DEV Community

Firewall Technical IT Insights
Firewall Technical IT Insights

Posted on Originally published at firewalltechnical.com

Is Your On-Premises SharePoint Server Still Putting Your Business at Risk?

If your business still runs SharePoint on a server in your own office or data centre, a wave of attacks from 2025 is worth understanding. They targeted a weakness in on-premises Microsoft SharePoint, and they revealed something every business owner should take to heart: closing the original hole does not always remove an attacker who has already slipped inside. Canada’s national cyber security agency documented the whole story in detail, and the lessons reach well beyond SharePoint.

What Happened With the SharePoint ToolShell Vulnerabilities?

In mid-2025, attackers began exploiting a chain of flaws in on-premises Microsoft SharePoint Server, known collectively as ToolShell (tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). *The Canadian Centre for Cyber Security investigated one of these compromises and published a thorough account of what it found.

According to the Cyber Centre, the earliest signs of exploitation appeared roughly 12 days before the vulnerabilities were publicly disclosed on July 19, 2025. In other words, some servers were already compromised before most organizations even knew there was a problem to fix. Rather than leaving the obvious traces that early guidance told defenders to look for, the attackers loaded custom code straight into the server’s memory, which made the intrusion much harder to detect with routine checks.

Did You Know: A vulnerability being “disclosed” on a certain date does not mean that is when attacks started. In this case, exploitation was already underway almost two weeks earlier. That gap is exactly why waiting for headlines before acting can leave a business exposed.

Why This Matters for Small and Medium Businesses

It is tempting to read a story like this and assume it only concerns large enterprises with sizable IT departments. Small and medium businesses should not dismiss the risk so quickly. The Cyber Centre noted that the organization in its investigation followed strong security practices and still could not have prevented the initial break-in, because the weakness lived in the software itself.

For a small or medium business, one exposed server can become a doorway to far more than a single application. In this case, the attackers used their foothold to steal stored credentials, copy password databases for later cracking, search connected file shares for sensitive documents, query the company directory for user and administrator accounts, and even try to reach the internal email system. A single vulnerable server rarely stays a single-server problem.

This pattern is not unique to SharePoint. According to Ottawa-based *Field Effect’s 2026 Cyber Threat Outlook, more than 80% of the incidents the firm investigated in 2025 involved cloud identity compromise. In many of those incidents, attackers used valid or stolen credentials rather than breaking through another technical barrier. The SharePoint investigation illustrates how a software vulnerability can quickly become a broader identity and access problem once credentials are exposed.

Pro Tip: If your team has ever thought “we installed the update, so we are covered,” treat that as a prompt to ask a harder question: could someone have gotten in before the update, and what would they have been able to reach from that one server?

Why Installing the Patch May Not Be Enough

Here is the part that surprises many business owners. Applying the security update is necessary, but on its own it may not be enough to make the problem go away.

During the SharePoint attacks, intruders extracted the server’s cryptographic keys early on. As both the Cyber Centre and Microsoft warned, once those keys are stolen, patching alone does not lock the attacker back out. They can keep regaining access until the keys are rotated and the server is restarted. The attackers in this case also planted a second entry point on a different server that was not even running SharePoint, then went quiet for about two weeks before returning to test whether their access still worked.

Key Takeaway: A security update can close the original door, but it cannot automatically remove an attacker who is already inside. Recovering from a compromise means assuming they may have made copies of your keys and hidden other ways back in, then acting accordingly.

Are You Running SharePoint Online or SharePoint Server?

This distinction matters, because only one of the two was affected. SharePoint Server is the on-premises version: you install it on hardware you own and manage, and your team is responsible for patching and securing it. SharePoint Online is part of Microsoft 365, hosted in Microsoft’s cloud, where Microsoft maintains the underlying infrastructure and applies fixes like these for you. The ToolShell vulnerabilities affected on-premises SharePoint Server, not SharePoint Online.

If you are not certain which one your business relies on, that is worth confirming today. Many organizations run a mix, especially if they moved to Microsoft 365 but left an older on-premises server quietly running in the background. Those forgotten servers are often the least monitored and the most exposed.

What to Do If You Rely on On-Premises SharePoint

If your business runs SharePoint Server, or any other business-critical software on your own hardware, a handful of concrete steps meaningfully reduce your exposure:

  • Apply the latest security updates from Microsoft without delay.
  • Rotate credentials and cryptographic keys, then restart affected servers, so stolen secrets can no longer be reused.
  • Review server and access logs for unusual activity, especially sign-ins from unexpected locations.
  • Run regular vulnerability scans and server audits so new weaknesses surface before an attacker finds them.
  • Monitor network traffic for signs of movement between servers, which is often the first clue that a single compromise is spreading.
  • Keep tested, isolated backups so you can recover cleanly if the worst happens.
  • If you suspect a system has been compromised, bring in a professional incident response investigation rather than assuming a patch has settled the matter. Multifactor authentication also provides an important additional barrier around the accounts an intruder may try to steal. It should be used wherever available, particularly for administrator accounts and remote access.

How Managed IT Support Lowers the Risk

Most small and medium businesses do not have the time or the in-house expertise to watch for threats around the clock, and that is precisely the gap attackers count on. A story like the SharePoint attacks is not meant to frighten you into buying something. It is meant to show that maintaining business-critical software on your own servers takes more than installing updates when you remember to.

This is where a managed IT and cybersecurity partner earns its place. Proactive patch management keeps known weaknesses closed. Continuous server and network monitoring catches unusual behaviour early, when it is still contained. Layered protection limits how far any single compromise can spread. And a tested incident response plan means that if something does slip through, there is a calm, practiced process ready rather than a scramble.

For a typical Ottawa professional services firm running a small on-premises environment alongside Microsoft 365, that combination can reduce the risk of prolonged downtime, data exposure, and an expensive recovery effort.

If you are not sure whether your on-premises servers are properly protected, call Firewall Technical at 613-288-5805. A short conversation can help clarify what you are running, where the most important risks may be, and what should happen next.

Citations:
Canadian Centre for Cyber Security
Field Effect’s 2026 Cyber Threat Outlook

Top comments (0)