Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should security teams do when employees keep…
Cyber Security

What should security teams do when employees keep exposing sensitive data in SaaS tools despite awareness training?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Security teams should treat repeated exposure as a process and control problem, not just a training gap. Tighten sharing permissions, monitor collaboration platforms for regulated data, remove hard-coded secrets from repositories, and automate quarantine or redaction where possible. Reinforce policy with targeted user guidance so employees get immediate feedback at the point of risk.

Why awareness training keeps failing at the point of exposure

Repeated data exposure in SaaS usually means the control failed earlier than the user’s decision. If employees can share broadly, paste secrets into tickets, or leave regulated data visible in collaboration spaces, then the organisation is relying on memory where the workflow should enforce safer behaviour. Treat the problem as an access, classification, and workflow design issue, not a one-off education problem.

That is why exposure often persists even after awareness campaigns. People respond to speed and convenience, so if the SaaS path still makes unsafe sharing the easiest path, training becomes advisory rather than preventive. The stronger fix is to change defaults, reduce broad sharing, and make risky actions harder or visibly unsafe before data leaves the intended boundary.

For evidence that this pattern is often tied to secret and credential leakage rather than simple user ignorance, the Ultimate Guide to Non-Human Identities notes that 96% of organisations store secrets outside secrets managers in vulnerable locations, and 30.9% store long-term credentials directly in code. Those numbers are useful because they show how often sensitive material ends up where collaboration and editing tools can expose it by default.

What security teams should change inside the SaaS workflow

Start by narrowing who can share, export, and externalise data. Tighten default permissions, separate open collaboration from regulated workspaces, and review whether guest access, link sharing, and sync settings are too permissive for the data being handled. If a team routinely works with sensitive content, the workspace should enforce that sensitivity rather than rely on users to remember it.

Next, move detection closer to the activity itself. Monitor collaboration platforms, document stores, ticketing systems, and code repositories for regulated data patterns, then route findings into quarantine, alerting, or automatic redaction where that is operationally safe. The best controls are the ones that intervene before the data is replicated into a dozen places, because cleanup after spread is slow and usually incomplete.

Where secrets are involved, remove them from places employees naturally share content, especially repositories, pasted logs, and support threads. If teams must move quickly, give them approved secret-handling paths that are easier than ad hoc copying. The most durable improvement is usually a combination of safer defaults, automated detection, and immediate feedback, not another broad reminder campaign.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementRestricts who can share, export, or access sensitive SaaS data.
3 — Data ProtectionSupports detection, redaction, and handling of sensitive data in collaboration tools.
5 — Account ManagementCovers removing excess access that enables broad collaboration and accidental exposure.
Recommendation — Review and tighten SaaS access paths and sharing permissions for sensitive content. Deploy data protection controls to detect and limit sensitive data exposure in SaaS tools. Remove unnecessary accounts, guests, and stale access from collaboration platforms.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlApplies to controlling who can access and share sensitive SaaS content.
DE.CM — Continuous MonitoringSupports monitoring SaaS platforms for regulated data and risky sharing behaviour.
PR.DS — Data SecurityDirectly addresses protecting sensitive data at rest, in use, and when shared.
Recommendation — Apply access control policies that limit sensitive-data sharing to authorised users. Monitor collaboration platforms for sensitive-data exposure and abnormal sharing. Protect sensitive data with classification, redaction, and retention controls.

Practitioner Guidance

What to prioritise: Focus first on the workflows that repeatedly create exposure, not the teams that merely received the most training. If the same data class keeps appearing in the same tools, fix the control point in that tool before broadening awareness content.

What to verify: Check whether permissions, retention, and classification controls actually block or flag the risky action in the SaaS product itself. A good test is whether an ordinary user can still share a sensitive file, paste a secret, or sync a regulated record without any friction or visible warning.

Practitioner takeaway: When exposure keeps happening, the organisation has not yet made the safe path operationally easier than the unsafe one, so the control objective is to enforce safer defaults and immediate intervention at the point of sharing.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org