How secure is a platform the moment it connects to everything else?

0
9

By Benjamin Schilz, CEO, Wire

For years, enterprise collaboration platforms have positioned themselves as productivity enablers. The ability to connect messaging with CRM systems, project management software, document repositories, customer support platforms, AI assistants and workflow automation tools has transformed them into the operational hubs of modern organisations.

Every integration promises to eliminate manual work and help employees make better decisions faster. As a result, collaboration platforms have evolved from simple communication tools into the digital backbone of day-to-day business operations.

Join The European Business Briefing

New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.

Subscribe

From a productivity perspective, that evolution has been enormously successful. From a security perspective, however, it has introduced a problem that many organisations have yet to fully recognise. In Wire’s latest research, 84% of IT professionals said they were confident in the security of their collaboration environment, yet only 29% believed their collaboration tools were fully suitable for handling sensitive communications. The gap suggests organisations often trust the platform itself while overlooking the risks created by the wider ecosystem surrounding it.

Much of the discussion around collaboration security still focuses on familiar concepts such as end-to-end encryption, identity management, multi-factor authentication and secure cloud infrastructure. These remain essential, but they primarily protect the collaboration platform itself. The greater challenge lies beyond the platform, where information is continuously exchanged with dozens, sometimes hundreds, of connected services.

Every API connection, chatbot, workflow automation or AI assistant extends the boundary of the collaboration environment, creating another route through which sensitive information can be accessed, processed or shared. Individually these integrations appear low risk because they are trusted, approved and designed to improve business processes. Collectively, however, they create a far larger attack surface than many organisations realise.

Security doesn’t end where encryption begins

Organisations increasingly expect messages to remain protected while in transit and at rest. Yet encryption only protects information while it remains inside the protected environment. The moment data is decrypted so that an external application can analyse it, classify it, summarise it or trigger a workflow, many of those security guarantees disappear.

That doesn’t necessarily indicate poor security on the part of the third-party service. Most reputable SaaS vendors invest heavily in protecting their own environments. The issue is architectural. Once information leaves its original encrypted context, organisations become dependent on another provider’s security model, governance controls, retention policies and access management. The result is a chain of trust that is only as strong as its weakest participant.

The consequences are already visible. Wire’s research found that 61% of organisations say access to shared files often remains active longer than necessary, while 34% struggle to determine who has access to sensitive information. These are governance failures rather than encryption failures, and they become increasingly difficult to manage as more integrations are added.

This challenge becomes even more significant as organisations embrace AI-powered productivity tools. AI assistants are designed to consume context from conversations, documents, calendars and business applications in order to generate useful responses. The more context they receive, the more valuable they become. Unfortunately, the opposite is also true from a security perspective.

The more systems capable of accessing business conversations, the greater the opportunity for commercially sensitive information to be exposed, retained or processed in ways security teams may struggle to monitor.

Productivity has outpaced governance

Organisations do not deliberately create insecure collaboration environments. Risk accumulates gradually. A marketing team connects campaign management software. Finance links approval workflows. HR integrates recruitment systems. Customer support adds ticketing platforms. Sales enables CRM notifications. Then AI assistants arrive to summarise conversations, draft responses and retrieve information from multiple business systems simultaneously. Rarely does anyone step back to assess what those dozens of integrations collectively mean for the confidentiality of business communications.

The challenge is compounded by the fact that responsibility for integrations is often distributed across departments. Individual teams authorise connectors to improve productivity, while security teams may only gain visibility after the connections have already become business critical.

This is precisely the risk the UK’s National Cyber Security Centre highlights in its supply chain guidance: organisations often have strong controls over their own systems while lacking visibility into the third parties connected to them. In a collaboration context, every integration is a small supply chain of its own.

The collaboration platform itself may be tightly governed, but the growing network of connected applications often develops with far less oversight.

Extensibility was always sold as an advantage

This raises a broader question for the industry. If every integration requires sensitive information to leave an encrypted environment in order to function, can we really claim that enterprise collaboration is secure?

The challenge becomes even greater when organisations collaborate beyond their own boundaries. Yet Wire’s research found that only 28% use a secure collaboration platform when working with external partners, despite those partners often operating under different security policies, governance processes and compliance obligations.

For many years, extensibility has been viewed almost exclusively as a competitive advantage. The larger the integration marketplace, the more attractive the platform became. Perhaps it is time to evaluate integrations differently.

Rather than asking how many services can be connected, organisations should ask whether those services can participate without weakening the security guarantees that made the platform trustworthy in the first place.

That requires security to become an architectural property of the entire collaboration ecosystem rather than a feature of the messaging application alone. The objective should no longer be to secure communications before they reach third-party services. It should be to minimise the number of situations in which sensitive information needs to leave its protected environment at all.

A different design philosophy

Encouragingly, a different design philosophy is starting to appear. Instead of treating integrations as external services that retrieve decrypted information through APIs, newer approaches seek to make extensions participants within the encrypted collaboration environment itself. Rather than exporting conversations to multiple connected systems, functionality can be brought into the protected workspace where processing occurs without unnecessarily exposing the underlying data.

 

As AI becomes embedded across virtually every business function, this distinction will become increasingly important. Future collaboration platforms will not simply connect people with applications; they will connect autonomous software agents, automated workflows and intelligent assistants that continuously exchange business context at machine speed.

Securing that future cannot rely solely on stronger authentication or better encryption algorithms. It requires rethinking where trust exists within the collaboration architecture itself.

For security leaders, the practical question is no longer whether their collaboration platform is encrypted. It is how much sensitive information leaves that protected environment every day, through how many connections, and under whose control. Organisations that can answer that clearly will be the ones still in control of their data as AI pushes collaboration to machine speed.

LEAVE A REPLY

Please enter your comment!
Please enter your name here