Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • IT Management

    Why Shadow IT Must Be Considered in Securing an Enterprise

    By
    Chris Preimesberger
    -
    July 24, 2018
    Share
    Facebook
    Twitter
    Linkedin
      ShadowIT

      2017 was infamous for cybersecurity breaches worldwide. These incidents were at such a global scale, they completely changed the game for organizational vulnerability. Now security is no longer a departmental or team problem but rather an organization-wide concern.

      According to Tracy Hernandez, Vice-President of Product Marketing at IT management software maker Kaseya, the recent trends in internal security actually can be an opportunity for strategic-thinking IT organizations.

      The topic of shadow IT—and shadow cloud IT—for two examples, have risen in importance for CIOs. Hernandez suggests that organizations accept the fact that unknown apps and devices are being used every day within the enterprise. Hernandez believes that rather than combat rogue agents, infosec admins should work toward enabling IT to have visibility and provide staff with automated endpoint management capabilities so shadow IT does not become the source of entry for vulnerabilities.

      In this eWEEK Data Point article, Hernandez offers five tactics that IT must execute in order to better understand the concept of shadow IT and manage it accordingly.

      Data Point 1:  Fully Embrace Shadow IT

      The concept of shadow IT emerged more than a decade ago as companies began to allow users to personalize their work experience. Early on, IT admins were frightened by this shift in workforce accessibility, wondering if they would: a) lose visibility, and b) lose control of their environments. In today’s world, shadow IT is a fact of life, so instead of fearing and fighting for control of it, IT admins need to admit its presence and form a symbiotic relationship with it.

      Data Point 2:  Education

      From a cultural perspective, it’s necessary to keep an open line of communication with end users and discuss how they may be contributing to breaches. Ongoing education is necessary, because employees often don’t realize the actions they take can lead to an organizational vulnerability.

      For example, a simple unauthorized Skype call can be problematic, because IT might not even know the app is being used. End users simply don’t recognize that what they perceive as everyday business activity can actually expose the company to unnecessary IT risk. It is up to IT leaders to provide education and best practices for its employee base.

      Data Point 3:  Better-Fitting Technology

      When an organization uses multiple tools for one IT management purpose, such as antivirus, it breeds unnecessary complexity and extraneous work streams, causing the rise of management mistakes and gaps. Most likely these disparate tools do not integrate and fit seamlessly with each other in a dynamic network. Strong integrations or single-platform devices help alleviate this issue.

      Data Point 4:  Automate and Govern by Policy

      Complete endpoint management that encompasses discovery and management of off-network devices, patching that extends beyond Microsoft to Mac and third-party applications and automation that is scalable and can drive consistency are important here. IT administrators must first have visibility on an automated basis; this includes third-party apps and cloud systems where data could be hidden. This also includes network work traffic flow—even browser extensions, so a management plan can be created—despite the end users adopting technology without IT involvement.

      Data Point 5:  Understand that Shadow IT Affects All Organizations, Regardless of Size

      With midmarket enterprises, in particular, there is still a cultural idea that cybersecurity does not affect them as much as their larger enterprise counterparts—that bad actors are not looking at them, only the “big guys.” This is a dangerous. Small organizations actually have more to lose, because downtime for them can be catastrophic.

      The good news is that solutions are available for midmarket players.

       

       

       

       

       

      Chris Preimesberger
      https://www.eweek.com/author/cpreimesberger/
      Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×