Understand what actually happens with an attachment. The file is copied into the recipient's mailbox, into your sent folder, into both providers' storage, and into every backup either party keeps, indefinitely. If the wrong person receives it, if an account is later compromised, or if the recipient leaves their organisation, the file is still there and you have no ability to reach it. Modern email is generally encrypted in transit, which addresses interception and does nothing about persistence.

A link to a file you control behaves differently. You can see who accessed it, revoke access when the work concludes, set an expiry date, and remove it entirely if something changes. The file exists in one place that you administer rather than in a dozen mailboxes you do not.

Grant access to a named person rather than creating a general link, wherever the material is genuinely sensitive. A link that works for anybody who has it is an attachment with extra steps: forwarded once, it is outside your control again. Named access ties the permission to an identity and produces a record of who opened it.

Set an expiry on anything time bound, which most services support and almost nobody enables. Documents shared for a project should not remain accessible two years after it finished, and expiry converts a decision you would have to remember into one the system enforces.

For anything requiring a password or a credential, do not send it in the same channel as the file, and preferably do not send it at all. Password managers support sharing a single item with somebody outside your organisation, which is considerably better than any message. Where that is impossible, a separate channel is the minimum, and the credential should be changed once the work is complete.

Consider whether the material needs to move at all. Frequently a client needs to see something rather than possess it, and view only access satisfies that while preventing downloads and copies. That is a setting rather than a technique and it is available in every mainstream storage service.

Understand what your industry requires, because several categories carry specific obligations that exceed general good practice. Health information, financial records, and legal material each have rules about how they may be transmitted and stored, and a mainstream consumer service may not be permitted regardless of how carefully it is configured.

Then check what you already have sitting in old email threads. Most small businesses discover that a considerable amount of client material is distributed across years of correspondence, accessible to anybody who gains access to either mailbox. Moving to a better method going forward does not address what is already there, and deciding what to do about the existing exposure is part of the same task.

Agree the method with the client at the start rather than at the moment something needs sending, because the default under time pressure is always an attachment. A sentence in your onboarding stating how documents will be exchanged sets the pattern for the whole engagement, and clients generally follow whatever you establish first.

Remove the shared material when the engagement ends rather than leaving it accessible indefinitely. A folder from a project completed two years ago is still open to whoever was granted access then, and closing it is a minute of work that nobody is ever prompted to do.