Creeping in under the radar of the IT department, shadow IT is a symptom of the increasing amount of processing power found in our pockets, as well as the explosion in recent years of cloud-based collaborative working services.
Need to share a 10GB file? No problem, use Dropbox. Want to hold a virtual meeting? Easy-just Skype. What about writing up a proposal? That’ll be Google Docs or Office 365. Want to collect your in-house work mail on your private Android phone? What could be simpler?
These services and hundreds more like them put massive functionality in the hands of the individual, allowing them to streamline the way they work, improve their efficiency and offering them huge flexibility. All that’s needed to get up and running is a credit card, and in many cases you don’t even need that-an e-mail address will do.
Unsanctioned
Typically unsanctioned by the IT department-indeed it’s likely that the IT department has no idea it’s being used at all-shadow IT has permeated the business world. Unsanctioned devices such as smart phones and tablets are becoming common in Irish workplaces, while for many people, using web services to help them in their job is so routine as to be unremarkable.
It is typical for the individuals who use these services to only see the benefits they carry, particularly for themselves. Unless the person has some kind of responsibility for security or corporate governance within the organisation, the odds are they will not stop to consider the potential problems that come with the convenience.
"I’ve come across companies that are consciously using these services to carry out their day to day work, and I’ve come across companies that weren’t aware their staff was using them at all," said Brian Honan of BH Consulting.
"Probably the most basic issue that companies should be aware of is that these kinds of services tend to be tied to the specific individual that registers to use them, not the company they work for. Because they’re personal and not corporate accounts, the company doesn’t own the account even if it owns the data stored there. So if there is ever an issue where they need to know who is doing what with the company’s data, in the case of fraud or data leakage for example, they don’t have any actual right to access those accounts. That’s potentially a serious risk."
In addition, the nature of cloud-based services means it’s often very hard to know where the provider is hosting its data centres and storing its customer’s data.
"Depending on the information that is being moved around, there may be regulatory obligations to consider. For example, under the data protection act, Irish companies shouldn’t be sharing information or details about consumer clients in a spreadsheet using a service like Dropbox," said Honan.
"Doing that actually places that data outside the EU and outside the control of the company, therefore they are technically exporting personal data outside the EU with the proper controls in place."
Security lapses
A much more obvious risk posed by trusting sensitive proprietary information to a third party is that posed by security lapses. While an individual company is relatively unlikely to find itself specifically targeted by hackers, very visible international service providers are often targeted. And sometimes they just make mistakes.
"There have been many cases where these kinds of services have had security problems, they’ve been hacked and had their security compromised. They tend to protect the information uploaded to them with nothing more sophisticated than a password," said Honan.
"And one thing that we all know is that people tend to use the same weak passwords across multiple services. Recently LinkedIn was implicated in a security breach where people’s passwords were taken and posted on a Russian discussion forum-the odds are that many of those passwords are also registered on many, many other web services."
Similarly, Dropbox recently suffered an embarrassing security lapse when an employee’s own account was accessed without authorisation, allowing an intruder to make off with data. The attacker gained access by stealing user names and passwords from a separate website and then using them to log in to Dropbox, where they discovered that one of the accounts to which they had gained access belonged to the Dropbox employee.
As a response, the company has announced that it is beefing up its security measures, but the incidents highlights yet again the weakness of web services which depend on passwords alone to protect user data. From the point of view of managing shadow IT in your company, this is a real issue to consider.
When individuals sign up for these services on behalf of the company, they tend to manage those services in the same way they do their Facebook or Gmail accounts. But corporate data demands a higher level of consideration, and not everyone in the company is likely to be as security conscious as the IT department.
Thorny issue
So how should companies handle the issues that shadow IT present? Is the wisest course of action to forbid staff to use these services, or should they be sanctioned and used freely? Is there a middle ground that allows the organisation to benefit from increased work flexibility while not exposing itself to increased security risks?
"Part of the reason why shadow IT has become so prevalent is down to the consumerisation of IT-we have all the means at our disposal in the form of phones and web browsers," said Paul Pollock, senior executive with Accenture Ireland’s technology practice.
"Organisations can try to do one of two things-either get complete control over it and stamp it out, or figure out how to embrace it and ensure it’s used responsibly. The important thing is to get some governance in place and on the back of that start to formulate some policies."
According to Pollock, IT has to get closer to the business. "It has to be a partner to the business in delivering what the business requires. At the same time, the IT department has to protect the company’s core assets and the data or intellectual property that the business generates and has a responsibility to protect," he said.
"The average business person is now much more educated about technology and in many cases are quite tech savvy. As a result of this, they’re able to engage with the IT department at a level that years ago wouldn’t have been possible. The fact is that if you try to say no to this, people will do it anyway. We’re talking about services and technologies that increase employee’s productivity and allow them to do their job more efficiently. If you put barriers up, then people will see them as an irritation and will find ways around them. In such a situation, you have no input into the security of your data."
This is something that Mike Harris, a director in Deloitte’s enterprise risk services department, agrees with.
Denial of service
"When it comes to shadow IT, just saying ‘no’ is not a valid response anymore. The world is turning and the way people are interacting with technology is turning with it. In general, people are much more tech-savvy than they used to be, and because of smart phones and the power of the Net, they have a lot of powerful tools at their fingertips," he said.
"They see how useful they are and they want to use them to do their jobs better. Realistically it’s probably now impossible for IT departments to just put their foot down and say no, you can’t do this. The horse has bolted on that front."
Harris’ perspective is that the people using these services are looking for the best way to achieve their goals-they’re not deliberately trying to bypass company controls, that’s a side effect rather than a main goal. His advice for companies wondering how to handle this situation is to first of all carry out a risk assessment-understand what sort of information they have and what the risks of having that information compromised would be.
"In some cases, it might be perfectly reasonable to use web services to move some types of information around, but in others it may not. For example, you might want to use Dropbox to distribute information that is going to be given to the public anyway, like brochures and press releases. On the other hand, it may not be appropriate to use that service to distribute strategic plans to senior executives," he said.
The company should address these questions-when and where is it appropriate to use Dropbox, Skype, Amazon Web Services, Gmail and similar services? What kind of information is it okay to store in that way and what needs to have a higher level of security applied to it?
"There will be situations where a web-based file sharing service might be very useful to an organisation, but where you couldn’t use Dropbox because of the criticality of the data involved. In that case, the IT department should be looking at other third party services or even developing an application itself."
Honan of BH Consulting suggests that a variety of different approaches are necessary to manage the situation.
Education and awareness
"One approach is to educate people, to make staff aware of what the implications of their actions are. Look at how employees are working and how they are sharing information outside the organisation, and make sure they have alternatives," he said.
"There’s no point in saying you can’t use Dropbox if that’s the perfect way for them to share a 20GB file for legitimate work-related reasons. If there is no alternative solution, then the IT function needs to educate people on why they shouldn’t use public services and point out the liabilities. Make ignorance a non-issue, put these issues in the company policies and manage them."
Honan also suggests it can be worth monitoring data traffic and taking note of data being moved via instant messaging services or cloud storage providers.
"Keep an eye on it and investigate, but don’t necessarily block it. Security and IT are there to enable business, not slow it down or stop it from working. Instead of cutting the data off in a knee jerk reaction, ask why the employee is working that way, is there a better way and if there is something that can be learned from it."
The same is true for the phenomena of people bringing their own devices into the workplace, technology which staff perceive to have value to them but which the IT department doesn’t offer.
"We find that companies usually don’t know what devices are attaching to their networks, let alone what security risks they may pose, because they don’t have a service installed that can identify that information," said Richard Little, senior service offerings architect for enterprise mobility with Fujitsu. "It’s usually an eye opener for them when they see what mobile devices and services are being used."
Device management
Fujitsu is one of many companies which offers mobile device management tools designed to allow companies gain control over how data is used by well-intentioned employees. Its software has the capability to ring-fence corporate data on a privately-owned device, placing limits on how it can be used while leaving the device owner’s personal data untouched.
"The majority of smart devices are now privately owned and people at all pay grades have iPhones and Android devices, not just senior management. Everyone who has one of these wants to use it in the way that is most convenient for them, and that usually means accessing work data on it."
This is particularly true in technology companies where most people are extremely tech savvy and are happy to purchase the latest handsets for themselves, just because they want them.
"They often have multiple access devices-in our experience it’s not uncommon for executives to have a laptop, a tablet, a company phone and a private phone. Some people have even more. When you have lots of privately-owned devices being used to handle company data, you have to be really careful how you apply security measures to those devices," said Little.
"Remotely wiping a company-owned device if it’s lost or stolen isn’t a problem, but things are much less clear when it comes to company data stored on a privately-owned device-does the company have the right to remove that data?"
"If you don’t have proper controls in place, what do you do when an employee is leaving the company or has been fired? If they’re using a privately-owned device and you’re worried about your data become available to competitors then all you can do is ask the person nicely to delete it."
"If they don’t want to, there’s not much you can do," he said.





Subscribers 0
Fans 0
Followers 0
Followers