New research has uncovered that nearly three quarters (73%) of security professionals admit to using SaaS (software as a service) applications that haven’t been provided by their company’s IT team in the past year.
This is despite the fact that they’re acutely aware of the risks, with respondents citing data loss (65%), lack of visibility and control (62%), and data breaches (52%) as the top risks of using unauthorised tools.
Further, one in ten admitted they were certain their organisation had suffered a data breach or data loss as a result.
These insights come from a survey of more than 250 global security professionals at RSA Conference 2024 and Infosecurity Europe 2024, conducted by Next DLP, the provider of insider risk and data protection solutions.
When it comes to how security professionals view their organisation’s training and overall understanding of the risks of shadow SaaS, 40% don’t think employees properly understand the data security dangers that are associated.
Yet, they’re doing little to combat this, with only 37% of security professionals having developed clear policies and consequences for using these tools, with even fewer (28%) promoting approved alternatives to combat usage.
Only half had received guidance and updated policies on shadow SaaS and AI in the past six months, with one in five admitting to never receiving this.
Meanwhile, half of the respondents highlighted that AI use had been restricted to certain job functions and roles in their organisation, while 16% had banned the technology completely.
Adding to this, 46% of organisations have implemented tools and policies to control employees’ use of GenAI.
Recommended reading
- Half of Employees Fear Reporting Security Mistakes
- CFOs, CEOs Identify AI as Most Impactful Tech Over Next 3 Years
- Hackers Have Stolen More Than £1BN in Crypto Already This Year
“Security professionals are clearly concerned about the security implications of GenAI and are taking a cautious approach,” explained Next DLP’s chief security officer, Chris Denbigh-White.
“However, the data protection risks associated with unsanctioned technology are not new. Awareness alone is insufficient without the necessary processes and tools. Organisations need full visibility into the tools employees use and how they use them.
“Only by understanding data usage can they implement effective policies and educate employees on the associated risks.”
“Clearly, there is a disparity between employee confidence in using these unauthorised tools and the organisation’s ability to defend against the risks,” Denbigh-White continued.
“Security teams should evaluate the extent of Shadow SaaS and AI usage, identify frequently used tools, and provide approved alternatives. This will limit potential risks and ensure confidence is deserved, not misplaced.”





