Shadow IT: Balancing Efficiency with Security

Shadow IT: Balancing Efficiency with Security

With great access comes great responsibility, especially with regard to IT security policies. In recent months, discussions around security have evolved to include the growing risks associated with Shadow IT. While the practice of Shadow IT has existed since computing became a staple of the workplace and tech-savvy employees started skirting the rules, the risks of Shadow IT have skyrocketed with the exponential rise of mobile devices and cloud technology.

Shadow IT is greatly propelled by cloud services, where individual employees or work groups within a company deploy these solutions without the approval of their IT department, or without following established security policies.

These apps are easy to install and many employees don’t understand how their behavior can jeopardize the security of the company. This is especially true of millennial employees who, as digital natives, are often perceived as technically proficient despite evidence to the contrary.

Convenience is frequently the motivating factor when an employee decides to bypass IT. If installing a non-approved app will help them get their job done more effectively—and going through sanctioned channels is seen as too complicated or unlikely to result in a positive outcome—then asking for forgiveness becomes easier than asking for permission.

It also doesn’t help that few organizations have a formal policy in place that publicizes white- and black-listed apps internally. With this direction, employees believe they are simply enhancing their productivity without understanding the potential consequences.

Mobile growth has compounded the issue further, as employees seek new ways to bring their work with them out of the office and off the local network. Cloud applications streamline this process, by making data available from any location and device. But what happens when the application has a backdoor that can be used by an attacker to access the corporate network? With network access and data, now accessible through an unauthorized application, and often with IT none the wiser, the risk to the organization is immeasurable.

Considering more than half of employees use two or more work devices, the potential for a data breach increases significantly, as each device becomes a new potential point of entry for attackers.

While CIOs undoubtedly recognize that unauthorized applications are in use in their organization, most CIOs can often underestimate the extent. In a typical enterprise, there are 15 to 20 times more unauthorized cloud applications in use than estimated by their IT department. As company data flows through these applications, tracking that data to ensure that it remains safeguarded becomes impossible. Often this flouting of security can happen just as often within the IT department.

According the results of our recent report, 45% of IT professionals admit to knowingly circumventing security policies at their workplace, while 33% say they have successfully hacked either their own company or that of another organization. Clearly policies related to Shadow IT need to be inclusive of those with privileged access.

All these findings support the idea that a company’s greatest vulnerability is the insider threat.  Bad behavior, human error and social engineering are often at the root of data breaches, and with Shadow IT, these actions can occur either on or off the corporate network, with the same devastating consequences. However, while the threat is rooted in people, so is the solution.

In responding to Shadow IT, companies can start by listening to their employees to learn what they need and provide more corporately-approved options based on that information. With the right tools on offer, a company can curb rogue app installations while increasing productivity.

Educating employees about data security will also help them make informed decisions. Training workshops and security policies can set clear expectations for employees while outlining the real-world consequences of exposing corporate data. Identifying the applications that are supported (or not) is another way to keep the message current and employees informed. Within the IT department, oversight must be maintained over all corporate networks, devices, and data. If a security incident occurs, IT should have a formal response plan in place so that the threat can be swiftly neutralized.  Automated alerts and tools that can be used to remotely freeze or disable compromised endpoints are an essential component of this type of remediation strategy.

Organizations can also contain the risk of Insider Threats by closing gaps in existing vulnerabilities. According to a Forbes Insights report, known vulnerabilities are the leading cause of data breaches, accounting for 44 percent of all incidents. A critical step in remediation is to improve the ability to prioritize and fill these security holes which will ultimately reduce your organization’s overall attack surface.

Regardless of whether companies see Shadow IT as a problem to be eliminated or an opportunity to improve practices within an organization, a response is imperative in order to reduce corporate risk.

Featured

  • New Gas Monkey Garage Venue Uses AI-Enhanced Video Technology

    Gas Monkey Garage, the automotive custom shop and entertainment brand founded by Richard Rawlings of Fast N’ Loud TV fame, has opened a vibrant new restaurant and bar in South Dakota, equipped with advanced, AI-enhanced video tech from IDIS Americas. Read Now

  • Data Driven, Proactive Response

    As cities face rising demands for smarter policing and faster emergency response, Real Time Crime Centers (RTCCs) are emerging as essential hubs for data-driven public safety. In this interview, two experts with deep field experience — Ross Bourgeois of New Orleans and Dean Cunningham of Axis Communications — draw on decades of operational, leadership and technology expertise to share how RTCCs are transforming public safety through innovation, interagency collaboration and a relentless focus on community impact. Read Now

  • Integration Imagination: The Future of Connected Operations

    Security teams that collaborate cross-functionally and apply imagination and creativity to envision and design their ideal integrated ecosystem will have the biggest upside to corporate security and operational benefits. Read Now

  • Smarter Access Starts with Flexibility

    Today’s workplaces are undergoing a rapid evolution, driven by hybrid work models, emerging smart technologies, and flexible work schedules. To keep pace with growing workplace demands, buildings are becoming more dynamic – capable of adapting to how people move, work, and interact in real-time. Read Now

  • Trends Keeping an Eye on Business Decisions

    Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.