There’s been an increase in the use and reliance of communication platforms since the recent crisis-forced shift to remote work. Now scattered in different remote locations, employees across organisations are looking for an efficient, secure way to continue collaborating across the business. The need to migrate onto business communication platforms as an alternative to in-person and other technical communication has become a top-line priority for a business’s digital transformation.
Similar to communication platforms such as Slack and Zoom, Microsoft Teams has fast become a hugely successful business collaboration platform, with currently 75 million, and growing, daily active users since the global pandemic. Teams has transformed how employees communicate, share information, and maintain relationships when scattered across the world. Employees across their organisation leverage Teams to conduct video calls, share business critical information, conduct organisation chats, share GIFS, and more, in order to foster team collaboration and mimic in-person team meetings held in conference rooms and “water cooler talk” that now seem like a distant memory.
With more communication – and business critical information being shared – across cloud platforms like Teams, companies leave themselves vulnerable to serious security threats. As we’ve seen with COVID-19, there has been a surge in cyberattacks, with targeted Teams attacks via impersonating Teams notifications, World Health Organization (WHO) phishing scams, and GIFs vulnerabilities. What can companies do to protect themselves and ensure their teams are secure when using Teams? Here are vulnerabilities and risks to be aware of, and strategies organisations should implement to maintain a strong security posture.
Vulnerabilities and Risks Within the Platform
In order to drive mass adoption, Microsoft ensured it was easy to access the platform with a flexible access policy on by default. This allowed users within organisations to quickly adopt Teams, and oftentimes faster than the organisation was prepared to secure it. The default access policy was and still is left on in many organisations, leaving them open to vulnerabilities if they aren’t properly checking their security.
In terms of external vulnerabilities, when Teams is implemented out of the box, federated access to external users is on by default. This means anyone in the world can search for a user by email, request to chat, share files and expose the individual, and in turn, their entire organisation, to communications that are often acted with malicious intent.
Teams also allows individuals to interact with content outside of the Teams’ perspective So, in the previous situation, an external user could search for someone in your organisation and send them a malicious file stored in a third-party storage provider. We’ve seen something similar to this with malicious GIFs shared via Teams from external users. These external users could pose as a partner or vendor using teams to phish for credentials, deliver malicious payloads, or perform a new form of BEC financial scams.
Even approved users can create security holes, such as through negligent actions like downloading vulnerable applications to their Teams environment. Most administrators aren't aware that this action is also enabled to users by default, which makes it difficult to control the apps that are being downloaded. Without first exploring the app’s privacy policy, individuals can sign away their privacy rights with a click, allowing third-party apps to share data insecurely or with other organisations.




