Security is a big concern of mine. Real security, not fake stuff where an employee can initiate a breach by posting something to slack.
If I can screw up and post company financials, ssns, whatever sensitive stuff to Slack, then that is a big security risk. And Slack isn’t my company’s problem. The problem is training, and digital loss prevention, and access controls.
If company IT approved solutions don’t meet business needs, then I think that’s a bit security risk. To prevent people from posting inappropriate material, we need effective tools.
Should the partner not have given his presentation?
The solution, I think, is to identify docs with SSNs wherever they may be on network and major cloud vendors and redact them, or remove the files when they are uploaded.
In the partner’s case there was no sensitive data in the presentation. IT should know that and help users. If the solution is to ban cloud docs in 2009 with no solution then I think that creates more risk because rather than trying to adapt to using google drive and training users how to use it, there’s a lot of shadow functions.
There is risk in these tools, my point isn’t that we must allow everything. I think we have to support common use cases and banning functionality needed by users, and used by competitors, is actually riskier than supporting enough so that users can do their jobs.