Security budgets keep climbing, and most of that money buys the same story: zero-trust architecture, biometric MFA, a shiny new identity provider. Boards get a tidy quarterly slide showing the front door is locked tight. What that slide never shows is the inside of the house — because nobody has walked through it in years.
That’s where the real damage happens. Not through a clever external breach, but through internal sprawl that nobody owns: shared drives nobody has cleaned since 2019, SaaS entitlements nobody reviews, and spreadsheets nobody can even locate. Knowing who logged in was never the hard part. Knowing what they could touch once they were inside — that’s the part everyone skips.
The Interior Nobody Audits
Shared drives are where this starts. They were sold as frictionless collaboration space; in practice, they behave like an attic nobody’s cleared out. Folders nest inside folders, each with its own inherited permission set, and nobody remembers why. A contractor from a three-week engagement in 2022 can still open strategic planning folders in 2026. An employee who moved teams twice keeps every permission from both previous roles, because removing access is nobody’s job, the way granting it is.
SaaS platforms compound the problem rather than fixing it. Single sign-on solved the login screen, not the entitlement underneath it. Give someone CRM or ERP access and it’s treated as a switch — on or off — when the real question is what they can pull out once they’re in. A mid-level analyst rarely needs the ability to export the full customer register or the unreleased pricing sheet to their laptop. Most environments give it to them anyway.
And once that export happens, the data lands in the one place governance never reaches: the spreadsheet. Financial models, comp drafts, merger targets — they all end up living as loose .xlsx files with no access log, no version history, and no way to know where the third copy ended up.
The Case That Should Worry Every CISO
In 2023, security researchers at Wiz found that a Microsoft AI research team had, without realising it, exposed 38 terabytes of internal data through a single sharing link. The link was meant to hand out a small set of open-source training files. Instead, it was scoped to the entire storage account, and it carried full-control permissions rather than read-only — meaning anyone who found it could not just view the data but alter or delete it. Buried inside were employee credentials, internal Teams messages, and backups of two employees’ workstations. Microsoft closed the exposure once notified, but the incident is a clean illustration of the article’s core point: the failure wasn’t a broken lock, it was a link nobody remembered to scope correctly.
What This Looked Like From the Inside
Most CTOs have lived a version of this problem directly. A few months into my current role, we still had a legacy Windows shared-drive environment running across the organisation — tens of terabytes, spanning multiple departments, some folders dating back over a decade. Permissions had been layered on top of permissions by whoever happened to be IT lead at the time. Nobody could tell you, with confidence, who could see what. On top of that sat the usual duplication problem: the same file existing in four locations under three different names, each one slightly out of date.
We took the decision to dismantle the shared-drive structure entirely rather than patch it, and migrate to SharePoint with a proper information architecture underneath it — role-based access mapped to actual job function, retention rules attached to content type, and an owner assigned to every library who was accountable for what sat inside it. It wasn’t a lift-and-shift; it was a rebuild of how access itself was decided. The exercise took months, not weeks, and it wasn’t popular with everyone who’d grown used to finding files by memory rather than by structure. But the payoff showed up at the next audit cycle: zero findings related to shared-drive access or data ownership, for the first time in the organisation’s history. That’s the kind of outcome that doesn’t make the boardroom slide, but it’s the one that actually matters when a regulator or an auditor comes asking.
From Authentication to Governance
None of this gets fixed by tightening the front door further. It gets fixed by treating access as something that has to be earned continuously, not granted once and forgotten. In-app entitlements need the same scrutiny as network logins — automated, tied to current role, built to stop bulk exports by default rather than after the fact. Shared drives need an owner, an expiry date on every external link, and a recurring attestation where someone has to justify why access still exists. And spreadsheets — since banning them was never realistic — need protection that travels with the file itself: rights management, watermarking, and encryption that hold even after the workbook has left the building. Authentication tells you who walked in. Governance is what decides what they can do once they’re standing inside. Until organisations treat the second question with the same seriousness as the first, the fortress is only secure on the slide.
Anand Iyer is the Group CTO at ICRA.
