Handling and security Current

Handling sensitive documents shared by email safely

A practical approach for the most common channel clients actually use.

Clients will send sensitive documents by email whether or not it's your firm's preferred channel. This guide sets out a practical approach to accepting and handling them safely when they do. It is general information, not IT security advice.

Action plan

1 Verify the sender before trusting an unexpected attachment Business email compromise relies on a message looking like it's from someone you trust.

ACSC's guidance on preventing business email compromise describes how criminals impersonate business representatives using compromised email accounts or lookalike domain names, and recommends that staff who receive an unusual or unexpected request find out if the email is genuinely legitimate before actioning it. Apply the same principle to an unexpected sensitive attachment: if anything about the sender or the message looks off, verify directly with the client through a separate channel before opening or relying on it.

  • Check the sender's domain name carefully for lookalike substitutions
  • Verify directly with the client through a separate channel if anything looks unexpected
  • Treat an unexpected sensitive attachment with the same caution as any other unusual or unexpected request

Done when: The sender has been verified before an unexpected sensitive attachment was trusted

ACSC: preventing business email compromise
2 Move the document out of the inbox into controlled storage promptly An inbox is not designed to be the long-term home for sensitive client documents.

Once verified, move the document into your firm's controlled, secured storage system rather than leaving it sitting in an inbox, where it's easier to lose track of, accidentally forward, or leave exposed to whoever else has inbox access.

  • Move the document into controlled storage rather than leaving it in the inbox
  • Apply the same baseline security controls to that storage as any other sensitive record
  • Delete or archive the email copy once the document is safely stored

Done when: The document has been moved from the inbox into controlled, secured storage

See storing client identity evidence securely
3 Apply baseline security controls to the mailbox that receives them The mailbox itself is part of what needs securing, not just what's done with the document afterward.

The mailbox that receives sensitive attachments should itself carry the relevant baseline controls, particularly multi-factor authentication, so that a compromised mailbox doesn't become the weak point that exposes every document sent to it.

  • Confirm multi-factor authentication is enabled on mailboxes that receive sensitive documents
  • Apply the relevant Essential Eight controls to the mail system generally
  • Review who has access to a shared mailbox that receives sensitive documents

Done when: Baseline security controls, including MFA, are confirmed on the mailbox receiving sensitive documents

ACSC: Essential Eight explained