Cybersecurity & Data Protection Blog | CyberGrant

CyberGrant Launches Connector for SharePoint and OneDrive

Written by CyberGrant Team | Sep 29, 2026, 1:07:04 PM

CyberGrant Launches Connector, Bringing File-Centric Encryption Inside SharePoint and OneDrive

The new product keeps documents protected after download and sync, with no migration and no change to file formats, permissions, or the way people work

Connector arrives during European Cybersecurity Month and on the eve of Italy's October 31 NIS2 deadline

MENLO PARK, Calif., and MILAN, Sept. 28, 2026 - The human element shows up in 62% of the breaches analyzed in Verizon's 2026 Data Breach Investigations Report. In the same edition, breaches involving vendors and other third parties climbed from 30% to 48%. Those numbers describe a way of working in which documents move every day across cloud platforms, corporate devices, and outside collaborators, on the assumption of a protection level that often is not there. The financial side is just as concrete: IBM's Cost of a Data Breach Report 2025 puts the global average cost of a breach at $4.44 million, and organizations with heavy use of unauthorized AI tools pay roughly $670,000 more. The exposure starts with the most ordinary actions. Saving a file to a laptop, syncing it to a personal device, sending it to someone outside the company: routine gestures that, once the document leaves the corporate perimeter, fall outside any control.

The timing sharpens the point. October is European Cybersecurity Month, the annual campaign ENISA and the European Commission run to promote cybersecurity awareness. In Italy, October 31, 2026 is also the deadline by which essential and important entities already inside the NIS2 scope must have adopted the baseline security measures defined by the National Cybersecurity Agency (ACN), encryption policies among them.

Encryption moves into the workflow

That is the context for Connector, the new product from CyberGrant, a company focused on file-centric protection and data loss prevention. Connector brings file-centric encryption directly into SharePoint and OneDrive. Files stay in the SharePoint libraries where they already live, with their existing extensions and access permissions: no migration is required. Protection does not stop at the corporate perimeter either. It stays bound to the document when the file is downloaded, synced to another device, or shared externally, so organizations can keep collaborating without losing control of the information.

Connector is built for organizations running SharePoint and OneDrive that want to extend protection to the confidential files they handle, covering download, sync, and sharing. It asks nothing new of daily habits. An administrator selects the sites or folders to protect, and Connector automatically encrypts every file in those areas. Scope covers Office documents, PDFs, images, design files, and source code, with no change to the file extension. That last detail is not a given: other encryption tools rename protected files, require a dedicated viewer to open them, or come with steep licensing costs. On an unauthorized device the content stays unreadable, even after it has been synced or copied.

CyberGrant's architecture also separates custody of the content from administration of the Microsoft tenant. On external shares, the sender can revoke access after sending, without creating a new user in the corporate tenant. Connector is available as an extension of FileGrant, and works with RemoteGrant for secure local access to documents.

"SharePoint and OneDrive are already part of daily work at a huge number of organizations, but many of them have assumed that managing access permissions was the same thing as protecting content. It isn't. An authorized user can download a document and take it anywhere, and from that moment the file is beyond any control. This gap affects everyone, not only companies that have already been breached, because the human element and third-party involvement in data breaches keep growing. With Connector we wanted to close it without adding complexity: encryption moves into the environments people already use, with no new tools and no new habits, and it stays attached to the document even after it leaves the corporate perimeter," said Valerio Pastore, co-founder of CyberGrant.

Encryption designed for the post-quantum scenario

Across its suite, and therefore in Connector, CyberGrant uses post-quantum encryption based on the CRYSTALS-Kyber family. In August 2024 the U.S. National Institute of Standards and Technology published FIPS 203, the standard defining ML-KEM, the Kyber-derived mechanism built to withstand attacks from future quantum computers. Files stolen today in encrypted form can be decrypted once a sufficiently powerful quantum computer exists. That is the harvest-now-decrypt-later logic: collect the data now, wait for the capability. For documents with long-term value, multi-year contracts, intellectual property, clinical records, the threat horizon is not distant. It is a real factor in choosing the encryption you adopt today.

About CyberGrant

CyberGrant develops cybersecurity solutions for protecting corporate data, files, and access. Its portfolio includes FileGrant, RemoteGrant, EmailGrant, SecretGrant, AIGrant, and Connector. The company is headquartered in Menlo Park, California, and works with businesses and public organizations in sectors that handle confidential information. More at www.cybergrant.net.

 

Press contacts

CyberGrant Inc. Press Office
ddl studio, viale Premuda 14, Milan, Italy
Mara Linda Degiovanni | maralinda.degiovanni@ddlstudio.net | +39 349 6224812
Cristiana Freguglia | cristiana.freguglia@ddlstudio.net | +39 339 8739453

 

Frequently Asked Questions About Protecting Files in SharePoint and OneDrive

What is CyberGrant Connector?

Connector is the FileGrant extension that encrypts files directly inside Microsoft SharePoint and OneDrive. Documents stay in their existing libraries, with the same permissions and the same Microsoft interface, and open only on authorized company devices. Protection lives in the file, so it holds even after the document leaves the tenant.

Does Connector replace SharePoint, OneDrive, or Microsoft Purview?

No. Connector runs on top of the Microsoft 365 stack you already have and adds a file-level encryption layer. SharePoint and OneDrive keep handling access and collaboration; Microsoft Purview keeps handling labels and classification. Connector covers what is missing: persistent encryption that follows the document outside the perimeter.

Do files have to be migrated to use Connector?

No. Documents stay exactly where they are, in the SharePoint libraries and OneDrive accounts already in place. An administrator picks the scope, an entire site or a single folder, and Connector encrypts the files inside it automatically. No new repository is created, no data is moved, and permissions are not redefined.

Which file types does Connector encrypt?

Any format, not just Office. Connector encrypts Office documents, PDFs, images, design files (PSD, AutoCAD), source code, and text files, keeping the original extension. That is a meaningful difference from Microsoft Purview, which applies sensitivity labels and encryption mainly to Office formats and PDFs and leaves the rest uncovered.

Can Copilot read files encrypted by Connector?

No. Copilot and other AI assistants index SharePoint documents to answer user queries. On a file encrypted by Connector they see only ciphertext and metadata, never readable content. The same holds outside the tenant: a document that leaves encrypted never feeds a model.

Is Connector's encryption quantum-safe?

Yes. Connector uses CRYSTALS-Kyber, the algorithm NIST standardized as FIPS 203 (ML-KEM) in August 2024. It addresses harvest-now-decrypt-later attacks, where encrypted data is stolen today and stored until a sufficiently powerful quantum computer becomes available. The exposure matters most for documents with long-term value: multi-year contracts, intellectual property, clinical records.

Does Connector help with Italy's October 31, 2026 NIS2 deadline?

The baseline security measures defined by Italy's ACN include encryption policies, access control, and traceability of operations. Connector applies automatic encryption to documents in SharePoint and OneDrive, ties file access to authorized devices, and logs access. Those are documentable elements during an audit, though NIS2 compliance remains an organizational program that no single product covers on its own.