Why Your Team’s Dropbox Habit Is Quietly CreatingProblems

Share this post

You might’ve hired a new staff accountant last month. She’s a sharp graduate, eager to help, already handling client work. Then yesterday, you discovered she’s been uploading client tax returns to her personal Dropbox account so she can work on them at home.

Your stomach sank. Not because she’s doing anything malicious, but because you just realized how little control you have over where your client data lives. This isn’t an isolated incident. If you walk into most small accounting firms, and you’ll find a patchwork of file sharing happening across personal Dropbox accounts, Google Drive, personal OneDrive, email attachments, and USB drives. Everyone’s just trying to get their work done, right?

The problem is that each of these workarounds creates a vulnerability you didn’t authorize, can’t monitor, and probably don’t even know exists.

What “It Just Works” Actually Leads To

What can happen is that your firm has some official file storage system. Maybe it’s a server in the office, maybe it’s a cloud service. But it’s clunky, or slow, or people forget their passwords, or the VPN is acting up again.

So, someone discovers they can just upload files to their personal Dropbox. It’s fast, it works from anywhere, and within a week, half the team is doing it too. It can seem that it is an easy way to solve the problem. But, a lot of people don’t realize that you’ve just created several problems that don’t show up until it’s too late:

Where is your data living?

When staff upload files to personal cloud accounts, that data lives outside your firm’s control. You can’t enforce encryption standards, can’t monitor who has access, and can’t ensure it gets deleted when someone leaves the firm.

Who else can see it?

Personal cloud accounts usually default to allowing file sharing with anyone who has a link. One accidental click and confidential client information is accessible to anyone on the internet. Even without that mistake, many personal accounts sync files to personal devices like home computers and phones that lack business-grade security.

What happens when someone leaves?

When an employee departs, you can revoke their access to company systems. But if client files live in their personal Dropbox account, those files leave with them. You’re now hoping a former employee remembers to delete work files from their personal account.

Can you prove compliance?

When cyber insurance providers or regulators ask about your data security practices, “we hope everyone’s being careful with their personal Dropbox accounts” isn’t an acceptable answer. You need to demonstrate actual control over client data.
“The risks are backed by research. According to CurrentWare, 83% of IT professionals report that employees store company data on unsanctioned cloud services. More concerning, when it comes to employee departures, data shows that workers are significantly more likely to take data with them when leaving a company, whether intentionally or accidentally. Even without malicious intent, when files live in personal accounts, firms lose all visibility and control over sensitive client information the moment an employee walks out the door.”

The Microsoft 365 Confusion

Many firms use Microsoft 365 and assume that means everyone’s OneDrive is under company control. Sometimes yes, sometimes no.

Microsoft 365 offers two types of OneDrive accounts. Business accounts are owned and controlled by your organization. Personal Microsoft accounts that happen to include OneDrive are not. If your team member signed up for a free Microsoft account years ago using their work email address, they might be saving work files to a personal OneDrive account that looks like it’s part of your business system but isn’t. Your IT team has zero visibility or control over these accounts.

The same confusion exists with Google Workspace. Just because someone uses their work email address doesn’t automatically mean the account is under your organization’s control. Personal Gmail accounts can use custom domain email addresses through Google, creating the appearance of a business account without actual business controls.
This gets even messier when firms transition from one email system to another. Staff who have personal accounts might keep using them alongside new business accounts, creating a split where some files live under company control and others don’t.

What Does Keep Your Data Secure

The solution is implementing file sharing that gives your team the convenience they need while giving you the control and security you’re responsible for maintaining.
Proper business file sharing includes several key elements:

Centralized control. Your IT team can see who has access to what, enforce security policies across all users, and ensure data stays within systems you control.

Automatic encryption. Files get encrypted both when stored and when transmitted, without requiring individual users to remember to do it.

Access logging. You have records showing who accessed which files and when. This matters for both security investigations and compliance documentation.

Departure procedures. When someone leaves, you can immediately revoke all access and ensure company data stays with the company.

Device management. You can enforce requirements like password protection on devices that access company data and can remotely wipe company data from a lost phone without touching personal information.

Compliance documentation. When cyber insurance providers, regulators, or clients ask about your data security practices, you have actual policies and technical controls to point to, not just hopes and good intentions. Solutions that provide these controls include properly configured Microsoft 365 with business accounts, Microsoft SharePoint, and specialized cloud services designed for professional firms.

The Human Side Nobody Talks About

If your team can’t reliably access files from home, they’ll find another way. If the VPN drops constantly, they’ll stop using it. If the official system takes five minutes to load a file that Dropbox loads instantly, they’ll use Dropbox. This means fixing the problem requires both better technology and better communication. You need to provide file sharing that’s convenient while explaining why it matters and making sure everyone knows how to use it properly.
Many firms approach this by first implementing the right technology, then conducting a simple training session showing staff how to properly share files within the company system. The conversation focuses on making their jobs easier while protecting client information, not on punishing people for past workarounds.

Some firms also include file sharing expectations in employment agreements and periodic security training. Not as a “gotcha” but as a clear standard everyone understands from day one.

What This Looks Like in Practice

A properly configured business file sharing system should feel almost invisible to your team. If someone needs to work from home, they can log into the company portal and access files exactly like they’re in the office. If someone needs to share a tax return with a client, they can use a secure client portal that creates a time-limited, encrypted link. And if a staff member leaves the firm, then their access can get revoked immediately and all company data stays exactly where it belongs.

The technical setup typically involves:

Setting up proper business cloud accounts for all staff, ensuring everyone has access to approved file storage, configuring security policies that enforce encryption and access controls, implementing tools that make secure file sharing as easy as using personal services, and establishing clear policies about where company data should live.
Most firms partner with IT providers who specialize in accounting firm needs and can handle both the technical setup and the ongoing management. The right provider can typically implement this within a few weeks, including migrating existing files from various personal accounts to a controlled business system.

Making the Decision

If you’re reading this and realizing your firm has a file sharing problem, you’re not alone. Most small accounting firms went through a period where personal cloud storage filled a real need before better solutions were in place.
Start by understanding your current situation. Where is client data living right now? Not where it’s supposed to be, but where it is. Talk with your team about how they’re accessing and sharing files. Most will be relieved someone’s finally addressing the awkward workarounds they’ve been using. Then implement a solution that balances security with convenience. Your team needs to work, and they need tools that help rather than hinder. But you also need to maintain proper control over sensitive client information.

The investment in proper file sharing infrastructure typically costs less than most firms expect, especially compared to the potential costs of data breach, compliance violation, or the simple operational chaos of not knowing where your files are.

Your clients trust you with their most sensitive financial information. Making sure that information stays secure isn’t just about checking compliance boxes. It’s about maintaining trust that makes your practice possible.
If you’re not confident you could answer “where is all our client data right now?” with complete accuracy, it might be time to have that conversation with someone who can help you fix it.

About Plus 1 Technology

Plus 1 Technology provides IT services exclusively for accounting firms. We help CPAs implement secure file sharing and cloud solutions that work the way your team actually works, without sacrificing the security your clients expect.

Share this post

Other Related Blogs

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.