Security News

Cybersecurity news aggregator

INFO News Dark Reading

European Organizations Have a Collaboration Security Confidence Gap

  • What: A survey shows European organizations have overconfidence in collaboration tool security
  • Impact: May lead to underestimation of risks in enterprise environments
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS REMOTE WORKFORCE CYBER RISK APPLICATION SECURITY NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific European Organizations Have a Collaboration Security Confidence Gap A new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms. Jai Vijayan,Contributing Writer July 9, 2026 4 Min Read SOURCE: VECTORFUSIONART VIA SHUTTERSTOCK If confidence alone were enough to secure enterprise collaboration, many organizations in Europe would have little to worry about. A new survey from communications provider Wire found that 84% of IT professionals in the UK, France, and Germany are confident in the security of their collaboration environments, and 79% have the same faith in their ability to control access to collaboration data. But other findings in the survey suggested a more complicated reality. Just 29% said their collaboration tools were fully suitable for handling sensitive communications, 61% reported that access to shared files often remained active longer than necessary, and 34% said they struggled to determine who had access to sensitive files within their organizations. Nineteen percent found it very difficult to revoke access to collaboration data after granting that access. A Divide Over Secure Collaboration As Wire summarized it: "The central finding of this report is not that organizations are careless about collaboration security. It is that confidence in collaboration security and the reality of how sensitive information is handled exist in significant tension." Related:Operation Escaneo Signals Shift in LatAm Threat Landscape Wire's survey showed European organizations are using a broad combination of tools to collaborate with others, both internally and externally. The list included enterprise messaging and collaboration platforms, email, online file storage and sharing services such as OneDrive and Dropbox, and consumer messaging apps such as WhatsApp and Signal. Often, organizations are using these different tools simultaneously without segmenting based on information sensitivity or workflow. Wire found the lack of governance especially telling in collaboration flows involving organizations and their external partners. Three-quarters of organizations used the same email platform as they did internally when sharing information with external partners, 45% used file-sharing lines, and 42% used message apps. Less than a third (28%) of organizations used a secure tool for external collaboration, which, as Wire noted, "matters because external participants may not follow the same policies, use the same systems or retain information in the same way." Unsurprisingly, 33% expressed a lack of confidence in their ability to retain control over externally shared files. The Shadow IT Problem There were other issues as well. One of the biggest was the prevalent use of consumer messaging apps, personal cloud storage, and file-sharing services for official purposes. Employees most frequently resorted to using these shadow IT tools and services when speed and urgency mattered, though that was not the only trigger. The same thing happened when an external partner didn't use the same official tools as the organization did, if the officially sanctioned tool was too complex, or when workers were using mobile devices or were working remotely. Related:EU Gets a Head Start in Developing 6G Network Security When assessing the security of their collaboration environments, IT and security leaders first consider whether they have officially sanctioned collaboration tools, if those tools are governed by IT processes, and whether they live under the umbrella of standard corporate security measures, says Benjamin Schilz, CEO at Wire. The answer to all three questions, in many cases, is in the affirmative, Schilz notes. "From a systems perspective, that would lead them to say that their official tools are properly secured. That's not a wrong answer, but it's incomplete." The gap lies in the extent to which employees turn to unsanctioned, ungoverned consumer apps, exposing organizations to security and compliance risks, he points out. In the Middle of the Maturity Range Despite the high level of confidence that survey respondents expressed, Wire itself assessed most organizations to be somewhere in the middle of the maturity scale when it came to the security of their collaboration data. Organizations that fell into this category used enterprise tools for internal collaboration but were inconsistent in how they managed the use of email and consumer apps for external collaboration. Related:Asia's Cyber Insurance Market Shows Signs of Life Those with slightly more mature practices had a clear understanding of compliance needs, had controls in place for managing risk, used segmented tools for different types of data, and had at least some oversight over external collaboration. "Organizations in this range have built the policy and tool foundation. What they have not yet closed is the loop between policy, workflow and demonstrable control," Wire noted. In 2026, organizations need to be secure by design if they want to truly protect their collaboration environment, Wire noted. This means implementing end-to-end governance across internal and external workflows and having auditable, sovereign, and compliant controls. "Mainstream collaboration platforms and systems as implemented in enterprises are simply not well-suited for unified, internal-external collaboration," Schilz says. "As a rule, enterprise collaboration platforms or systems are collections of tools that evolved together over time." Often, an enterprise collaboration platform consists of email, online drives, shared file links, chat, and conferencing tools that were built primarily for internal use within the organization’s boundaries. "The fragmentation makes them complex to manage from an access POV [point of view], so access control tends to be all or nothing," he says. All-or-nothing access isn’t appropriate for external parties, he adds, and internal collaboration platforms and tool collections lack easy, unified mechanisms to grant selective access to external collaborators. "As a result, the administrative work of granting outsiders' access is burdensome, which manifests as IT process friction," Schilz points out. "This in turn leads to human risk — employees turning to a tool they can control and use — due to urgency, lack of access, and perceived tool complexity." Read more about: Europe About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos, Contributing Writer OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 CYBERSECURITY OPERATIONS Women Who 'Hacked the Status Quo' Aim to Inspire Security Careers by Elizabeth Montalbano, Contributing Writer JUL 16, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly

Share this article