Cyber Security
Browsers Are Now the Workplace
Does thinking about it as the new end point change anything?
Editorial
How shadow IT made cyber security so much more difficult
That way, they could make sure the technology in question was appropriate for the organisation, made sense financially, and wouldn’t introduce unnecessary security risks.
Then, as the world of work became less centralised and more flexible, approaches to tech procurement changed extremely quickly. People and departments no longer want to wait for IT approval and budget planning to get new solutions and innovations up and running. Like Veruca Salt in Charlie and the Chocolate Factory, they want them NOW.
This has led to a ‘wild west’ approach where individual departments pretty much do what they want, whether that’s Marketing adopting SaaS-based sales platforms, Operations deploying automation, or Human Resources leveraging AI to boost their productivity. Forget waiting around for a green light from your IT or security teams: sometimes they won’t even bother to tell you that they’re doing it.
A recent report by Gitnux into the spread of shadow IT lays bare the scale of the security problem this represents. Nearly half of businesses (45%) say that their employees are allowed to buy and run software without having to gain approval from IT, and more than two-thirds (68%) are concerned that this is exposing them to greater cyber risk. The same report also found that 57% of businesses say unmanaged cloud services, a common case of shadow IT, increase the risk of credential theft or account takeovers.
It doesn’t matter whether somebody bypassed IT to install something. It doesn’t matter whether you know they’ve done it or not. It doesn’t even matter if you knew about it, told them not to do it and watched them do it anyway. Rightly or wrongly, it’s your responsibility to keep data, systems and applications secure — and you’re the one who will carry the can if/when something bad happens (even if it’s absolutely no fault of your own).
So how do you stop fighting the tide and start working with it?
To an extent, it’s a case of ‘if you can’t beat them, join them’. Are departments bypassing traditional IT procurement, security and governance processes because they’re too slow and cumbersome? If so, then the only realistic way to get them back on side is to revise those processes to match the accelerated speed of modern business.
Of course, how that works in practice will vary substantially from one industry and organisation to the next. And that’s why it’s so important to get specific, tailored advice on how your security and governance processes can evolve to fit in better with the business aspirations of your workforce.
Here's where you can access more information in this ebook "Endpoint First: Charting the Course to AI Security Operations"
Download
Cyber Security
Does thinking about it as the new end point change anything?
Cyber Security
While security teams draft policies, users are already uploading data
Cyber Security
Beyond the perimeter lies a smarter way to secure work
Cyber Security
The perfect storm waiting to happen inside your business
Cyber Security
Smarter security choices that reduce complexity and improve protection
Cyber Security
But built it one family car at a time
Cyber Security
Enterprise security without the enterprise barriers to entry
Cyber Security
Business moves fast; Security still owns the consequences.
Cyber Security
You can't protect what you can't see is running
Cyber Security
Every unknown application is an open invitation.
Cyber Security
Explore your next decision with confidence
Cyber Security
When new ways of working outpaced security teams