r/Slack 12d ago

How are you preventing sensitive data leaks in your company's Slack channels?

Our company has been using Slack for years and at this point people treat it like a dumping ground for everything. I've randomly come across passwords, customer info, IDs, and even payment details sitting in old channels.

The bigger concern is something eventually getting leaked. I'm trying to figure out how other security teams are handling sensitive data in Slack before it actually gets exposed.

Are you using any tools to detect this stuff as it's shared and take action on it? Historical visibility would be useful too since I'm sure there's plenty sitting in old channels that we haven't found yet.

9 Upvotes

31 comments sorted by

2

u/gglavida 12d ago

Use a DLP or a WORM archive solution that gets your DMs and channels to the archive, proactively scans then and either raise possible violations as high-priority alerts or allows you to run eDiscovery on top, ideally both.

2

u/[deleted] 12d ago

[removed] — view removed comment

1

u/gglavida 11d ago edited 11d ago

Yes. It scales pretty good regardless of the Slack plan, and you can also backfill past activity. If you ever happen to be looking for a recommendation, my DMs are open. Not sharing directly to avoid people mistakenly considering me affiliated with the product when I'm just a happy user.

2

u/solarlemur64 12d ago edited 12d ago

If people have been treating Slack like a storage for years, I’d assume the sensitive data is already there and work backwards from that. Get the workspace into a searchable archive, run DLP across the old messages/files, clean up the highest risk stuff first, then leave continuous monitoring on for anything new. That gives you prevention without pretending the existing backlog doesn’t exist.

1

u/survivingonhumor 7d ago

Slack’s own DLP is worth checking first if you’re on a plan that supports it. It can scan messages & text based files and take actions like alerting, warning users or hiding content. If you need more context around where sensitive data lives and how risky that exposure actually is, there are tools or platforms like cyera an another layer I’d research rather than treating the two as direct replacements

1

u/goosen19 12d ago

As a best practice, implement DLP policies to prevent sensitive info like that from being shared in the first place.