5 ms·
Ohhh man/woman. I'm a security person. I often work with my customers' central IT. I'm not going to have an opinion or judge you, but consider: You're giving
by SCHiM 5y ago
Ohhh man/woman.
I'm a security person. I often work with my customers' central IT. I'm not going to have an opinion or judge you, but consider:
You're giving people nightmares. I've seen it go very wrong (front-page news wrong). And then the threads commenting on "how incompetent can they be, blabla". I've worked with the people stressed, sad and disappointed that they got pwned because of shadow IT. It's a ticking time bomb.
The cloud wont save you from shadow IT's insecurities. In two years, when you switch to another SAAS provider, or the domain changes, and the enterprise app is left in your azure subscription, and the baddies notice... Then you'll call me or someone like me, and I can earn my paycheck :)
- MattGaiser 5y agoI'm too junior to make decisions, but a lot of it basically came down to the organizations I have worked with all either being government or running things on quarters. In the former case there was high turnover (replace the team in 1.5 years) and in the latter cases there was high turnover coupled with a problem more than a month away not being considered a problem. So in the former knowledge poured out the door and in the latter knowledge poured out the door and nobody had an interest in anything beyond the quarter, so you do what gets you to the next review cycle. Basically in both cases the bomb does not matter as you either probably won't be there when it goes off or it doesn't matter as you miss your quarterly goal instead.
- bachmeier 5y agoIt usually goes something like this: We need software to do X. Call IT, they give you software that sort of does part of X, but it's some enterprise garbage where you quit your job if you have to use it. Call IT and tell them that's not a good solution. We have this other realistic solution instead. IT, not wanting to be bothered, laughs and hangs up the phone. Sometimes they'll throw in an excuse that everyone knows doesn't make any sense. The workers that need to do their job pay for an actually working solution out of other funds (or use their personal software). Things go wrong and they call you. It's the ineffectiveness of IT to help people get their work done that's the source of the problem.
- meowface 5y agoA properly functioning IT department will say using the SaaS is fine as long as they conduct a security review of it and how it'll be used and integrated. (For example, if it's Dropbox and one of the proposed directories to be synced contains trade secrets, that's something they'll want to know about and deal with or prevent ahead of time.)
- acdha 5y agoI've also see shadow IT be the only part of the IT operation which is safe because it was run by people with security expertise, the cloud provider has a stronger security foundation than on-premise (not uncommon), and central IT's security group was primarily a compliance shop which had lots of Word documents and not much in the way of technical skills. The way I read shadow IT is as the requirements analysis central IT hasn't done. People aren't taking on all of that extra expense because they want two jobs, they're doing it because central IT is making it hard to do their jobs. When security policies conflict with productivity, it has a direct cost from inefficiency but often a greater one by training people to think of central IT as an obstacle to be bypassed rather than an ally. That inevitably causes other problems and takes a considerable amount of work to improve.
- jcelerier 5y ago> You're giving people nightmares. I've seen it go very wrong (front-page news wrong). And then the threads commenting on "how incompetent can they be, blabla". I've worked with the people stressed, sad and disappointed that they got pwned because of shadow IT. It's a ticking time bomb. Who cares about front-page news wrong lol. Equifax was front-page news wrong, and there were 0 actual consequences for people in it.
- znpy 5y agoI like your thinking.
- Godel_unicode 5y agoSolarwinds stock price is up a few percent compared with a year ago. Neither Home Depot nor Target appear to be hurting.
- raesene9 5y agoAnd of course before a breach, every company thinks "that won't happen to me". I'm sure that breach was expensive to Equifax internally, but as you say 0 external consequences mean, what company will change their ways...?
- deleted 5y ago[deleted]
- raesene9 5y agoI've been in security in various roles for a while now and what I've found is, in companies where IT is treated as a cost centre and Security say no to stuff, Shadow IT will always be rampant. If you put someone in business into the position of choosing between getting their job done/making money and adhering to a set of IT/Security rules, I can tell you which one they'll take :) How do you avoid this? Well it's not easy and it's not cheap. The most important part is ensuring that IT isn't treated like an expense, but an enabler. then you work with your business teams to make sure they have the services they need to get the job done, as safely as possible. Security teams shouldn't be blockers, but advisors. for this to work, it needs to be acknowledged that the business leaders own the risks ofc. That's massively easier to write than do, but from what I've seen of various companies, it's pretty much the only way to have a chance of doing things without huge amounts of shadow IT.