The SharePoint Iceberg: Why AI is Bringing Decades of Bad Governance Home to Roost
Transcript
Hey guys. Thanks for the intro. We're here with Andy Serwach, who's technical evangelist for Hornet Security, and while we're having a little chat about the trouble with Microsoft SharePoint.
You may have all forgotten about it, but it's still out there and still widely used and, well, surprise, surprise, there are security issues. Andy, welcome to the show. Hey, appreciate you having us, and good to be here.
So what exactly is going on here with SharePoint? There seems to be a lot of users, people logging in, maybe guest accounts and stuff that we haven't paid a lot of attention to over the years that's going to come back and bite us. So dive in a little bit here, will you?
Yeah. So SharePoint and I go way back. I remember installing SharePoint Portal Server back in 2007 or something like that.
And of course, back then, SharePoint primarily lived on premises, right? It always started as an on-premises technology. And while Microsoft, over the years, they've kind of shoehorned it into being a cloud product, right?
And that's why we have SharePoint online today. And the way that I've always described the problem that you're getting at, Mike, is, I guess I call it the SharePoint iceberg, right? With an iceberg, you can only see a portion of the iceberg, right?
And with SharePoint Online, it's so easy to share files. Every Office application has that Share button in the top right corner. And it's great, don't get me wrong, but it creates a problem.
And so over time, oversharing happens, right? Permissions get out of whack. Microsoft doesn't provide a lot of great tools in 365, native tools to help admins wrap their hands around that.
And so it creates this oversharing problem, this potential data leakage problem. And because it's in the cloud, that complicates the security model even further. And so, the tools only allow you to see the tip of the iceberg, right?
Once you start peeling away the layers and start seeing how bad the problem really is, you find out that, hey, this is a much bigger problem than we originally thought. And so, yeah, that's kind of where we're at here with SharePoint. And of course, AI makes it even worse, so.
So are the bad guys aware of this? Are they targeting SharePoint? Is it, from their perspective, just easy pickings?
Well, it can go both ways. So I've seen this issue crop up from both an insider threat perspective, either a true insider threat, or maybe you just have a snoopy end user that's trying to poke around and maybe find stuff that they shouldn't have access to. And I've been in IT for 25 years.
I have yet to see an organization properly manage their SharePoint Online and OneDrive for Business permissions. And let's talk about Copilot for a second here as part of this conversation. So Copilot, for 365, is a great tool.
It does a lot of stuff. It helps with business processes. I'm not vilifying Copilot at all.
But in terms of this particular conversation, Copilot will surface anything it deems relevant that the user has access to. And you have some SharePoint environments that have been out there for 10 years now, right? And again, I just got done saying that there are no good native inbox tools to help manage permissions across that SharePoint environment.
So Copilot often surfaces things that the user finds out they have access to that they shouldn't, and it does it in sometimes surprising ways, right? "Oh, hey, there's a salary spreadsheet that it just gave me. " Right?
Now, that's from an insider perspective. To answer your question about threat actors, here at Hornet Security by Proofpoint, one of the most common things that we've seen in terms of attack lately is the use of reverse proxy phishing kits, which steals end user credentials for 365. Now, if I'm an attacker and I gain access to somebody's 365 account, and I find out that there's a Copilot license enabled inside of this account, as the attacker, now I can use Copilot to help do internal reconnaissance of the target's 365 environment.
So it absolutely can be used by threat actors, but it has to be a case where there's a compromised account, right? Is that going to become a lot more common these days? Because it seems to me like the bad guys are credentials left, right, and center, but now they're going to go after our AI agents that inherited all our permissions, right?
Right. Everything I've said so far takes into account Copilot just being Copilot as we've known it to date, right? Just a simple chatbot.
Well, Microsoft has been rolling out agentic AI, right? So AI agents that can do things on our behalf. And as a security industry, yeah, we're still kind of wrapping our hands around what this new threat model looks like.
Now we don't just have to worry about end users and securing end user behavior, we have to worry about agentic AI behavior as well, too, right? And so it's definitely changing the game, and I think it remains to be seen exactly what the impact is going to be in terms of securing SharePoint. But there certainly will be an agentic security factor in the coming months and years, regarding SharePoint and OneDrive for Business, I'm sure.
Who's in charge of this? Is it the security people, or is it the folks who deployed in the IT department, SharePoint in the first place? Because it seems to me that those two aren't always on the same page.
That's very true. It's always this constant push and pull between ease of use and security, right? And really what I've seen from my seat in the industry is thatIt comes down to the organization itself, right?
You might have your SMBs and your mid-market companies that they only have one or a few IT people, and they're probably the sys admin and the database admin and the storage admin and the kitchen sink admin and everything, right? And in those situations, it's even more difficult for those organizations to really lock down their SharePoint and OneDrive environments. In the larger organizations, yes, you'll probably have a dedicated security team that has their eye on this.
And so I think to give you a more crisp answer here, I think ultimately when we talk about who's responsible for taking care of it, I see this as being cleaned up as part of a security team initiative. Or maybe you're a smaller organization, you partner with a service provider or a security service provider that helps you lock this down on a per project basis. And then ongoing, logic needs to be built into the business, processes need to be built into the business.
Maybe some products need to be procured in order to help your business maintain that new reduced permission state ongoing from there, so you don't end up having the same problem a year or two later. Is it worth keeping SharePoint, or should people be thinking about different platforms, or are they? Or will people look at this whole AI and security issue and kind of wonder if the time has come to maybe think about some other way of doing all this?
That's a good question, and to be clear, I'm not vilifying SharePoint in any way, shape, or form here. I've got enough gray hair in my beard to remember how we used to do things. We used to have file servers on premises.
We only had to worry about security within the four walls of our building. Well, we found out very quickly during the cloud era that that model doesn't always work the best, and so that's why we have things like SharePoint and OneDrive. And when we talk about file storage in the cloud era, they do a great job at that.
It's just the security model is vastly different than what we've had to deal with historically as an industry. So, SharePoint absolutely can be a very effective storage platform for businesses. It just has to be managed and secured properly just like anything else, right?
It also seems, though, what you said, right? The enemy of security is integration. Looks like in the age of AI at least, we're going to have more integration than ever, so are some of these attacks we're going to see maybe the blast radius is going to be a lot wider than any of us anticipate.
Absolutely. Absolutely, and that's all the more reason to make sure you really understand the full size of that iceberg, that SharePoint iceberg I was talking about earlier, right? Because when we talk about securing our cloud files, again, I mentioned earlier how AI agents, we don't fully understand the security model there yet.
The industry, we're still learning what that looks like. For example, I think it was a researcher at Google, if I remember correctly, an AI researcher. They were testing out AI agents, and despite their pleading, they had an AI agent nuke their entire inbox, even though they told it to stop, right?
And so that's my point is that AI agents often behave in a way that we don't fully anticipate. And so when we talk about security, in order to secure something, I have to fully understand how that thing works, AI agents being the case right now, and as an industry, we're still learning how that works. And so I think solutions are going to be developed to combat that, keep an eye on that.
But in terms of SharePoint and OneDrive for Business, one of the best things that you can do right now is adopt a zero trust policy and a policy of least access, right? Only give people access to what they absolutely need to do their jobs with the idea that when it comes time to start securing things more focused on the AI agent standpoint, some of the work will already be done as part of your efforts to reduce that security footprint, right? A lot of SharePoint, when you look at it, it's a digital file cabinet.
But I wonder if we have too much stuff in our file cabinet and we just didn't go in there and delete enough stuff over the years because there's probably stuff in there that we don't need. We can certainly get rid of it, and it's just going to cause more problems for AI agents that are going to get confused about which data set to access anyway. Yes, very true.
I forget what the statistic is. It's changed many times over the years, but the growth of overall data year over year has been accelerating probably for the last decade since I've been keeping tabs on it, right? And businesses do what businesses do.
Business happens, your projects happen, and all the files that were associated with that project get left behind when the project's done with. Or you have the compliance and regulatory side of things as well, too, where as a business, if I have to adhere to, I don't know, CMMC or HIPAA or whatever, I have to retain all my files basically for a set period of time. And so regulatory bodies aren't helping with that data sprawl issue either.
But if you are in a position where you have files or data sets with sensitive information that you don't need anymore, yeah, by all means, if you don't need them anymore, get rid of them because they can be a liability if they're not managed properly. And if they're just not there, well, you don't have to worry about them. But again, not every business can do that.
A lot of businesses have to retain all that information. So what's your best advice to folks about how to go after all this or think about it? Because I think sometimes people look at a task like this and they go, "Well, it's one of those things that's easier said than done, and once I get into it, it's a lot bigger project than I bargained for.
" Yeah, that's a good question. And so, again, talking about SharePoint and OneDrive for Business specifically, you heard me mention OneDrive a couple of times because it's SharePoint Online under the hood. And so the two kind of get mixed in with each other.
But to get your hands wrapped around that, just like anything, you first have to understand what you have. You need an image of where you are as an organization. And there are some tools in Box that allow you to kind of get a picture of what you have in terms of SharePoint Online, in terms of permissions, in terms of the folder structure.
But a lot of times you'll need some sort of third-party tool to go out and get a nice snapshot of where you're at currently inside of SharePoint. And then you need to talk with stakeholders within your organization to understand how things should be in terms of your SharePoint hierarchy and permissions. Because, for example, as an IT person looking at, I don't know, an accounting library in SharePoint, I can make assumptions on how I, as the IT person, think that this folder should be set up and secured.
I don't understand the data, though. Only the people in accounting really understand the data and who needs access to what. So it's not just an IT conversation, it's a business conversation as well, too.
And so once you have where you're at, where you want to be, now you can start taking concerted efforts to get there. But that's not the end of the story. Once you're there, you need to have a plan in place to maintain that, because you don't want to have this problem again.
All right, folks. Hey, when you think about it, a lot of the issues that pertain to SharePoint have been around forever, and we've just kind of been ignoring them. The problem now is AI is bringing them all home to roost.
Hey, Andy, thanks for being on the show. Yeah, appreciate it. Thanks for having us.
All right. And back to you guys in the studio.