Be Careful What You Put in the Group Chat

cyber-safety in your work group chat

Workplace collaboration apps help us get our work done faster and more efficiently.

Instead of writing an email, you can send a quick message through Microsoft Teams, Slack, or another company platform and get an answer almost immediately.

If you need someone to check a customer account, you can paste the information into one of these programs. For help with a document, you can send someone a screenshot. When a coworker needs an account number, you can just drop it into a message.

On the other hand, that convenience can also make it incredibly easy to put sensitive data somewhere it does not belong, or share it with someone who shouldn’t see that information.

Group Chat Messages Are Still Company Property

Our direct messages feel temporary and inconsequential. You send a question, have a quick chat , and move on with your day.

In reality, those messages may remain stored long after the conversation ends. Depending on your organization’s policies and settings, they might also archive, search, export, or retain your conversations for compliance purposes.

That means you should treat online workplace discussions with the same caution you would use with email or any other company records.

If you would hesitate to tell certain details into as tranger, then think twice before pasting it into a friendly conversation with your coworkers.

Who Can Actually See That Channel?

Now, some of these channels contain only a few coworkers. Others may include entire departments, outside contractors, vendors, or guests.

Before sharing sensitive information, look at who can actually see the conversation.

Imagine someone asking you a question about a customer account. You paste the customer’s name, address, and account number into the group chat where that coworker broached the subject.

Unfortunately, that conversation also included 35 other people who have no reason to see the information. In other words, you may have just exposed Personally Identifiable Information (PII) to people who weren’t authorized to access it.

Don’t Share More Than the Recipient Needs

This brings us back to one of the most important ideas in cyber-compliance: Data minimization.

It means that you only share the information someone actually needs.

If a coworker needs an order number, for example, then you probably don’t need to include the customer’s entire account record. If IT needs to review a payment error, they may not need a screenshot containing someone’s whole credit card number. Take a few extra seconds to remove unnecessary information before you hit Send!

The less sensitive information you share, the less information you can accidentally expose.

Private Messages Aren’t Necessarily Private, Either

Direct messages can feel safer because they involve fewer people. That doesn’t mean you can send whatever you want, though. Your organization may have specific approved systems for transmitting financial information, Protected Health Information (PHI), passwords, payment information, or other sensitive data.

A private chat does not automatically override those systems.

If company policy says that you have to share customer documents shared through a secure portal, then sending one through a private chat can still violate data compliance laws.

Watch Out for Screenshots, Too

Screenshots deserve special attention because they often reveal more than we intend or realize. You might send a screenshot to show someone a single line of information while accidentally including customer names, account numbers, browser tabs, email notifications, or other confidential information around it.

Crop screenshots before sending them, and take care to check the entire image! Better yet, if you can explain the problem without including sensitive information at all, then do that instead.

Don’t Forget About Safe Passwords

If your coworker messages you, “What’s the password for that account?” Don’t send it.

Passwords, MFA codes, recovery codes, and other authentication information should never be casually passed around through workplace chat.

If several people legitimately need access to the same system, then your IT team should provide an approved method for granting that access.

Remember, your login identifies when you use your device and what you do with it. Sharing that information destroys accountability and may give another person access to information they were never supposed to see.

Slow Down Before You Hit Send

Chat platforms encourage quick responses. That’s one of their biggest advantages. Unfortunately, it can also be one of their biggest risks.

Before sending sensitive information, take a moment to check:

  • Who can see this conversation?
  • Does everyone here need this information?
  • Am I sharing more information than necessary?
  • Is this an approved place to send this type of data?
  • Is there sensitive information hidden somewhere in my screenshot or attachment?

If you aren’t sure, you should always ask before sharing.

Conclusion

Workplace communication platforms make it easy to have a quick chat with a coworker. Sometimes, though, we need to slow down when it comes to cybersecurity and cyber-compliance.

A message that takes two seconds to send could contain information that your organization is legally or contractually required to protect. Pay attention to what you paste, where you paste it, and who can see it.

“It’s just a chat” doesn’t mean that information inside your message doesn’t count!

More Articles & Posts