Editorial

Losing Control of the Perimeter

How shadow IT made cyber security so much more difficult

Monday, June 01, 2026 | 5 MINS

IT teams like yours,  and by extension, the security teams within them, used to be in complete charge of technology within a business. By and large, nobody used any hardware or software for professional reasons without their say-so. 

That way, they could make sure the technology in question was appropriate for the organisation, made sense financially, and wouldn’t introduce unnecessary security risks.

 Then, as the world of work became less centralised and more flexible, approaches to tech procurement changed extremely quickly. People and departments no longer want to wait for IT approval and budget planning to get new solutions and innovations up and running. Like Veruca Salt in Charlie and the Chocolate Factory, they want them NOW.

This has led to a ‘wild west’ approach where individual departments pretty much do what they want, whether that’s Marketing adopting SaaS-based sales platforms, Operations deploying automation, or Human Resources leveraging AI to boost their productivity. Forget waiting around for a green light from your IT or security teams: sometimes they won’t even bother to tell you that they’re doing it.

Somebody else did something bad, and it’s your fault!

A recent report by Gitnux into the spread of shadow IT lays bare the scale of the security problem this represents. Nearly half of businesses (45%) say that their employees are allowed to buy and run software without having to gain approval from IT, and more than two-thirds (68%) are concerned that this is exposing them to greater cyber risk. The same report also found that 57% of businesses say unmanaged cloud services, a common case of shadow IT, increase the risk of credential theft or account takeovers.

It doesn’t matter whether somebody bypassed IT to install something. It doesn’t matter whether you know they’ve done it or not. It doesn’t even matter if you knew about it, told them not to do it and watched them do it anyway. Rightly or wrongly, it’s your responsibility to keep data, systems and applications secure — and you’re the one who will carry the can if/when something bad happens (even if it’s absolutely no fault of your own). 

What can you do about it?

So how do you stop fighting the tide and start working with it?

To an extent, it’s a case of ‘if you can’t beat them, join them’. Are departments bypassing traditional IT procurement, security and governance processes because they’re too slow and cumbersome? If so, then the only realistic way to get them back on side is to revise those processes to match the accelerated speed of modern business.

Of course, how that works in practice will vary substantially from one industry and organisation to the next. And that’s why it’s so important to get specific, tailored advice on how your security and governance processes can evolve to fit in better with the business aspirations of your workforce.


This topic is sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.


DOWNLOAD ENDPOINT FIRST

Here's where you can access more information in this ebook "Endpoint First:  Charting the Course to AI Security Operations"

Download

This topic was sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.

Also in this section

}());