"wp:attachment":[{"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/media?parent=2025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/categories?post=2025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/tags?post=2025"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.infosys.com\/engineering-services\/wp-json\/wp\/v2\/coauthors?post=2025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}