Straight to the bloody point: Shadow IT in under 300 words

happygeek 3 Tallied Votes 989 Views Share

Shadow IT is the usage of unauthorized tech by employees; usually cloud applications and services.

A progression of the Bring Your Own Device (BYOD) debate, I have not said that the applications or services themselves are inherently insecure. Nor that usage is for malicious purposes. Quite the opposite is mostly true.

Insecurity and risk enter the equation because by being unauthorized shadow IT remains invisible to security controls. This can lead to the creation of an unmanaged attack surface, and blind spots in your company security implementation are never going to be a good thing.

Or are they?

There are upsides to shadow IT usage for just about any organisation, in that it can 'shine a light' on applications and services that can aid productivity and might otherwise not be considered by the business.

Equally, they can shine that light on a policy restriction that gets in the way of user productivity, and so the savvy employee finds a way to work around it. And adding something to that corporate policy that prohibits such usage isn't, when you think about it, likely to be effective.

If you want to truly embrace digital transformation and all the business benefits that can bring, then bringing shadow IT into the fold is part and parcel of it. Getting the balance between convenience and control is key, and true visibility the goal.

As I said to begin with, it's not the apps or services themselves that is the problem; it's them not being visible to existing security measures. There's no reason why they shouldn't be audited in the usual way for your organisation and brought under the secure umbrella of corporate security policy and control...

rproffitt 2,662 "Nothing to see here." Moderator

As a developer of apps for embedded devices, testers on the production line and field diagnostics I've run afoul of IT groups that were for the most part not willing to invest the time to embrace the product development side of the business.

IT seems OK for run of the mill office work, the company web site, billing systems and such but the product developers are aliens or "the enemy within."

So they don't support us. That's fine by us. They also don't want the job but are ready to throw stumbling blocks in your path.

Is IT outdated today for companies that create apps and more?

Subraa_1 0 Newbie Poster

Is IT outdated today for companies that create apps and more?

I have the same query @profitt

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.