Insecure sharing to external users

Overview

When using "not equal" conditions, a sharing rule operates on an opt-out basis, meaning that the sharing occurs unless certain non-sharing conditions are met. As a best practice, especially when sharing CRM data with external users, one should define the sharing rules on an 'opt-in' basis. This approach keeps data private by default and opens up visibility exclusively when specific conditions apply.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Rare

Incidence

How common is this issue?
1%0%
arrow down0%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
2 years2 years
arrow down27%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconSharing and VisibilityiconA04:2021 – Insecure Designicon