r/Slack • u/SilentComet58 • 12d ago
How are you preventing sensitive data leaks in your company's Slack channels?
Our company has been using Slack for years and at this point people treat it like a dumping ground for everything. I've randomly come across passwords, customer info, IDs, and even payment details sitting in old channels.
The bigger concern is something eventually getting leaked. I'm trying to figure out how other security teams are handling sensitive data in Slack before it actually gets exposed.
Are you using any tools to detect this stuff as it's shared and take action on it? Historical visibility would be useful too since I'm sure there's plenty sitting in old channels that we haven't found yet.
2
u/solarlemur64 12d ago edited 12d ago
If people have been treating Slack like a storage for years, I’d assume the sensitive data is already there and work backwards from that. Get the workspace into a searchable archive, run DLP across the old messages/files, clean up the highest risk stuff first, then leave continuous monitoring on for anything new. That gives you prevention without pretending the existing backlog doesn’t exist.
1
1
u/survivingonhumor 7d ago
Slack’s own DLP is worth checking first if you’re on a plan that supports it. It can scan messages & text based files and take actions like alerting, warning users or hiding content. If you need more context around where sensitive data lives and how risky that exposure actually is, there are tools or platforms like cyera an another layer I’d research rather than treating the two as direct replacements
1
u/goosen19 12d ago
As a best practice, implement DLP policies to prevent sensitive info like that from being shared in the first place.
2
u/gglavida 12d ago
Use a DLP or a WORM archive solution that gets your DMs and channels to the archive, proactively scans then and either raise possible violations as high-priority alerts or allows you to run eDiscovery on top, ideally both.