Back to Resources

The Complete Guide to Slack Security & Best Practices

The Complete Guide to Slack Security & Best Practices

Slack is an essential tool for many businesses, but it can also create security vulnerabilities if the appropriate security controls are not in place. These weaknesses can include an increased risk of social engineering, account theft, or unintentional public data exposure. To compound the issue, threat actors have been known to use Slack accounts to impersonate users within an organization in order to gain further access. A recent example occurred at Electronic Arts (EA) when attackers purchased a stolen Slack cookie, allowing them to send messages to IT support members requesting MFA codes, claiming they had lost their phone and needed to access the EA corporate network. This resulted in the loss of the source code for FIFA 21 and the source code for the Frostbite engine. This blog will cover security best practices for Slack and introduce a free tool that can be used to audit over 100 SaaS apps (including SaaS apps) for even more best practices.

1. Require Admin Approval for New Invites

Enabling users to invite anyone can result in unanticipated billing hikes and potential unauthorized access. If an attacker gains access to your workspace, they may try to stay undetected by inviting another user account, leading to additional, unnoticed users. To address this, Slack provides the option to mandate admin approval for new invitations, allowing you to review and authorize user addition requests.

Require admin approval for workspace invitations (Slack Help Center)

2. Restrict Slack Connect for Direct Messages

By default, everyone except guests can start DMs from external organizations that may not be connected to your Slack Connect. This poses a security risk as members from external organizations may attempt to use this method to social engineer your users. Disabling this setting may impact some legitimate use cases – but your users can still connect and talk with organizations a workspace admin or owner has added.

Manage settings and permissions for Slack Connect direct messages (Slack Help Center)

3. Disable Direct Message Invitations from Unverified Organizations

Unverified organizations may indicate newly created (or malicious) Slack workspaces which may intend to message your users (or entice them to accept a conversation) to further social engineer them. Disabling direct messaging will mitigate this risk and only allow verified organizations to directly message members.

Verified organizations (Slack Help Center)

4. Enforce Multi-Factor Authentication (MFA)

Enforcing MFA adds an essential layer of security to your Slack accounts. Even if a user’s password is compromised, MFA ensures that the attacker cannot access the account without the second authentication factor preventing unauthorized access to your workspace.

Mandatory workspace two-factor authentication (Slack Help Center)

5. Require App Approval

“Consent phishing” is a technique where attackers disguise malicious apps as legitimate ones, hoping that users will accept them. Allowing any user to accept apps can lead to potentially malicious applications performing actions in your Slack workspace, such as reading messages or carrying out other malicious activities. To reduce this risk, enable app approval and allow users to request adding apps. As an admin reviewing app approval, make sure to verify the identity of the application and the permissions it is requesting. For instance, if a supposed Calendar integration is asking to read your files and messages, it should raise red flags. Always assess consent permissions, even for legitimate applications.

Add files to Slack (Slack Help Center) Free Security Awareness Training (Including Consent Phishing and other topics)

Manage app approval for your workspace (Slack Help Center)

6. Disable Public File Sharing

Slack members can unintentionally share files externally from the Slack channel, leading to potential data loss or exposure. It’s important to outline in your Data Management policy the proper procedures for sharing files externally, such as uploading them to SharePoint and specifying the intended recipient, rather than allowing public sharing.

Add files to Slack (Slack Help Center) Crafting & Implementing A Data Management Policy (WatchDog Security)

7. Configure Session Timeout

This recommendation is specifically for larger organizations with multiple departments and business processes. For organizations falling under this category, typically mid-to-large enterprises, setting up a session timeout for Slack to invalidate cookies is possible. This means that if a user’s cookies are stolen and used or sold on the dark web, they will only be valid for a shorter period. By default, sessions do not expire, and cookies associated with users are permanent, which poses significant security risks.

Manage session duration (Slack Help Center)

Total visibility. Zero blind spots. WatchDog helps you monitor every user, service account, and system across Cloud, SaaS, and devices -flagging misconfigurations and risks the moment they arise.

  • âž• Asset management – Add and track your own assets easily across Cloud, SaaS + On-Prem
  • Identity monitoring – Limited to Google Workspace & M365 Non-Human Identities on free plan
  • đź”§ SaaS + Cloud hardening checks – Spot misconfigurations before they become risks

Get started free today – no credit card required.