Shadow IT and Your Data
Shadow IT is what happens when employees work around organizational controls by using IT resources that were never sanctioned by the IT department. You will also hear it called Bring Your Own Cloud (BYOC) or Rogue IT. The most common example I see is a user storing company documents on a public file sync and share service such as Dropbox, usually so they can keep working from home or from a phone. As organizations become more mobile, this behavior is intensifying, and I do not expect that trend to reverse.
It is worth being honest about why it happens, because the reasons are mostly legitimate.
It’s convenient. With a quick visit to an app store, users can give themselves access to company information on nearly any device, from any location. The availability and practicality of cloud and SaaS (Software as a Service) applications has never been higher, and the sign-up process for most of them takes less time than submitting a ticket to IT.
Employees just want to do their jobs. There is rarely anything underhanded about shadow IT. In almost every case I have investigated, the user was trying to be more productive, not less careful. They reached for a tool they already knew because the sanctioned path was slower or did not exist.
Everybody does it. A recent McAfee-sponsored report found that 83% of surveyed business and IT workers admit to using non-approved cloud and SaaS applications for work. Note that the figure includes IT workers. When the people who write the policy are quietly violating it, the policy has a credibility problem, not just a compliance problem.
Policies are unclear, or unknown. Many employees genuinely do not know whether their organization has a cloud or SaaS policy, because the policy was written years ago for a different set of technologies. IT departments have to review and revise these documents continually; a policy that never mentions file sync services is silent on the single most common shadow IT behavior of the moment.
The sanctioned options are limited. When the approved tools cannot perform a function the business needs, users look to the cloud. Every gap in your application portfolio is an invitation.
There is a dark side, and it is usually unintentional. Sensitive company information can leak through carelessness at the end-user level: a mis-shared folder, a synced laptop that gets stolen, an account protected by a password reused from a personal site. It can also leak at the provider level, and here is the part that should concern anyone responsible for client data: when an employee moves files into a personal cloud account, the company loses visibility entirely. You cannot revoke access you do not know exists. When that employee leaves, the data goes with them, not out of malice, but because nobody ever knew it was there. In a business that handles client contact data, that is not a hypothetical risk; it is a contractual one.
That said, the risks of cloud and SaaS use are not fundamentally different from the email mishaps we have lived with for years, and the most effective prevention is the same: user education and self-awareness. A ten-minute conversation about what belongs in a personal Dropbox account (nothing generated on company time, is the short version) does more than a firewall rule that users will simply route around on their phones.
A successful IT department establishes a policy that aligns with business objectives. If the business needs to out-maneuver competitors by being agile and responsive, then employees need room to find creative solutions, and that argues for a broad policy rather than a restrictive one. There is a fine line between security and accessibility, and the job of IT is to find the balance and provide oversight, not to run a free-for-all and not to shut everything down. A blanket ban has a predictable outcome anyway: usage does not stop, it just goes further underground, and IT loses even the limited visibility it had. It is not feasible for corporate IT to regulate every aspect of technology inside an organization, but it remains IT’s responsibility to mitigate the risk of breaches, data loss, and exposure of confidential information.
The practical middle ground is to compete with shadow IT instead of merely policing it. Find out what the unsanctioned tools are being used for, then offer a sanctioned equivalent that is genuinely as easy to use, with company-controlled accounts and the ability to cut off access when someone leaves. Rather than restricting usage, the goal should be to expand the set of tools that let employees do their jobs better, without compromising security or liability. Users take the convenient path every time. The trick is making the convenient path the safe one.