All insights

How should you share files with clients securely?

5 min readBy Brendon Whiting, Founder · 9 February 2026

Share a link rather than an attachment, restrict it to specific people rather than anyone with the link, and set an expiry. For ongoing work, add the client as a guest to a dedicated Team or site instead. Then review guest access when engagements end, which is the step nearly everyone skips.

Most businesses share client files the way they always have, by attaching them to an email, and it is worth being precise about why that is the weakest option. The moment it sends, you have lost control of that copy: you cannot revoke it, cannot see who opened it, and cannot correct it if the version was wrong. If the address was mistyped, client material is now sitting in a stranger's inbox permanently. And the copy immediately begins diverging from yours as people edit and reply.

A link solves all four problems at once. The file stays in your SharePoint or OneDrive, so there is one authoritative version. Access can be revoked. You can see who has opened it. And if the wrong person receives the link, a properly configured one will not let them in. That last clause is doing the work, because a badly configured link is not much better than an attachment.

Microsoft 365 offers a few link types and the distinction matters. Anyone with the link works for whoever holds it, with no sign-in, which is convenient and is precisely the setting that turns a forwarded email into an exposure. Specific people requires the recipient to verify who they are, which is the sensible default for client material. People in your organisation is for internal use and is a common accidental choice when sharing outward, producing the confused client who cannot open anything.

Two settings turn good intentions into a system. Expiry, so links do not outlive the engagement, since an unexpired link from 2023 still works and nobody remembers it exists. And permission level, meaning view rather than edit unless collaboration is genuinely intended. Both can be set as tenant-wide defaults, which is far more effective than instructing people, because the safe option becomes the one that requires no thought.

For ongoing client work, guest access is the better model. Add the client to a dedicated Team or site for their engagement, and they get a proper shared workspace with conversation, files and history in one place, under permissions you control. The important caveat is scope: a guest sees the whole Team, not one folder, so the Team needs to be built for that from the start rather than being an internal space you later invited someone into. That mistake is common and quietly exposes internal discussion.

The step almost everyone skips is the review. Engagements end, projects finish, and the guest account remains, still able to reach the site months or years later. Quarterly, list your guests and confirm each still needs access. This is usually the single most productive half-hour in a small business's security year, because it reliably finds several people who should have been removed long ago, occasionally including someone who now works for a competitor.

Receiving files from clients deserves as much thought as sending them, and it gets almost none. The usual arrangement is that clients email documents, which puts sensitive material into a mailbox rather than into managed storage and leaves it there indefinitely. A request link that lets someone upload directly into the right library without seeing anything else solves it, and it also removes the size limits that push people toward personal file-sharing accounts you have no visibility of at all.

Some material warrants more than a link. Anything highly sensitive, health records, financial documents, legal material, deserves consideration of sensitivity labels, which can restrict what recipients may do with a document, and in some industries a purpose-built portal rather than general file sharing. Check your professional obligations before assuming a link is sufficient, because in regulated fields it sometimes is not.

The honest caveat is that the secure path must also be the convenient one or it will not be used. If sharing properly takes six clicks and emailing an attachment takes two, people will email the attachment, and no policy survives that gap. Set the defaults so the right thing happens automatically. If you want yours configured that way, call 1800 456 567.

Make secure sharing the easy option

We configure sharing defaults, expiry and guest access so the convenient path and the safe path are the same one.

Frequently asked questions

Three things: you lose control of the copy the moment it sends, version confusion follows as people reply with edits, and mailbox size suffers. The bigger risk is misdirection, since a wrong address sends client material to a stranger with no way to retract it. A link can be revoked; an attachment cannot.

For most small businesses handling client data, yes, or at least restrict it to specific people and require expiry. Anyone-with-the-link is convenient precisely because it removes verification, which means the link works for whoever ends up holding it, including in a forwarded email months later.

It is excellent for ongoing collaboration and poor for a one-off document. A guest sees the whole Team, not a folder, so it suits a genuine shared workspace and not a quick handover. Whichever you choose, review guest access when the engagement ends, because guests outliving projects is the most common sharing problem we find.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.