Legal

“Anyone with the link” is not a client portal

The FBI warned in May that an extortion crew has been calling law firms while posing as their own IT help desk.

1 min readOriginally posted on LinkedIn

The FBI warned in May that an extortion crew has been calling law firms while posing as their own IT help desk — and in some cases showing up at the office in person.

What they're after is documents. Not your servers. The client files.

So here's the question I'd put to any managing partner: right now, how do clients send you documents, and how do you send them back? If the answer is email attachments and the occasional "here's a link," there's a hole you can't see.

In SharePoint and OneDrive, an "Anyone with the link" link works with no sign-in, can be forwarded to anybody, and — this is Microsoft's own documentation talking — that access can't be audited. So when a client calls and asks who has seen their file, nobody in the firm can answer. Not you, not me.

Building a real client portal is mostly unglamorous settings work. Share to specific people, so the link is tied to the named recipient and dies if it gets forwarded. Require anonymous links to expire, and make them view-only. Give each client a folder instead of a thread of attachments.

None of it slows your people down. It just means the next time someone asks who opened the file, you have a record instead of a guess.

Worth a look before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions