Site navigation

NCSC Issues New Shadow IT Guidance

Michael Edgar

,

Shadow IT guidance
The National Cyber Security Centre (NCSC) releases comprehensive guidance to help organisations manage and mitigate the risks associated with shadow IT.

Shadow IT, or grey IT, is the unauthorised use of resources by employees for business purposes. This could be unauthorised devices connected to corporate networks, but it can also be users storing sensitive data in personal cloud networks, or using unapproved messaging or collaboration tools. 

According to the NCSC, most organisations have some level of shadow IT without realising. “This could result in the exfiltration of sensitive data, or spread malware throughout the organisation,” warns the NCSC.

According to the NCSC, shadow IT is rarely the result of malicious intent. It is usually a result of staff struggling to use sanctioned tools to complete a task. Therefore the way to mitigate the use of shadow IT is to find where it exists and address the underlying causes of it. 

“If they’re resorting to unsecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make use of shadow IT solutions,” writes Simon B, NCSC researcher. 

Along with addressing the underlying needs, system owners and technical staff are also encouraged to identify and manage IT assets in their organisation through robust asset management and network access controls. 

According to figures from Gartner, 41% of employees acquired, modified, or created technology outside of IT’s visibility in 2022. A project management survey from Capterra also found that 57% of SMBs have had shadow IT outside the purview of their IT departments this year. 


Recommended


The report stresses the importance of not reprimanding staff for using shadow IT. Since the use is often linked with an issue with their sanctioned tools, if one staff member is punished, others will be reluctant to tell you about their own unsanctioned practices. 

“For this reason, the guidance also points out the importance of developing a good cybersecurity culture, so that staff will be able to communicate openly about issues (including where current policy or processes are preventing them from working effectively),” writes Simon B.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data