Join our Newsletter — 33% off our NHI Course

When should organisations continue using a collaboration platform despite security concerns?

Organisations can continue using a collaboration platform when the remaining risk is understood, controls exist to reduce exposure, and the vendor is actively addressing issues. A reasonable decision considers business need, user impact, attack conditions, and the likelihood of exploitation. If the product is improving and the threats are limited or controllable, continued use can be justified.

When continued use is reasonable

Continuing to use a collaboration platform can be reasonable when the issue is bounded, understood, and monitored rather than open-ended. The decision turns on whether the platform still supports an important business function, whether the exposure is realistically reducible, and whether the vendor has a credible remediation path. In practice, organisations should separate “imperfect” from “unacceptable”.

That distinction matters because many collaboration platforms are deeply embedded in daily work, workflows, and external communication. If the concern is a specific weakness, but access can be constrained, data exposure limited, and exploit conditions are narrow, the operational cost of immediate replacement may exceed the remaining risk. The question is whether the residual exposure is temporary and controlled, not whether the product is flawless.

Continuing use is also more defensible when the vendor is actively fixing the issue, publishing guidance, and closing the gap on a credible timetable. A platform with a known weakness and no evidence of progress is a different case from one where mitigations exist and the provider is visibly reducing the attack surface. That difference should be reflected in the decision, not treated as a side note.

What should change before you keep it in service

Before accepting continued use, the organisation should be able to describe the specific exposure, the affected user groups, and the compensating controls in place. If the security concern cannot be bounded to particular workflows, tenants, integrations, or data types, the risk is too vague to justify retention. Clear ownership for monitoring, exceptions, and vendor follow-up is part of the decision, not an afterthought.

Controls should match the weakness, not just the platform category. That may mean tighter access limits, shorter retention for sensitive content, stronger authentication for high-value accounts, restricted integrations, or blocking the most exposed features until remediation lands. The more the platform can be made to fail safely, the more credible continued use becomes.

Business tolerance also matters. If the platform is only supporting convenience, the threshold for keeping it despite security concerns should be high. If it is embedded in regulated operations, customer communication, or a critical internal process, the organisation may accept a short-term risk while planning a controlled transition, but it should do so with a defined end state and review date.

When continued use stops being justified

Continuation becomes hard to justify when the threat conditions are favourable to attackers, the exposure is broad, or the vendor response is weak. A known issue that can be exploited remotely, at scale, or with little user interaction is materially different from a niche weakness requiring unusual conditions. If compensating controls cannot meaningfully reduce blast radius, the platform may need to be paused, replaced, or severely limited.

It is also a warning sign when the platform’s role has expanded faster than its governance. Collaboration tools often accumulate files, chat history, shared links, and third-party integrations until the security boundary becomes unclear. At that point, the product may still be useful, but the organisation has to decide whether the convenience is now carrying too much unreviewed exposure.

Risk and Threat Considerations

Security concerns become more serious when collaboration platforms sit at the centre of communication, file sharing, and external access. If an attacker can abuse trust in shared content, tokens, links, or integrations, the platform can become a high-leverage route into sensitive information or wider account compromise.

Failure mechanism: Weaknesses become material when they combine with broad access, long-lived sessions, over-permissive sharing, or uncontrolled integrations. In those conditions, a single flaw can scale into data exposure, unauthorized access, or lateral movement.

Impact: The practical impact is usually not just one compromised message or document, but loss of control over sensitive collaboration data, business disruption, and a larger trust failure in how the organisation manages shared work.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy This question is about deciding whether residual risk is acceptable.
Recommendation — Define a risk tolerance threshold for continued platform use and review it against the identified exposure.
NIST SP 800-53 Rev 5 RA-3 — Risk Assessment The decision depends on understanding exploitability and impact.
AC-6 — Least Privilege Continued use depends on reducing exposure through tighter access.
SI-2 — Flaw Remediation The vendor's remediation progress is central to the continuation decision.
Recommendation — Assess the specific platform weakness, exposure path, and likely consequence before approving continued use. Reduce platform exposure by constraining access to only the users and functions that are required. Track remediation progress and remove or limit use if the flaw is not being fixed promptly.

Practitioner Guidance

What to verify: Confirm that the remaining risk is tied to a specific, documented weakness and not a general discomfort with the vendor. If you cannot state what is exposed, who can reach it, and which control reduces it, do not treat the risk as acceptably bounded.

Decision rule: If the platform can be narrowed through access controls, feature restrictions, and monitoring so that exploitability is low and recovery is feasible, continued use may be defensible. If the issue is broad, active, and difficult to contain, treat replacement or suspension as the safer course.

Practitioner takeaway: Keep the platform only when the organisation can prove the residual risk is temporary, contained, and actively shrinking; otherwise, continued use becomes a decision to tolerate unmanaged exposure.