The UK’s National Cyber Security Centre has published new guidance to help organizations identify and reduce shadow IT, which is the use of technology systems, software, applications, and services within an organization without the explicit approval, knowledge, or oversight of the IT department or the organization’s official IT policies. The risks associated with shadow IT include the possibility of exfiltration of sensitive corporate data and malware infections that could lead to data theft or cyber espionage.
This is one of those resources that is useful to leverage. I was struck by one paragraph:
“Avoid unnecessary lockdowns of enterprise IT, such as preventing external collaboration with cloud storage or not having an instant messaging platform. If you can anticipate your users’ needs, you may be able to prevent shadow IT from starting.”
Or said more simply, don’t be the department of no. It’s sound advice to remember.

