Secure collaboration and file sharing: cloud, email and messaging

For everyone who works in shared drives, email, chat and video meetings: share what is needed, with the right people, and keep the records your organization must keep.

For: All employees who use cloud storage, shared drives, email, workplace chat, business texting and video meetings

  • 2 contact hours
  • 6 modules
  • 8 interactives
  • 4 job aids
  • Updated October 11, 2026

What you will be able to do

  • Identify over-sharing risks in cloud tools and choose least-privilege link types, permissions, guest settings and expirations for a given file.
  • Apply safe email practices for recipients, Bcc, encryption, large files and background settings such as forwarding rules and out-of-office replies.
  • Determine whether a chat, texting or meeting tool is approved, explain why off-channel business communications violate recordkeeping rules, and obtain recording consent correctly.
  • Manage files across their lifecycle: version control, external partner sharing, retention and legal holds, connected apps, and access changes when people join, move or leave.
  • Respond to a mis-share, lost device or account misuse by containing, reporting promptly with accurate facts and supporting follow-up fixes.

Learn the everyday habits that keep work files and conversations from reaching the wrong people: choosing link types and permissions, handling guests, sending email safely, using only approved chat and texting tools, recording meetings lawfully, keeping one source of truth, and responding fast when something is shared by mistake.

Built for all staff, from front office to finance to field sales, in any organization that works in cloud office suites. Short scenarios set in real US workplaces show the decisions people face and what good choices look like, and you leave with a checklist, a policy starter, an incident worksheet and a quick-reference card.

Most data exposure at work is not hacking. It is ordinary sharing choices: an anyone link, an autocomplete error, a client text on a personal phone. This course explains the legal anchors where they apply (financial recordkeeping rules, recording consent laws, legal holds) and separates them clearly from good practice, so you know what is required and why it matters.

What you’ll be able to do Monday morning

  1. Share files with named people at view-only with an expiration instead of anyone links to folders.
  2. Add email recipients last, read full addresses and send sensitive data only by encryption or secure link.
  3. Move any client or customer conversation off personal apps and onto approved, recorded channels.
  4. Announce recordings and get everyone's consent, and check for AI note-takers before sensitive topics.
  5. Run a 10-minute review of what you have shared and remove stale links and guests.
  6. Report a mis-share or near miss by phone within minutes, with the facts written down.

Curriculum

6 modules · 24 lessons · about 2 contact hours

01Why does everyday file sharing go wrong?Free preview13 min
  1. What makes cloud collaboration risky?
  2. Who is responsible for what in a cloud tool?
  3. How do I judge the risk before I share?
  4. Which information needs extra care?
  • Matching activity: What does this sharing setting really allow?

Diagram · In practice checklist · 3-question knowledge check

02How do I set permissions and links safely?14 min
  1. What do the link types actually mean?
  2. How should guests and external users be handled?
  3. How do I check and clean up what I have already shared?
  4. How do shared drives, labels and sign-in settings help?
  • Spot the issue: Spot the risky entries in a sharing report

Diagram · In practice checklist · 3-question knowledge check

03How do I send email without leaking data?13 min
  1. Why are recipient mistakes so common?
  2. When does email need encryption, and how do I send large or sensitive files?
  3. What should Dov do, and what does a good email look like?
  4. What about forwarding rules, shared mailboxes and calendars?
  • Spot the issue: Spot the risks in this email draft

Diagram · In practice checklist · 2-question knowledge check

04Which chat and meeting tools may I use, and what must be kept?15 min
  1. Approved tools versus personal apps
  2. What are off-channel communications and why do regulators care?
  3. How do I run and record video meetings safely?
  4. How do I use chat well without creating risk?
  • State rules selector: Recording consent: look up a state
  • Sort activity: Approved channel or off-channel?

Diagram · In practice checklist · 3-question knowledge check

05How do I manage versions, partners, retention and offboarding?14 min
  1. How do I keep one source of truth?
  2. How should we share with outside partners and keep records the right length of time?
  3. What has to happen when people join, move or leave?
  4. What about third-party apps, connectors and browser extensions?
  • Decision tree: How should I share this with an outside partner?

Diagram · In practice checklist · 2-question knowledge check

06What do I do when something is shared with the wrong person?13 min
  1. Why does reporting fast matter?
  2. What are the first steps?
  3. How do we stop it happening again?
  4. What if a device is lost or my account is misused?
  • Branching scenario: Friday, 4:05 p.m.: wrong channel
  • Self-assessment: How safe are my sharing habits?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 70% to pass, then your certificate

Try it now, no account needed

Friday, 4:05 p.m.: wrong channel

A branching scenario from this course. Your choices are not saved.

Free sample activity

Friday, 4:05 p.m.: wrong channel

You are an HR coordinator. You just posted the salary-review spreadsheet for 60 employees in the all-company sales channel, which includes two distributor guests.

Inside the course

Practice activities

  • Matching activity1
  • Spot the issue2
  • State rules selector1
  • Sort activity1
  • Decision tree1
  • Branching scenario1
  • Self-assessment1

Job aids you keep

  • Secure Sharing ChecklistChecklist
  • Collaboration and Messaging Policy StarterPolicy starter
  • Mis-Share Scenario and Incident WorksheetWorksheet
  • Secure Collaboration Quick ReferencePocket card

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any licensing board, state agency or continuing education accreditor, and it is not a substitute for any firm-specific training your regulator or employer requires, such as a broker-dealer's supervisory training on its own communication policies. Check with your employer or professional body whether this course fits your training plan.

We may pursue review under IACET-aligned continuing education processes in the future. No such approval exists today; the course page will show an approval only after it is granted.

Our full approvals list

State notes

Most of this course is about practices that apply nationwide. Two areas vary by state:

  • Recording consent. Federal law (18 U.S.C. 2511(2)(d)) allows recording with one party's consent. Several states require the consent of all parties to a private or confidential conversation, including California (Penal Code 632), Florida (Statutes 934.03), Pennsylvania (18 Pa.C.S. 5703-5704), Washington (RCW 9.73.030), Maryland (Courts and Judicial Proceedings 10-402), Massachusetts (G.L. c. 272, section 99) and Illinois (720 ILCS 5/14-2). New York (Penal Law 250.00, 250.05) and Texas (Penal Code 16.02) are commonly cited one-party states. When participants are in different states, announce the recording and get everyone's consent.
  • Data breach notification. Every state has a breach notification law with its own definition of personal information, encryption safe harbor and deadlines. That is why mis-shares must be reported quickly so your organization can assess which laws apply. Breach law is covered in depth in a separate course.

Sector rules (financial recordkeeping, health privacy, student privacy) are federal and apply regardless of state. Ask your legal or compliance team about rules specific to your location and industry.

Questions about this course

Who is this course for?

Anyone who works in shared drives, email, workplace chat, business texting or video meetings: office staff, managers, sales, finance, HR and remote or hybrid employees. It is especially useful for people who share files with clients, vendors or partners outside the organization, and for team or site owners who are responsible for access reviews.

Does this course meet my firm's recordkeeping or supervisory training requirement?

It explains why regulated firms must capture business communications and what off-channel use looks like, but it does not replace training on your own firm's policies, approved tools and procedures. Your compliance department decides what satisfies its supervisory requirements. You can share the course outline with them and ask whether it fits their training plan.

Is this course specific to Microsoft 365 or Google Workspace?

No. It teaches decisions that apply in any cloud office suite: link types, permissions, guests, labels, email settings, chat and meetings. Labels in your tools may differ. Where helpful, it refers to CISA's Secure Cloud Business Applications (SCuBA) baselines, which cover common suites, but you do not need admin access or a particular product.

How long does it take, and what do I receive?

Plan on about two hours, including six modules, interactive exercises, knowledge checks and a final assessment. You need 70 percent on the final assessment to pass. You receive a certificate of completion for 2 contact hours of instruction, plus downloadable job aids you can keep.

Does this course cover state recording laws?

Yes, at an awareness level. It explains federal one-party consent and lists commonly cited all-party consent states with their statutes, and it includes a state lookup. Laws have details and exceptions, so for anything unusual, such as recording customer calls at scale, ask your legal team.

Is it approved for continuing education credit?

Not at this time. It awards a certificate of completion for 2 contact hours. It is not approved or accredited by any licensing board, state agency or accreditor. Check with your employer or professional body whether they accept it for your purposes.

This course is general education and training awareness from CE Courses Hub on secure collaboration and file sharing. It is not legal, medical or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.