Tens of millions of users around the world use Google Drive every day. Apparently many of those users are doing so without considering security.
A new report from data security company Metomic suggests companies are putting sensitive data at risk by storing it in Google Drive. The company's 2023 Google Scanner Report found that 40% of the 6.5 million Google Drive files it scanned contained confidential information, such as customer information, employee records or company secrets.
The scanning was conducted with Metomic's proprietary data security technology via a campaign offering businesses the opportunity to scan their Google Drives so they could learn about the amount of sensitive data stored there.
[Related: What is multifactor authentication (MFA)? How it works, why adopt it and its challenges]
“Over the last several years, businesses [have been] leveraging more and more SaaS [software-as-a-service] tools to enable innovation and productivity — and that's a good thing. However, data security teams aren't aware of the amount of sensitive data being stored and shared in these platforms,” Rich Vibert, CEO of Metomic, told SDxCentral. “Everytime we conduct a scan of a Google Drive or a Slack instance, data security teams are shocked to learn the extent to which their business is exposed to potential data breaches.”
Widespread sharing exposes dataIn addition, the report found that 34.2% of scanned files were shared externally outside of the company domain. This amounted to 2.2 million files that may have been shared with unauthorized parties.
The report also found 357,000 files were shared fully publicly, accessible to anyone on the internet. This further increases the risk of sensitive data exposure.
"In making documents easy to share, individuals may not realize just how easy it is for anyone to access their sensitive data," the report warns.
Metomic ranked 18,000 scanned files at a "critical" risk level. These files contained highly sensitive data or permission settings that weren't properly restricted. Having so much high-risk data accessible increases the danger from potential cyberattacks.
The report emphasizes that data breaches can be catastrophic for companies. In 2023, the average data breach cost $4.45 million — the highest ever. Minimizing the amount of sensitive data stored in apps like Google Drive can help reduce potential damage if a breach does occur.
How to reduce the riskThe report suggests that there are four key things organizations can do to help reduce the risk and secure data.
- Tighten access controls. Limit access to sensitive files to protect high-risk data.
- Implement multifactor authentication. Passwords alone can't stop hackers; enable multifactor authentication for added security.
- Build a “human” firewall. Train employees how to spot unusual behavior for maximum security impact.
- Use data loss prevention (DLP) tools. DLP tools (Metomic develops one such tool) help to secure sensitive data in SaaS apps without restricting employees.
As to why so many organizations share files via Google Drive in an insecure way, Vibert postulated that some simply haven't had the chance to think about the risks they pose. That said, he noted that increasing numbers of data security teams are looking closely at how their organizations are using SaaS.
“Essentially, the security leaders who are able to stay ahead of the trends and prioritize effective data security strategies will be the ones best equipped to protect their company’s systems,” he said. At the same time “while also maximizing productivity across the numerous cloud-based tools their organization uses to get work done.”
Comments