Implementing a Secure Multi-Site Document Sharing Solution with SharePoint
In today’s digital landscape, businesses require robust, secure, and efficient solutions for sharing documents across multiple sites. This case study explores how we addressed such a need for a client already utilizing Office 365 for email by leveraging SharePoint, Microsoft’s comprehensive collaboration platform. Our approach focused on ensuring data security, version control, and compliance with Financial Conduct Authority (FCA) regulations.
Client Requirements and Challenges
Our client, an FCA-regulated business, sought a secure, multi-site solution for sharing Office documents among users. Key requirements included:
- Version Control: The ability to track and manage document changes, akin to the ‘Track Changes’ feature in Word, with the added necessity that users could not disable this functionality.
- Data Security Compliance: Adherence to FCA guidelines to ensure the protection of sensitive financial data.
- Principle of Least Privilege (PoLP): Implementing strict access controls to minimize potential attack vectors, thereby reducing the impact of cyber threats.

Choosing SharePoint as the Solution
Given the client’s existing use of Office 365, SharePoint emerged as the natural choice. SharePoint offers a suite of features that align with the client’s requirements:
- Versioning: SharePoint’s version history allows users to view and restore previous document versions, ensuring comprehensive change tracking.
- Auditing and Compliance: SharePoint provides extensive auditing capabilities, enabling organizations to monitor document access, modifications, and deletions, which is crucial for compliance reporting.
- Access Control: SharePoint supports granular permissions, ensuring that only authorized users can access or modify specific documents, aligning with the PoLP.
Implementing the Solution
Our implementation strategy encompassed several critical steps:
- User Education and Training: Recognizing that SharePoint’s interface and functionalities differ from traditional file systems, we conducted comprehensive training sessions. This initiative aimed to facilitate a smooth transition and enhance user adoption.
- Auditing Configuration: We configured SharePoint’s auditing features to monitor and log all document-related activities. This setup ensures that any unauthorized access or modifications are promptly detected and addressed.
- Access Control Implementation: Applying the PoLP, we meticulously set up permissions to restrict access to documents based on user roles and responsibilities. This approach minimizes the risk of data breaches and ensures compliance with FCA regulations.
- Change Management: To ensure a seamless transition, we established a change management plan that included regular consultations with key user groups. These groups participated in beta testing, providing valuable feedback that informed the final deployment.

Benefits Realized
The implementation of SharePoint yielded several significant benefits:
- Enhanced Data Security: By adhering to the PoLP and configuring SharePoint’s security features, we significantly reduced potential attack vectors, thereby enhancing the organization’s overall data security posture.
- Improved Compliance: The auditing capabilities of SharePoint enabled the organization to maintain detailed records of document access and modifications, facilitating compliance with FCA regulations.
- Streamlined Document Management: Version control and access management features improved document collaboration and management, leading to increased operational efficiency.
Conclusion
Implementing SharePoint as a secure, multi-site document sharing solution effectively addressed our client’s requirements for version control, data security, and compliance with FCA regulations and good cyber security practice. By focusing on user education, auditing, access control, and change management, we ensured a successful deployment that enhanced data security and operational efficiency.


