@ThingsExpo Authors: Elizabeth White, Zakia Bouachraoui, Liz McMillan, Pat Romanski, Yeshim Deniz

Related Topics: @CloudExpo, Cloud Security, @ThingsExpo

@CloudExpo: Blog Post

The Answer to Shadow IT Is at Your Fingertips | @CloudExpo #Cloud

Shadow IT is used to describe information-technology systems and solutions built and used inside organizations

Buoyed by BYOD

Turn back the clock to 2008. The recession was in full swing and IT managers feeling the pinch decided to allow employees to use their own devices (in turn leading to the now ubiquitous term of bring your own device (BYOD)) to undertake their job, thus reducing capital expenditure and allowing IT managers to spend their budget elsewhere. Whether BYOD itself turned out to be good or bad is still a point of conjecture, especially when weighing up its benefits against potential security risks. What is true, however, is that it has played a big part in the current scourge of the IT Manager - Shadow IT.

If you haven't heard of the term Shadow IT yet, you will do soon. Shadow IT is used to describe information-technology systems and solutions built and used inside organisations without explicit organisational approval. It is also used, along with the term "Stealth IT", to describe solutions specified and deployed by departments other than the IT department.

Where the money goes

Staff often download and install applications to help them complete their work more effectively. New software can either help them become more efficient generally or it has become necessary to use the software due to client demands. For example, someone may install Skype because the client only wants to run conference calls via video. However, these employees may feel they cannot approach the IT department to install this software as there is too much red tape, and will be denied the request.

Gartner claims that Shadow IT regularly surpasses 30 per cent of a company's IT spend. According to Atos[1], 36 per cent of that money is being spent on file sharing software, 33 per cent on data archiving, 28 per cent on social tools and 27 per cent on analytics. The worrying primary reason for shadow IT is the IT department's inability to test and implement new capabilities and systems in a timely manner.

Pros and cons

There are undoubted benefits to Shadow IT. It lowers IT costs in a similar way to BYOD, increases flexibility, speeds up task completion and means the user isn't constantly banging on the IT admin's door. But there is a flipside. Shadow IT means no centralised IT oversight so an increase in organisational data silos, impeding cross-functional collaboration issues and increasing security risks. IT bosses are not left in the shadows, but completely in the dark on how securely corporate data is being accessed and shared by staff via unapproved application.

The security issue is unfortunately not only a critical one but a cultural one. When an employee casually uses an application such as Dropbox to transfer files there is likely to be little thought about the risk of potentially sensitive data - whether that is customer contact details, financial information or intellectual property - falling into the wrong hands. But the fallout could be catastrophic and lead to regulatory fines, customer distrust and reputational damage.

This scourge of shadow IT has been accelerated by cloud adoption and cloud-based file sharing. According to a recent survey conducted by Fruition Partners[2] of 100 UK CIOs, 84 per cent believe cloud adoption has reduced their organisation's control over IT, with a staggering nine in ten believing unsanctioned use of cloud services has created long-term security risks. Specifically, 60 per cent of respondents said there is an increasing culture of shadow IT in their organisations, with 79 per cent admitting that there are cloud services in use that their IT department is not aware of.

The perfect solution

When CIOs and IT managers search for additional security layers to protect sensitive data within an organisation, it is best to turn to technologies familiar to their staff. One perfect example is two factor authentication (2FA). The use of the technology has become widespread in the consumer realm, with consumers well versed in how to use 2FA and the importance of it to keep their own private data safe from prying eyes. The latest solutions incorporate near field communication (NFC) - used in Oyster Cards and by Apple Pay - allowing users to simply tap their smart devices to gain access to the information they need. Ironically, by installing an application all BYOD and work devices can be equipped with 2FA to ensure only authorised staff can use them.

While 2FA empowers users, CIOs and IT decision makers also benefit from a flexible solution that can be hosted how, where and when they prefer. 2FA is built to suit any business, as it supports both on premise and cloud hosting and management, making it a strong contender for any CIO changing their security systems. By using existing infrastructure, on premise deployment is often convenient, swift and straightforward, while cloud services are appropriately supported by the 2FA provider. This gives decision makers full control and flexibility over the solution, which can be rolled out to departments and employees at their discretion.

If you can't beat them, join them

Shadow IT is here to stay. IT departments need to appreciate that it is so culturally inbuilt that shutting it down is now impossible; in fact, policies punishing the use of third-party apps would more likely push rogue users deeper into the darkness. The battle that can be won is to better educate staff and make Shadow IT an integral part of the company's wider security awareness program. Some staff are aware of the problems, and will ignore them, but many just simply won't understand why what they are doing could affect the whole business.

The good news is that many of the popular shadow IT applications downloaded by staff - such as Dropbox, Skype and TeamViewer - already have the option for 2FA[3]. By not only adopting 2FA for all BYOD and work devices, but reminding users to add this layer of security to the applications they are using for their business dealings too, would give IT managers piece of mind and is the answer to Shadow IT that until now has itself resided in the shadows.

[1] http://atos.net/en-us/home/we-are/news/press-release/2015/pr-2015_03_26_...

[2] http://fp.fruitionpartners.com/category/white-papers/cio-survey-report

[3] https://twofactorauth.org/

More Stories By Steve Watts

Steve Watts is co-founder of SecurEnvoy. He brings 25 years’ of industry experience to his role at the helm of Sales & Marketing for SecurEnvoy. He founded the company with Andrew Kemshall in 2003 and still works tirelessly to grow the company in new and established markets. His particular value is market and partner strategy; having assisted in the development and design of the products, designed the pricing strategy and recurring revenue model that has been so key to the businesses growth and success.

Before starting SecurEnvoy, Steve was responsible for setting up nonstop IT, the UK’s first IT security reseller in 1994. Prior to setting out on his own, Steve worked as Sales Director at the networking and IT division of Comtec, and had started his career in office solution sales in 1986.

Outside of work, Steve is a keen rugby fan. He also enjoys sailing, mountain biking, golf and skiing

IoT & Smart Cities Stories
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Dynatrace is an application performance management software company with products for the information technology departments and digital business owners of medium and large businesses. Building the Future of Monitoring with Artificial Intelligence. Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more busine...
Nicolas Fierro is CEO of MIMIR Blockchain Solutions. He is a programmer, technologist, and operations dev who has worked with Ethereum and blockchain since 2014. His knowledge in blockchain dates to when he performed dev ops services to the Ethereum Foundation as one the privileged few developers to work with the original core team in Switzerland.
Whenever a new technology hits the high points of hype, everyone starts talking about it like it will solve all their business problems. Blockchain is one of those technologies. According to Gartner's latest report on the hype cycle of emerging technologies, blockchain has just passed the peak of their hype cycle curve. If you read the news articles about it, one would think it has taken over the technology world. No disruptive technology is without its challenges and potential impediments t...
If a machine can invent, does this mean the end of the patent system as we know it? The patent system, both in the US and Europe, allows companies to protect their inventions and helps foster innovation. However, Artificial Intelligence (AI) could be set to disrupt the patent system as we know it. This talk will examine how AI may change the patent landscape in the years to come. Furthermore, ways in which companies can best protect their AI related inventions will be examined from both a US and...
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of San...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...