Five habits that keep file server access from spiralling out of control
A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

Key points
- File servers, the shared drives where staff keep documents, still hold much of the working data inside most companies.
- Permissions drift over time as people change jobs, projects end, and old access is rarely revoked.
- The Austrian software firm tenfold recommends five habits to keep access tight, including regular reviews and clear ownership of folders.
- Least-privilege access, meaning each person can only open what their job requires, remains the single biggest defence against ransomware spreading.
- Automated tools can flag risky permissions faster than manual audits, but the discipline still has to come from management.
File servers sound like something from an earlier decade. They are not.
Walk into almost any hospital, law firm or council office and you will find a shared drive stuffed with contracts, patient notes, HR files and finance spreadsheets. Staff open them every day without thinking. That quiet middle layer of company life is exactly where ransomware, the kind of malicious software that scrambles files and demands payment, does the most damage when it gets in.
A new guide from tenfold Software, an Austrian identity management vendor, argues that most of the risk comes from something duller than hacking: permissions that were handed out years ago and never taken back. The guide was first flagged by BleepingComputer.
Why do file server permissions get so messy?
Because people move around and access rarely follows them. Someone joins the marketing team, gets added to a folder, moves to sales, keeps the old access, then covers for a colleague in finance and picks up more. Multiply that by a few hundred staff over five years and the picture gets ugly fast.
When a criminal steals one employee's password, they inherit every folder that employee can reach. If that employee has quietly accumulated access to payroll, client contracts and the backup share, the attacker has a very good day.
What are the five habits tenfold recommends?
The short version is: know what you have, give out less, review often, assign owners, and automate the paperwork.
| Habit | What it means in plain English |
|---|---|
| Map your data | Know which folders exist and what sits inside them |
| Least privilege | Give each person the minimum access their job needs |
| Regular reviews | Check permissions on a schedule, not after an incident |
| Data owners | Name a person in the business responsible for each folder |
| Automation | Use tools to grant, revoke and log access consistently |
None of this is glamorous. That is rather the point.
Who should actually own a folder?
Not the IT team. The person in the business who understands what the files are for. IT can set up the permissions, but only the head of HR knows who should see salary data, and only the finance director knows who belongs in the audit folder.
When ownership sits with IT by default, requests get rubber-stamped because the ticket queue is long and nobody in IT wants to be the person blocking the sales team on a Friday afternoon. Named business owners break that pattern.
Does automation really help, or is it just another product to buy?
It helps when the manual version has already collapsed. A team of two administrators looking after twenty thousand folders cannot review access by hand, so they stop trying. Software that lists who has access to what, flags dormant accounts, and routes approval requests to the right owner turns a task that never gets done into one that does.
The caveat: a tool without a policy behind it just automates the mess.
What ordinary staff can do
If you use a shared drive at work, two small habits matter. Do not save personal copies of sensitive files to your own desktop, and tell IT when you change roles so old access can be removed. That is it. The heavy lifting sits with the people running the servers, but attackers count on staff hoarding access quietly, and they are usually right.
File servers are not going anywhere. Neither is the ransomware crews' interest in them.



