Security Leaders Are Overconfident — and That’s a Problem
A fresh survey out of Europe drops a troubling finding: most security leaders think their collaboration tools are safer than they actually are. The report, conducted by Cybersecurity Intelligence and released this week, surveyed over 400 CISOs and security managers across the continent. The result? A clear collaboration security gap between perception and reality.
It’s not that companies aren’t using tools like Microsoft Teams, Slack, or Zoom. They are — heavily. But the confidence those tools inspire may be misplaced. The data shows a dangerous mismatch: executives assume their platforms are locked down, while actual vulnerabilities remain wide open.
The Numbers Behind the Confidence Gap
Here’s the raw data. Nearly 70% of respondents rated their collaboration security as “good” or “excellent.” Yet fewer than 40% had actually conducted a dedicated security audit of those same platforms in the past year. That’s a 30-point gap — and it’s exactly where breaches happen.
Another number jumps out: 1 in 3 organizations admitted they don’t monitor third-party app integrations within their collaboration tools at all. Think about that. Bots, plugins, and external connectors can siphon data or introduce malware. And a third of firms simply don’t check.
Phishing attacks via collaboration channels are also on the rise. The survey found that 45% of European organizations experienced a phishing attempt through Teams or Slack in the last 12 months. Yet only half of those companies have specific policies for handling such incidents within chat apps.
Why Collaboration Tools Are a Blind Spot
Part of the problem is history. Collaboration platforms were adopted fast, often without security teams at the table. IT bought Slack or Zoom to keep people working remotely. Security was an afterthought.
Now those tools are deeply embedded. They host sensitive files, financial data, and internal strategy discussions. But the security models around them haven’t caught up. Many organizations still treat collaboration security as an extension of email security — and that’s a mistake.
“The threat surface has shifted,” says Maria Torres, a cybersecurity analyst at Gartner. “Attackers know that chat platforms are less monitored than email. They’re exploiting that.” Torres points out that collaboration tools often lack the same spam filters, link scanners, and attachment sandboxing that email has had for years.
What European Organizations Can Do About It
Closing the collaboration security gap doesn’t require a complete overhaul. But it does demand targeted action. Here are four steps the survey suggests:
- Conduct regular audits. Schedule a dedicated security review of every collaboration platform at least once a year. Include all integrations, bots, and external access points.
- Enforce least-privilege access. Not every employee needs admin rights to Teams or Slack. Restrict permissions to only what’s necessary for each role.
- Train employees on platform-specific threats. Generic phishing training isn’t enough. Show staff what a malicious link looks like inside a chat message versus email.
- Monitor third-party apps. Inventory every plugin and connector. Remove unused ones. Block risky categories like unverified file-sharing apps.
Some firms are already moving. A handful of European banks and healthcare providers have started using dedicated collaboration security tools — purpose-built software that sits between the user and the platform, scanning for anomalies. That’s a smart investment, but it’s still rare.
The Bottom Line: Confidence Isn’t Security
The takeaway from this survey is simple but uncomfortable. Feeling safe about your collaboration tools doesn’t mean you are safe. The gap between perception and reality is real, and it’s wide.
European organizations need to stop assuming their chat apps are secure by default. They need to audit, monitor, and train — just like they do for email and networks. The collaboration security gap won’t close on its own. Attackers are already counting on that.
For more on securing digital workspaces, see our guide on collaboration platform best practices and the latest enterprise security trends.