Skip to Content
Division of Information Technology

Share Sensitive Information with Confidence

Cybersecurity AwarenessSeton Hall is kicking off Cybersecurity Awareness Month with a focus on protecting data and making thoughtful decisions about how sensitive information is shared. University business often requires students, faculty and employees to exchange confidential material, making the method used to send or share it an important part of keeping that data secure. 

Sensitive information can take many forms and is not limited to Social Security numbers or financial records. It may include government identification numbers, account credentials, student education records, employee personnel or payroll information, medical information and confidential University business. Details about security incidents or investigations may also require protection, as can files containing multiple pieces of personal or confidential data. When there is uncertainty about whether something is sensitive, it should be treated as such and shared using an appropriate secure method.

Choose the Right Way to Share 

Sensitive information should not be sent through a regular, unencrypted email. Microsoft 365 provides secure options for exchanging confidential material, including encrypted email in Outlook and controlled file sharing through OneDrive and SharePoint. Before sharing sensitive information, consider which method provides the appropriate protection and confirm that it will only be accessible to the intended recipients.

Microsoft 365 email encryption helps protect sensitive information by restricting access to a message and its attachments. Depending on the information being shared, Outlook also provides options that can limit what recipients are able to do with the message, such as preventing it from being forwarded. When confidential information must be sent by email, encrypting an email in Outlook adds protection beyond a standard email.

For documents and other files, OneDrive or SharePoint can provide greater control over access than sending an attachment by email. When sharing sensitive material, permissions should be restricted to specific, intended recipients. The Anyone with the link sharing option should not be used for sensitive information because it allows anyone who obtains the link to access the file. Before sending a sharing link, review the permissions to confirm that access is limited to the appropriate individuals. 

Regardless of the method, security depends on more than the technology being used. An encrypted message can still be sent to the wrong address, and a file-sharing link is only as secure as its permissions. Taking a moment to confirm the recipient and review access before sharing can help prevent confidential data from reaching the wrong person. 

When in Doubt, Verify Before Sharing 

Cybersecurity Awareness Month is an opportunity to build habits that protect University and personal information throughout the year. Before sending sensitive data, consider what is being shared, who needs access and whether the method provides the appropriate level of protection. 

Questions about whether information is sensitive or how it should be shared securely can be directed to IT Security at [email protected]. 

Categories: Science and Technology