
By Patricia Prada, Cybersecurity Manager at Intexus.
In today’s productive environment, cloud collaboration platforms such as Google Drive, SharePoint, Google Workspace or Office 365 have become essential tools to improve productivity and facilitate teamwork. However, the widespread use of these platforms also brings a number of security risks that cannot be ignored. From phishing and credential theft to unauthorized access and insider threats, enterprises face multiple challenges in protecting their sensitive data shared in the cloud.
Although it is now commonplace to edit work documents in cloud services and share them via email, we are not aware of the security gaps that lie behind these actions. For example, unknowingly opening a fraudulent or phishing email allows cybercriminals to obtain a user’s login credentials to platforms and manage to infiltrate and steal sensitive data.
Also, downloading applications that employees install without the knowledge of the IT team may allow third-party applications to access sensitive data and transmit it to external locations, if the company does not have adequate controls in place to prevent unauthorized access to its platforms and data.
Impact and costs of unauthorized access
The impact of these attacks can be very significant for a company. According to the report “Cost of a Data Breach. from IBMThe average cost of a data breach in Latin America is approximately $2.46 million, with even higher costs in sectors such as finance and healthcare, which handle highly sensitive data. In addition, Organizations with hybrid work environments face average breach costs of $5.54 million , because they are more vulnerable to this type of data leak.
In addition to this direct monetary loss, a data leak can have a number of serious and far-reaching consequences for an organization. These impacts can affect a company’s reputation, customer confidence, internal operations, competitiveness and, therefore, its long-term sustainability. For all these reasons, having measures in place to protect the data shared on collaborative work platforms should be a priority for organizations in all sectors.
Measures for data protection in collaborative platforms

Of course, the first step should be to educate and raise awareness among members of the organization about the risks of a data leak and secure data handling practices, although the human factor is often the most vulnerable link and additional solutions such as multi-factor authentication and identity management that enforce access to accounts to confirm that the user is who they say they are or identify if credentials were stolen or there is an attempt at impersonation should be in place.
However, it is important to look for preventive measures against data leakage and, if possible, to thwart this type of attack with solutions that allow centralizing protection precisely in those data and their repositories, such as monitoring and detection of threats in databases and file servers, control and protection of data stored in SaaS applications, control of access to applications and control of policies that allow determining and monitoring the information that can be shared or not.
These measures make it possible to detect and respond to suspicious activities in real time, with decisive actions such as identifying and blocking fraudulent emails, not allowing the sending of sensitive information or blocking suspicious or unauthorized websites, among others.
Finally, measures such as data encryption can also strengthen the protection of data against threats, so the ideal is that each organization can establish a tailored data protection strategy, advised by an information protection expert such as Intexus.