The dangers of Shadow IT
Shadow IT is the use of technology, such as cloud-based software, without the approval or oversight from the organisation’s IT department.
Some examples of shadow IT include:
- Storing business data on a private Google account
- Using a personal account on an online survey platform to collect work-related data
- Saving sensitive work personal data on an unmonitored personal laptop
- Using a private Dropbox account to manage a spreadsheet of work contacts
With the rise of online services in particular, more and more people have been able to use free or cheap tools to help with their work. These new online services can really help boost productivity.
The problem with Shadow IT is that the organisation that is responsible for the data has no direct visibility or control. This is a significant problem regarding Data Protection in the post GDPR world. It also causes challenges with data security, support and costs.
If an organisation’s Data Protection Officer receives a data access request, they are legally obliged to search through all the data in the organisation, and potentially delete personal data. If this is hidden away on a Shadow IT platform, the organisations is at risk.
Similarly, a data breach resulting from a Shadow IT system is likely to result in a hefty fine and the bad publicity that goes with it.
One of the reasons behind the rise of Shadow IT is that it took organisations time to evolve their IT infrastructure to incorporate effective cloud-based services. Some have still not caught up. Many have though, and now offer a suite of software tools such as Microsoft 365, Google Workspace or centrally monitored services such as survey software or online file storage.
This means that workers increasingly have a range of secure and supported online service they can use. The employer has oversight of the systems and can manage risks. Once official alternatives have been put in place, there are fewer practical benefits from using unauthorised software.
As part of my work as a technology consultant, I often must analyse and manage risks. Shadow IT is right up there with the highest risks facing organisations at the moment.
Where to start?
The challenge is to first stop it getting worse. This is done by auditing and documenting the systems in use and providing secure tools that people need and ensuing support/training is put in place.
The second stage is to start reviewing and removing historical accounts and data. This is a big challenge, but one I expect many more businesses and organisations are having to tackle as a priority.