Straight to the bloody point: Shadow IT in under 300 words

happygeek 3 Tallied Votes 1K Views Share

Shadow IT is the usage of unauthorized tech by employees; usually cloud applications and services.

A progression of the Bring Your Own Device (BYOD) debate, I have not said that the applications or services themselves are inherently insecure. Nor that usage is for malicious purposes. Quite the opposite is mostly true.

Insecurity and risk enter the equation because by being unauthorized shadow IT remains invisible to security controls. This can lead to the creation of an unmanaged attack surface, and blind spots in your company security implementation are never going to be a good thing.

Or are they?

There are upsides to shadow IT usage for just about any organisation, in that it can 'shine a light' on applications and services that can aid productivity and might otherwise not be considered by the business.

Equally, they can shine that light on a policy restriction that gets in the way of user productivity, and so the savvy employee finds a way to work around it. And adding something to that corporate policy that prohibits such usage isn't, when you think about it, likely to be effective.

If you want to truly embrace digital transformation and all the business benefits that can bring, then bringing shadow IT into the fold is part and parcel of it. Getting the balance between convenience and control is key, and true visibility the goal.

As I said to begin with, it's not the apps or services themselves that is the problem; it's them not being visible to existing security measures. There's no reason why they shouldn't be audited in the usual way for your organisation and brought under the secure umbrella of corporate security policy and control...

Dani AI

Generated

nailed the framing: shadow IT is a signal, not just a problem. Treat it as user-driven feature discovery and start with visibility — it is widespread (enterprises often see far more cloud services in use than IT expects) and a large share of staff use unsanctioned apps. Cisco: Shadow IT is rampant. Microsoft: Discover and manage shadow IT. (blogs.cisco.com)

A short, practical playbook: 1) discover everything first (firewall/proxy logs, endpoint telemetry, CASB); 2) triage by data sensitivity and threat surface (fast-block the high-risk services, allow low-risk quickly); 3) enable a secure self-service path — an approved SaaS catalog, templates, or sandbox environments so teams keep speed; 4) add simple KPIs (apps discovered, mean approval time, unsanctioned-app incidents) and iterate. Discovery tools and CASBs make the first step practical. TechTarget on discovery tactics. (techtarget.com)

To and : IT is not obsolete but its role must shift from gatekeeper to platform/partner. Embed security early (DevSecOps), create product-aligned IT liaisons, and treat shadow projects as inputs to the official roadmap. Governance + enablement beats blanket bans every time. The Cloud Security Alliance and several vendor case studies show governance, discovery, and self-service controls are the effective path forward. CSA cloud adoption guidance. (cloudsecurityalliance.org)

rproffitt 3,249 https://5calls.org Team Colleague

As a developer of apps for embedded devices, testers on the production line and field diagnostics I've run afoul of IT groups that were for the most part not willing to invest the time to embrace the product development side of the business.

IT seems OK for run of the mill office work, the company web site, billing systems and such but the product developers are aliens or "the enemy within."

So they don't support us. That's fine by us. They also don't want the job but are ready to throw stumbling blocks in your path.

Is IT outdated today for companies that create apps and more?

Subraa_1 0 Newbie Poster

Is IT outdated today for companies that create apps and more?

I have the same query @profitt

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.