Shadow IT, or grey IT, is the unauthorised use of resources by employees for business purposes. This could be unauthorised devices connected to corporate networks, but it can also be users storing sensitive data in personal cloud networks, or using unapproved messaging or collaboration tools.
According to the NCSC, most organisations have some level of shadow IT without realising. “This could result in the exfiltration of sensitive data, or spread malware throughout the organisation,” warns the NCSC.
According to the NCSC, shadow IT is rarely the result of malicious intent. It is usually a result of staff struggling to use sanctioned tools to complete a task. Therefore the way to mitigate the use of shadow IT is to find where it exists and address the underlying causes of it.
“If they’re resorting to unsecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make use of shadow IT solutions,” writes Simon B, NCSC researcher.
Along with addressing the underlying needs, system owners and technical staff are also encouraged to identify and manage IT assets in their organisation through robust asset management and network access controls.
According to figures from Gartner, 41% of employees acquired, modified, or created technology outside of IT’s visibility in 2022. A project management survey from Capterra also found that 57% of SMBs have had shadow IT outside the purview of their IT departments this year.
Recommended
- Ransomware Leaks Drop 25% in First Quarter of 2022
- ICO Releases New Data Protection Guidance for Tech Teams
- ICO Releases Data Protection Tips for SMEs
The report stresses the importance of not reprimanding staff for using shadow IT. Since the use is often linked with an issue with their sanctioned tools, if one staff member is punished, others will be reluctant to tell you about their own unsanctioned practices.
“For this reason, the guidance also points out the importance of developing a good cybersecurity culture, so that staff will be able to communicate openly about issues (including where current policy or processes are preventing them from working effectively),” writes Simon B.





