Well the table itself is open to EOTI subject to a Custom Permission rule. So I think the concept is not really that the link to the Report is Secure, but the set of records which is returned meets the criteria of the Custom Rule. So you need to come up with a strategy that the records themselves are "Secure".
So for example, let's say you had outside EOTI Vendors and the report was a report of Open Purchase Orders. Each PO knows the Vendor ID#, so you can make a Secure Link based on that Vendor ID# so that when you send a link to a report of the Open POs, that Vendor could not "hack" into other Vendor's Purchase Orders.